How Docracy meets UETA's requirements, section by section.

Not a marketing claim — an actual walkthrough of which part of Docracy's signing flow satisfies which part of UETA.

Sign a document

Consent to sign electronically (UETA §5)

UETA requires that parties agree to conduct the transaction electronically. Docracy makes signers explicitly acknowledge and consent before they can sign — this isn't implied just by opening the link.

Intent to sign (UETA §2, §7)

UETA requires a clear signing action, not passive agreement. Signers actively draw or type their signature and submit it — a deliberate act, not a default or pre-filled state.

Attribution (UETA §9)

Docracy's audit trail records the signer's email, IP address, and timestamp for every action in the chain, plus — optionally — a PIN the preparer sets that the signer must enter. Together, that's the kind of circumstantial record UETA §9 treats as sufficient to attribute a signature to a specific person.

Record integrity and retention (UETA §12)

Every completed document gets a SHA-256 hash — change even one character afterward and the hash no longer matches, so tampering is immediately detectable. That hash is also anchored to the Bitcoin blockchain for free via the OpenTimestamps protocol, and a certificate of completion is generated alongside the signed PDF, so the record stays both accurate and independently verifiable.

What this doesn't cover

UETA doesn't require identity verification, and neither does Docracy's default signature (a Simple Electronic Signature). If a document needs stronger signer-identity assurance, paid accounts can add a WhatsApp-verified signature track designed to meet the EU eIDAS Advanced Electronic Signature (AES) bar — see Trust & security for exactly what that does and doesn't prove. Docracy is not a Qualified Trust Service Provider and doesn't issue Qualified Electronic Signatures (QES).

FAQ

Does Docracy verify who's actually signing?

Not by default — Docracy's Simple Electronic Signature proves what was signed and when, not who physically signed. Paid accounts can add WhatsApp-verified signing for stronger identity assurance.

Is Docracy's audit trail enough to satisfy UETA's attribution requirement?

For the everyday business documents UETA covers, the audit trail (email, IP, timestamp, optional PIN) is the kind of circumstantial evidence UETA §9 treats as sufficient — though this isn't a substitute for your own legal advice on a specific document.

What happens to my document after everyone signs?

Docracy generates a hash-verified, tamper-evident PDF and certificate of completion, deletes the working copy after a short retention window (free tier: 9 days), and keeps a hash-based verification record indefinitely so the document can still be checked long after it's gone.

Does this apply in New York?

New York hasn't adopted UETA — it uses its own Electronic Signatures and Records Act (ESRA), which sets a broadly similar bar. This page isn't legal advice about which law applies to your specific document.

Why a simple signature is enough under UETA · ESIGN Act & UETA overview · Trust & security

Free to start — no account needed to send or sign.

Sign a document