How True Autograph works
Your signed document goes to every party, then we delete our copy. Here is what we keep and how anyone can verify a copy later.
The same story, written out
Everything in the video is illustrative: the names, links, and fingerprints are made up.
- 1
Send a request
The sender uploads a PDF and places fields, or sends from a template, the API, HubSpot, or Salesforce.
- 2
A private link for each signer
Signers can go in order, together, or a mix. Each one gets an email with a link that belongs only to them. The link carries a random token, and we store only a SHA-256 fingerprint of it, never the token itself.
- 3
Consent, then sign
The signer agrees to the electronic records and signatures disclosure, then signs in the browser without creating an account. Business and Enterprise plans can add an ID document and liveness check.
- 4
One signed PDF, sent to everyone
When the last person signs, the signed PDF is built once with every signature stamped in, fingerprinted with SHA-256, and emailed to every signer and to the sender.
- 5
We keep the proof, not your document
Right after that email, the document, the signature images, and any mapped data is deleted. What stays is the proof: who signed, their email, when and how, IP address and browser, consent, the name and title they typed, and the SHA-256 fingerprints.
- 6
A few requests wait
Requests sent from a CRM wait up to 72 hours for the CRM to record that signing is complete. Signed copies over 28 MB go out as a link that lasts 7 days, and the document waits for the link.
- 7
Anyone can check a copy
Anyone holding a copy can check it on the public Verify page. The file never leaves their device: the page works out its fingerprint in the browser and compares it with the one on record.