Skip to content
Proof and security

What DocTrace records. And what it doesn't.

We explain openly how a signature with DocTrace comes about and what it proves. No promises we cannot keep.

One final version, one checksum

After the last signature, DocTrace generates the finished PDF exactly once, calculates its SHA-256 checksum and stores it in the archive. DocTrace then sends exactly this file to everyone involved. Archive, e-mail attachment and download are identical byte for byte.

  1. 1Generate final version
  2. 2Calculate SHA-256
  3. 3Archive
  4. 4E-mail the same bytes

The proof page

DocTrace appends a page to every final version with the reference, document title, signers, time of signing with time zone, time source and the checksum of the original. For a document chain, it lists every stage with signer, server time, IP address and device.

Document uploaded9f3a…c21eE-mail with link sent← 9f3a…c21e 4b7d…08aaDocument opened← 4b7d…08aa e1c0…77f4Signature confirmed← e1c0…77f4 52d9…b3c1Final SHA-256 calculated← 52d9…b3c1 a8e4…1d90PDF archived← a8e4…1d90 c07b…5e62Audit chain intact

The chained audit log

Every entry contains the checksum of the previous entry. If anyone later alters an entry, even directly in the database, the chain no longer matches. DocTrace verifies the chain every time the detail page is opened and shows "Audit chain intact" or a warning.

Signed: 01.10.2026 14:32:07 (Europe/Vienna)Time source: DocTrace server
  • Personal links

    Every link belongs to exactly one person and one request. It expires, can be revoked and is locked once the request is completed. DocTrace stores only a hash of the link, never the link itself. A link never appears in the audit log.

  • Time from the server only

    Date and time always come from the server's clock, never from the person's device. The clock on the signer's phone has no influence.

  • Companies strictly separated

    Every company has its own recipients, documents, roles and its own audit chain. The separation is enforced in the database (Row-Level Security): a request only ever sees the data of the selected company.

  • Hosted in Frankfurt

    Servers and storage are located in the Google Cloud region europe-west3 (Frankfurt). The storage for originals and final versions prohibits deleting and overwriting. Connections are encrypted (TLS).

  • No trackers

    Neither the app nor this website uses trackers, analytics tools or advertising cookies. Fonts and content are served from our own server, so no cookie banner is needed.

  • E-mail delivery

    E-mails go out through your own SMTP server or through DocTrace's delivery. Credentials for your mail server are stored encrypted and are never returned.

  • Transparent support

    If you need help, our support team can view your company read-only at your request: documents, recipients, permissions, audit logs. Nothing can be changed in support mode, no link is created, and access ends after 60 minutes at the latest. Start, end, reason and every file retrieval are recorded in your audit log, and your company admins see all access under "Support access".

What DocTrace does not do

  • No identity verification: DocTrace does not check any ID document. The person is identified via the link sent to their e-mail address.

  • No qualified electronic signature (QES) and no certificate from a trust service provider in the PDF.

  • No one-time code and no login for signers. The link is the only access.

Whether a signature with DocTrace is sufficient for your purpose depends on the process. When in doubt, seek legal advice. Legal matters in the Help Center

Verify it yourself

The checksum of the final version appears in the e-mail, on the confirmation page and in DocTrace. With a single command on Mac, Windows or Linux, anyone can check whether their copy is unchanged.

$ shasum -a 256 DT-2026-00000417.pdf
4b7d08aa…e1c077f4 DT-2026-00000417.pdf

Guide: verifying the checksum

Your next signature in minutes instead of days.

Request a demo or get started right away. We reply personally.