The mechanism rests on two pillars: the authentication of the signer and the integrity of the document.
To authenticate the signer, one or more identification factors are used: a trusted email address (single-use link), an OTP code received by SMS, a personal cryptographic certificate, and so on. To guarantee integrity, a fingerprint (hash) of the document is calculated at the moment of signing. If the document is altered afterwards, the fingerprint no longer matches — and the signature is invalidated.
In solutions such as Certyneo, the process relies on PDF processing libraries that embed this cryptographic metadata directly into the file. A timestamped audit trail (action log) completes the set-up by recording every step: sending, opening, OTP validation, signing, and so on.
From a technical standpoint, several security mechanisms strengthen the integrity of the process: the qualified time-stamp (RFC 3161) applies certified proof of time to each signature; TLS 1.3 encryption protects data in transit; the geolocation and IP address of the signatory are recorded for traceability; finally, in certain flows (AES/QES), behavioral biometric data (typing speed, pressure) complement the identity fingerprint.
The concept of non-repudiation is central: thanks to the time-stamped and cryptographically signed audit trail, it is technically impossible for a signatory to deny having signed a document without falsifying the chain of evidence. With regard to archiving, French regulation (decree 2016-1673) requires 10-year retention for most commercial acts — Certyneo ensures this archiving with evidentiary value through sovereign hosting (EU).