US electronic signature law

Electronic signatures under ESIGN & UETA.

Docracy SES e-signatures are designed to support the U.S. ESIGN Act and Uniform Electronic Transactions Act for everyday business documents — with an honest audit trail, not overclaimed certifications.

What ESIGN and UETA look for

These U.S. frameworks generally give electronic signatures legal effect when parties do business electronically in good faith. In practice, that means consent, intent to sign, and a retainable record — not a specific vendor seal.

  • Consent to do business electronically
  • Clear intent to sign the electronic record
  • A record that can be retained and accurately reproduced

Why a simple signature is enough under UETA specifically → · How Docracy meets UETA's requirements →

What Docracy provides

Built for SES-style signing chains — free for up to two signers, no account required to start.

Consent acknowledgment

Signers check an acknowledgment before completing — recorded as a consent event in the audit trail.

Email attribution

Each signer is invited by email (optional SMS in the US on paid). The link is HMAC-signed — not a guessable password.

Optional signing PIN

Paid workspaces can add a PIN on signing links for an extra shared-secret step.

Timestamped audit trail

View, consent, sign, and decline events capture timestamp, IP, and user-agent.

Content hashes

Cryptographic hashes of document content at key points help show the record stayed intact.

Certificate of completion

When the chain finishes, parties get a signed PDF plus a completion certificate summarizing the trail.

Beyond SES: Advanced Electronic Signature via WhatsApp

ESIGN and UETA only require consent, intent, and a retainable record — the SES model above already clears that bar. Paid and Enterprise accounts can go further: WhatsApp-verified signing binds the link to a specific phone number and requires a PIN before signing, designed to meet the EU eIDAS criteria for an Advanced Electronic Signature (AES) — a stronger standard than U.S. federal law requires.

  • Uniquely linked to and capable of identifying the signatory — the link only reaches that signer's own WhatsApp number.
  • Created under the signatory's sole control — a preparer-set PIN is required, not optional, on every WhatsApp-delivered link.
  • Detectably linked to the signed data — the same SHA-256 hash chain and audit trail as every Docracy document.
  • Backed by delivery and read receipts, recorded in the audit trail alongside the signature.

This is a self-declared AES-track design, not a certified Qualified Electronic Signature (QES) — we're not a Qualified Trust Service Provider (QTSP). See Trust & security for the full picture.

How WhatsApp signing works → · More on Advanced Electronic Signature (AES) →

Honest limits

By default (free tier, no WhatsApp), this is simple electronic signature (SES) only — Docracy does not verify signer identity, and anyone with the link can sign as the name on it. Docracy does not offer Qualified Electronic Signatures (QES) on any plan, and doesn't claim third-party certification for the WhatsApp AES-track option above. For contracts that need identity-verified or certified signatures, use a compliance-grade provider. This page is not legal advice.

Common questions

Are Docracy signatures ESIGN / UETA compliant?

Docracy SES workflows are designed to support the U.S. ESIGN Act and UETA for many everyday business documents (consent, intent, retainable audit record). We use careful “designed to support / consistent with” language — not a certification that every document type is enforceable everywhere.

Do you verify who signed?

No. The audit trail proves what was signed and when, not who physically signed. Identity verification is out of scope for Docracy.

Is this AES or QES?

Not by default — the free tier is SES (simple electronic signature) only. Paid and Enterprise accounts can turn on WhatsApp-verified signing, designed to meet the EU eIDAS criteria for an Advanced Electronic Signature (AES): phone-bound delivery, a required PIN, and a tamper-evident record. It's still not a Qualified Electronic Signature (QES) — we're not a Qualified Trust Service Provider (QTSP) and haven't sought third-party AES certification.

Where can I read the full security posture?

See Trust & security for encryption, retention, subprocessors, Cloudflare infrastructure certifications, and the security questionnaire.

More detail: Trust & security · Pricing · Start free

Send your first document free — no account needed.

Start free — send a document →