Skip to content

Guide

How Electronic Signatures Work Here

A signature is only worth what can be proven about it afterwards. This is exactly what Convertitive Sign proves — and where it stops.

By Published

What gets recorded

When you sign a document, three things are produced and kept together:

  • The signed PDF.Your signature, initials, dates, and text are stamped into the file on Convertitive’s server — not in your browser. That matters: a sealed copy produced somewhere the signer cannot edit is the only kind worth hashing.
  • A SHA-256 hash of that PDF. A 64-character fingerprint of the exact bytes. Change a single character in the file and the hash changes completely. It is printed on the certificate and shown on the document page.
  • An audit trail. Every event — created, signed, completed, downloaded — with a timestamp, a hashed network origin, and the browser identifier. Raw IP addresses are never stored. The trail is append-only: nothing in the product can edit or delete an entry.

What the hash proves

The hash answers one question precisely: is this file byte-for-byte the one that was signed? Recompute SHA-256 over any copy you are handed. If it matches the certificate, the file is unaltered. If it does not, something changed — the hash cannot tell you what, only that it did.

The hash does not prove who signed. That comes from the audit trail and the account it is attached to, which is why Sign requires an account where the rest of Convertitive does not.

What this is — and is not

Convertitive produces a simple electronic signature. That is the category most e-signature products at this price sit in, and it is what most everyday agreements, consent forms, and internal sign-offs call for.

It is not:

  • a qualified electronic signature under the EU eIDAS regulation, which requires a certificate from an accredited provider and identity verification;
  • an ESIGN-certified service — Convertitive makes no certification claim under the U.S. ESIGN Act or any other statute;
  • notarisation, which involves a licensed notary witnessing the act.

If a counterparty, court, or regulator requires one of those, Sign is not the right tool for that document.

Retention and deletion

Uploaded and signed files live on Convertitive’s servers in Frankfurt, Germany, and are deleted 30 days after signing. The audit trail outlives the file — a record that something was signed remains even after the document itself is gone. You can delete a document earlier from its status page.

Ready to try it? Sign a PDF — or tidy the file first with the browser-only PDF tools.

Frequently asked questions

Is a Convertitive signature legally binding?
In many jurisdictions a simple electronic signature is a valid way to show agreement, and the audit trail helps establish who signed and when. Whether it satisfies a particular contract, court, or regulator depends on the law that applies to you. Convertitive does not provide legal advice.
Does Convertitive verify who I am?
No. Sign records that an account holder placed a signature and when, plus a hashed origin and browser string. It does not check government ID, and it is not a qualified signature under eIDAS.
Can someone change the document after signing?
They can edit their copy, but the SHA-256 hash on the certificate will no longer match it. Recomputing the hash over a file and comparing it with the certificate is how you detect that.
Where is my file stored, and for how long?
On Convertitive's servers in Frankfurt, Germany, for 30 days after signing. The audit trail is kept after the file is deleted.

Related

Published September 20, 2026