These are legal documents. ToroDocs treats them that way — with real compliance, tamper-evident sealing, and a complete evidentiary record.
Signatures captured through ToroDocs are valid and enforceable under the U.S. ESIGN Act and the Uniform Electronic Transactions Act — the same legal footing as ink on paper.
Before signing, every recipient is shown an electronic-records disclosure and must actively agree — the consent step ESIGN requires, recorded with a versioned timestamp.
When a document completes, the server stamps the values and signatures onto the PDF, flattens it, and computes a SHA-256 hash. Any later change to the file breaks the hash.
Each sealed document carries a certificate listing every signer, their email and IP address, and the exact timestamps for viewing, consenting, and signing.
Every event — sent, opened, consented, reminded, signed, completed, sealed — is logged to an immutable timeline for a complete evidentiary record.
Documents are stored on private object storage, never publicly accessible, and streamed only through authenticated, per-recipient links.
Each recipient gets a unique, unguessable signing link. Links expire when you set a deadline and stop working once a document is voided or completed.
Single active session per account prevents credential sharing, and every sensitive action is scoped to your team.