Skip to content
A plain-English guide to electronic signatures

What an electronic signature actually is — and what makes one hold up.

Most e-signature pages sell you a button. This one explains the thing behind the button: what counts as an electronic signature under ESIGN, UETA and eIDAS, what a platform has to record for a signature to survive being challenged, exactly what happens inside tuyaform between pressing Send and holding a sealed PDF — and where a simple electronic signature is the wrong tool.

Simple electronic signatures (SES) under ESIGN, UETA & eIDAS · read the legal detail

Definitions

What an electronic signature actually is

An electronic signature is any electronic sound, symbol or process attached to, or logically associated with, a record and adopted by a person with the intent to sign that record. That phrasing comes almost word for word from the U.S. ESIGN Act, and it is deliberately, usefully broad.

Broad means the form of the mark barely matters. A squiggle drawn with a fingertip, a name typed into a signature field, a deliberate click tied to one specific document — any of them can be an electronic signature. What matters is the intent behind the mark and the evidence tying that mark to a person, a document and a moment in time. This is the single most common misunderstanding we run into: people assume the cursive-looking image is the legal object. It isn't. The image is the symbol; the record built around it is the signature.

It is also why an image of your handwriting pasted into a PDF is weaker than it looks. Nothing about that picture records who applied it, when, from what device or network, whether the person meant to be bound by it, or whether the document changed the day after. It is a picture of agreement rather than proof of it. A signing platform earns its keep by producing the proof, not the picture.

The EU's eIDAS regulation grades the same idea into three tiers, and it is worth knowing which one you are actually using — because vendors rarely volunteer it.

The three eIDAS tiers

SES — Simple Electronic Signature
The everyday electronic signature: a mark applied with intent, backed by whatever evidence the platform captures around it. Recognised across the EU, and the closest equivalent to what ESIGN and UETA describe in the United States. This is the tier tuyaform produces.
AES — Advanced Electronic Signature
Adds a signer identity that is uniquely linked to the signature, created using data the signer keeps under their sole control, with tamper detection over the signed data. Getting there requires real identity verification. tuyaform does not verify identity, so tuyaform does not produce AES.
QES — Qualified Electronic Signature
An advanced signature created with a qualified signature-creation device and a certificate issued by an EU-accredited trust service provider. QES is the only tier that carries automatic legal equivalence to a handwritten signature across the EU. tuyaform does not issue QES.

U.S. law is not tiered the same way: ESIGN and UETA set one standard and let the evidence decide how convincing a given signature is. In practice, a simple electronic signature with a thorough audit trail is what the overwhelming majority of ordinary business paperwork runs on — NDAs, leases, waivers, consent forms, contractor and service agreements.

Go deeper:Are electronic signatures legally binding?

What a challenge looks like

What legally distinguishes a signature that holds up

Nobody argues about the pretty script. When an electronic signature is challenged, the argument is almost always one of four things: I never agreed to do this electronically; that wasn't me; that isn't what I signed; or you can't produce the record. Everything a serious signing platform does exists to answer those four.

Intent — did the signer mean to sign?

tuyaform never treats a page view or a pre-ticked box as a signature. The signer has to open their own link, apply a signature deliberately by drawing or typing it, and confirm with a final action. That deliberate act, and the timestamp attached to it, is what intent looks like once it is written down.

Consent — did both sides agree to do business electronically?

The signing page shows an electronic-records-and-signatures notice before the signer confirms, so the agreement to sign electronically is on screen at the moment of signing. Being straight with you: tuyaform does not capture a separate affirmative consent checkbox or offer a decline-and-sign-on-paper path, and consent is not written as its own audit event — the deliberate signing action is the record. If your transaction needs an explicit, separately recorded consent step, add a checkbox field to the document and assign it to the signer.

Attribution — can the signature be tied to a person?

Every signer gets their own single-purpose link that resolves to exactly one signer and expires after 30 days. When they open it and when they sign, tuyaform records the IP address, the browser user-agent and a UTC timestamp against that signer. An optional per-signer access code adds a second factor. That is possession plus evidence, not identity verification — a real distinction, and one we would rather you hear from us than discover later.

Retention — can you produce the record later?

On completion the document is written out as a final PDF, fingerprinted with a SHA-256 hash and stored, and a separate Certificate of Completion is generated carrying the signer details, the event log and that same hash. Every party receives the completed copy by email, and the owner can re-download both files from the dashboard at any point.

Three of those four are captured mechanically on every document. The fourth — consent — is disclosed on screen rather than logged as its own event. That is exactly the kind of detail worth digging for before you trust any platform's badge, including ours.

End to end

How a signing flow actually runs in tuyaform

Here is the whole path, including the parts product pages usually skip.

  1. 1

    Create the document

    Start from a blank document, from a signing template, or by uploading a PDF you already have — PDF only, up to 4 MB, which is what our single-request upload path can accept. Templates give you a field scaffold rather than pre-drafted legal text: the wording is always yours to supply.

  2. 2

    Place the fields

    Signature, initials and date-signed fields carry the signing itself; name, email, text and checkbox fields collect everything around it. On an uploaded PDF you drag each field onto the page where it belongs, at the size and position you want, page by page. Every field is assigned to a specific signer, so each person only ever sees and completes their own.

  3. 3

    Add signers and send

    Add one signer or several, choose sequential routing (one at a time, in the order you set) or parallel (everyone at once), and optionally require a per-signer access code. Then either email the invitations or copy the signing link and deliver it yourself. Emailed invitations are the one metered thing here: the free tier includes 30 a month, paid plans raise that to 3,000 or 10,000, and sharing a link is never metered at all.

  4. 4

    The signer opens a secure link

    No account, no app, no install. The link is a single-purpose token that resolves to one signer, expires after 30 days, and stops working the moment the document is completed, declined or voided. If an access code was set, it is required before anything is shown. Opening the document writes a viewed event with the signer's IP address and browser user-agent.

  5. 5

    The signer signs — or declines

    They complete their assigned fields, draw or type a signature, read the electronic-signature notice and confirm. They can decline instead, optionally leaving a reason, which ends the document and notifies you rather than quietly stalling. In sequential routing, finishing hands the turn to the next signer automatically; nobody downstream can open the document early.

  6. 6

    Seal, certify, deliver

    When the last required signature lands, tuyaform writes the final PDF, computes its SHA-256 hash (and, where a signing key is configured, signs that hash with Ed25519), generates the Certificate of Completion as a separate file, and emails the completed copy to every party. A scheduled job re-runs the sealing step for anything that did not finish cleanly the first time, so a completed document never sits unsealed.

From the signer's side all of that is one link and roughly ninety seconds. The machinery is the point: none of it is optional, none of it is an upsell, and it runs identically on the free tier.

Go deeper:What is a Certificate of Completion?

The evidence layer

What the audit trail records — and why append-only matters

A signed PDF on its own proves surprisingly little. What makes it defensible is a separate, ordered log of what happened to it and when. tuyaform writes an entry to that log at every meaningful moment in a document's life, with a UTC timestamp and — wherever a human did something — their IP address and browser user-agent.

EventWhat it records
createdThe document was created in the owner's account.
sentThe document was dispatched for signature, recording who it went to.
viewedA signer opened their link — timestamped, with IP address and user-agent.
signedA signer completed their fields and confirmed — timestamped, with IP address and user-agent.
declinedA signer refused to sign, optionally with a reason. Nothing is sealed.
reminderThe owner manually nudged a signer who had not signed yet.
completedThe last required signature landed and the document closed.
sealedThe final PDF was hashed and the Certificate of Completion generated.
voidedThe owner cancelled the document; every outstanding link stops working.

Append-only means entries are only ever added — never edited, never quietly removed. In tuyaform that is not a promise on a marketing page, it is how access is configured: the audit table grants the document owner read access and nothing else, and rows are written exclusively by the server-side signing path. There is no screen, no bulk action and no setting in the product that can rewrite history, which is the entire reason the log is worth reading.

That property is also what lets the hash mean something. The signed PDF is the agreement; the Certificate of Completion is the testimony about how it came to be signed; the SHA-256 hash binds the two together. Change one byte of the agreement and its hash no longer matches the value printed on the certificate and recorded in the log. That is precisely what tamper-evident means, and it is worth stating the limit out loud: it does not prevent anyone from editing a copy of the file. It makes the edit impossible to hide.

Go deeper:What is an audit trail for e-signatures?Security

Choosing the right tool

Signing a document vs. collecting signatures on a form

tuyaform does both, and they are not the same job. Picking the wrong one is the most common mistake we see in new accounts — usually discovered months later, when the evidence someone needs turns out never to have been created.

Send a document to sign when…

…there are named parties, an agreement, and a real chance you will need to prove later that a specific person agreed to specific wording. This is the send-to-sign path: assigned fields, per-signer links, an audit trail, a SHA-256 seal, a Certificate of Completion, and a sealed PDF delivered to everyone involved.

  • NDAs, leases, contractor and service agreements
  • Waivers, consents and permission slips
  • Anything a counterparty could one day dispute
  • Anything you would otherwise print, sign and scan

Use a form with a signature field when…

…you are collecting many responses from people you do not know individually, and the signature is an acknowledgement rather than an executed agreement. A form's signature field captures a drawn or typed mark as part of the response — it does not produce a per-signer audit trail, a sealed PDF or a Certificate of Completion, because there is no document being executed.

  • Sign-up sheets and event registrations
  • Acknowledging a policy or code of conduct
  • Intake and onboarding questionnaires
  • Anything where volume matters more than proof

If you are unsure, ask what you would want in your hand a year from now. If the honest answer is a signed PDF you could hand to a lawyer, send a document. If it is a spreadsheet of responses, build a form. And when one form response does need to become an executed agreement, send that person a document afterwards — both paths live in the same free account.

Go deeper:How to collect signatures on an online form

Honest limits

Where a simple electronic signature stops being enough

Every e-signature vendor's marketing implies universal validity. That is not how the law works, and pretending otherwise does you no favours. Four limits are worth knowing before you send anything that matters.

  • tuyaform produces simple electronic signatures — not AES, not QES. We verify possession of an emailed link, plus an optional access code, not identity. If your transaction, regulator or counterparty specifically requires an advanced or qualified electronic signature, tuyaform is not the right tool for that document.
  • Some document types are commonly carved out of e-signature statutes. Wills and testamentary trusts, many family-law filings, court documents and certain statutory notices are typical examples, and the exact list varies by country and by state. Those still need paper, notarisation or witnessing.
  • Notarisation and witnessing are separate legal requirements from signing, and no signing platform satisfies them by itself. tuyaform provides neither.
  • Being built around ESIGN, UETA and eIDAS means the record we produce is designed to support a valid simple electronic signature. It is not a guarantee that a particular agreement is enforceable — enforceability depends on the contract, the parties and the jurisdiction, never on the software that carried the signature.

This page is general information, not legal advice. If the document is high-value, regulated, cross-border or likely to be contested, have a qualified lawyer in the relevant jurisdiction confirm that an electronic signature is appropriate before you send it. We would rather lose the signup than have you lean on a document that does not hold.

Questions

E-signature questions, answered

The legal and practical questions we get most often, followed by the how-do-I ones.

Is a typed signature as valid as a drawn one?

Legally, yes — neither ESIGN, UETA nor eIDAS privileges one visual form over another, and a typed name adopted with intent is a signature. What varies is the evidence around it, and in tuyaform that evidence is identical either way: the same audit trail, the same timestamps, the same IP and user-agent capture, the same seal and certificate. Let the signer use whichever is easier on the device in their hand.

Can a signed PDF still be edited afterwards?

The file itself can be edited by anyone holding a copy — that is true of every PDF everywhere, on every platform. What changes after sealing is that its SHA-256 hash no longer matches the value recorded in the audit trail and printed on the Certificate of Completion, so the edit is detectable by anyone who checks. Tamper-evident is not tamper-proof, and any vendor telling you otherwise is overselling.

How long should I keep a signed document, and where does tuyaform keep it?

Retention periods come from your jurisdiction and document type rather than from us — six or seven years is a common baseline for contracts, but check the rule that applies to you. tuyaform keeps the sealed PDF and its Certificate of Completion in your account so you can re-download them, and every signer receives their own copy by email at completion. For anything important, keep your own archived copy too: the strongest position is one where the record survives independently of any single vendor.

Can I use an electronic signature with someone in another country?

Usually, yes. The U.S. ESIGN Act and UETA, the EU's eIDAS regulation and equivalent statutes in many other countries all recognise electronic signatures. Cross-border agreements add two wrinkles worth handling up front: which country's law governs the contract, and whether either side's rules demand a higher signature tier — some EU public-sector and regulated processes expect a qualified signature. Agree the governing law inside the contract, and check the tier requirement before you send rather than after.

What actually happens if someone disputes a signature later?

You produce the sealed PDF and the Certificate of Completion. Between them they show the document's hash, each signer's name and email, their IP address and browser user-agent, UTC timestamps for every recorded action, the authentication method used, and the full event log from send through to seal. That evidence is what makes a simple electronic signature defensible. It does not decide the dispute, but it answers the two questions disputes usually turn on: was it really them, and is this really what they signed?

Sending & signing

Practical questions about running a signature

How do I send a document for electronic signature?

Start from a ready-made template or build a document from scratch, add signature, initials, and date fields and assign each one to the right signer, add your signers' email addresses, and send. Each signer gets their own secure link and signs in their browser, on any device, with no account required.

Can signers sign on a phone or tablet?

Yes. The signing page works in any modern mobile browser with nothing to install. Signers can draw their signature with a finger or type it, fill in any required fields, and submit — all from a phone or tablet.

What's the difference between sequential and parallel signing?

Sequential signing routes the document to one person at a time in the order you set, so each signer's turn opens only after the previous one finishes — useful when approval order matters. Parallel signing sends it to everyone at once so they can sign in any order. You choose per document when you send it.

How do you verify that the right person signed?

Each signer gets a unique link tied to their email address, and you can require an optional per-signer access code as a second factor. Every action — view, consent, and signature — is recorded in the audit trail with a timestamp, IP address, and device, so each signature is attributable to the person who made it.

Can I track who has viewed or signed, and send reminders?

Yes. You can see each signer's status — invited, viewed, signed, or declined — and send a reminder to anyone who hasn't signed yet. When everyone has signed, all parties receive an email with the completed, sealed PDF, and the Certificate of Completion is generated and available to the document owner from the dashboard.

What happens if a signer declines?

A signer can decline instead of signing, optionally leaving a reason. The document is not completed and you're notified so you can follow up, fix it, or resend. Nothing is sealed or treated as binding until every required signer has actually signed.

Free forever

Now put it to work — send something to sign.

Build or upload the document, place the fields, add your signers, and send. Audit trail, SHA-256 seal and Certificate of Completion on every completed document, on the free tier. Emailed invitations are capped at 30 a month free; sharing a signing link is unlimited.