Go to main content
Certyneo
Security

Proof of electronic signature: what you need to know

Audit trail, timestamp, fingerprint: how to prove that a document was indeed signed electronically, and by whom.

Certyneo Editorial Team3 min read

Updated on

Digitalisation des processus administratifs — équipe en réunion de travail

Proof at the heart of electronic signature

Unlike paper, the electronic signature carries its own proof. A set of elements is retained to prove who signed, when, from where and on what content.

This proof can be used in the event of a dispute before a court — often more robust than a handwritten.

The components of proof

1. The audit trail

A timestamped log of all actions: sending, opening (IP address, user-agent), OTP entered, actual signing, any refusal, expiration.

2. The cryptographic fingerprint

SHA-256 hash of the document at the time of signing. Any modification produces a different fingerprint — the signature becomes invalid.

3. The timestamp

Precise date and time, ideally issued by a qualified third-party timestamping authority. See electronic timestamping.

4. Identification of the signer

Proof that the signer is indeed who they claim to be: email received, OTP entered, possible qualified certificate.

How to verify the proof

Open the PDF in Adobe Reader → Signature Properties. For a more in-depth analysis, export the audit trail from your platform. See how to verify a signed document.

When proof is useful

  • Contractual dispute (customer disputes having signed)
  • Internal or external audit
  • Regulatory inspection (URSSAF, CNIL)
  • Employment tribunal dispute
  • Judicial request

The audit trail is the primary evidence, admissible provided it is produced by a platform compliant with eIDAS.

Retention period

  • 10 years for commercial contracts
  • 5 years after termination for employment contracts
  • 30 years for notarial deeds

See retention of signed documents.

Mistakes to avoid

  • Keeping only the PDF, not the audit trail
  • Using a platform without a qualified timestamp
  • Not regularly checking the integrity of the archives
  • Losing the login credentials for the platform

Use case: employment tribunal dispute

A dismissed employee disputes having signed their non-compete amendment. The employer produces: the PDF in PAdES format, the audit trail (IP address consistent with the home address, OTP entered on the personal phone), the qualified timestamp. The employment tribunal upholds the evidence.

How Certyneo helps you

Every envelope signed via Certyneo automatically generates a complete audit trail, embedded in the PDF and retained for 10 years. With one click, you can export the signed PDF, the detailed audit trail and the timestamp certificate.

Discover the Certyneo electronic signature solution

FAQ

Is the audit trail admissible in court?

Yes, it is recognized by French courts provided it is produced by a platform compliant with eIDAS.

Can I create my own audit trail?

Technically yes, but it will carry less weight than a trail produced by a trusted third party.

What if the platform disappears?

PAdES PDFs remain verifiable offline. The audit trail should be exported regularly.

Can I export proof in bulk?

Yes, most platforms offer a CSV or JSON export.

Is the proof different for SES/AES/QES?

The structure is the same. The QES incorporates stronger cryptographic elements.

Conclusion

Proof makes the difference between a signature done "just because" and a legally enforceable signature. Take care in how it is built and retained.

Try Certyneo to send, sign and track your documents online simply, quickly and securely.

Try Certyneo for free

Send your first signature envelope in under 5 minutes. 5 envelopes/mo for 14 days, then 2/mo, no credit card required.

Go deeper on the topic

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.