Contracts & e-signature

E-signature legal basis and security

How Workspace369 contracts record consent, intent, and attribution, which e-signature laws and standards the design follows, and how signing data is protected.

View as Markdown

This article describes how the Contracts feature works. It is not legal advice. Whether a particular agreement can be signed electronically depends on the agreement and the jurisdiction, so check with your own legal adviser for anything unusual.

What kind of signature this is

Recipients sign with a simple electronic signature: a drawn or typed signature adopted on the signing page, backed by a record of who signed, how they were verified, what they agreed to, and when. Workspace369 then seals the completed document with its own digital seal so that later changes are detectable.

The seal is designed to meet the requirements for an advanced electronic seal. It is not a qualified electronic seal, and Contracts does not offer qualified electronic signatures or identity-document checks.

Laws the design follows

LawWhat it asks forHow Contracts provides it
US ESIGN Act, consumer consentInformed consent to electronic records before signingA versioned disclosure the recipient agrees to before any field can be filled. It covers the right to a paper copy, how to withdraw, and what is needed to access the records. The version agreed to is recorded.
UETA, intent to signA clear act showing the person meant to signThe recipient adopts a signature, then selects Sign and finish next to a statement of intent.
UETA, attributionEvidence linking the signature to the personA link issued to that recipient only, an email code or in-person identity check, and the IP address, browser and server time of every step in a chained audit trail.
ESIGN and UETA, record retentionRecords that can be kept and reproduced accuratelyThe sealed PDF is emailed to every recipient and kept with a protected evidence copy.
EU eIDAS Article 25Electronic signatures cannot be refused as evidence only because they are electronicThe same evidence as above.

What is recorded for every contract

  • The document fingerprint when it was sent, checked again whenever it is viewed, signed and sealed.
  • For each recipient: how they were verified, when they consented and to which disclosure version, when they were invited, opened the contract, verified and finished, and the IP address and browser used.
  • For in-person signing: the member who hosted it and the type of ID they checked. ID numbers are never recorded.
  • Every event in order, each linked to the one before it by a hash, so removing or editing an event breaks the chain.

The Certificate of Completion and the evidence file inside the sealed PDF carry this record up to the moment of sealing.

Standards

StandardUse in Contracts
ISO 32000-2The digital signature format inside the PDF.
ETSI EN 319 142-1 (PAdES)The seal level, PAdES baseline B-LTA, with trusted timestamps and long-term validation data.
ISO 14533-3The long-term signature profile the B-LTA level follows.
ISO 19005-3 (PDF/A-3b)The standalone Certificate of Completion.
ISO/IEC 27001:2022 Annex AThe security controls are mapped to Annex A. Workspace369 is not certified to ISO/IEC 27001.
WCAG 2.2 AAThe accessibility target for the signing page.

How signing data is protected

  • Signing links and verification codes are random and stored only as one-way hashes, and codes expire after 10 minutes.
  • Signing sessions last at most 30 minutes idle and 4 hours in total, and are kept only in the browser tab.
  • Nothing about the document is shown before the recipient verifies and consents.
  • Uploaded PDFs that contain scripts are refused, and the signing page opens documents with scripting and forms turned off.
  • Contract files are never publicly linked. Downloads use links that expire after 10 minutes.
  • The seal key is held in a hardware security module and cannot be exported.
  • Verification codes, links, field values and document content are never written to logs.

Retention and deletion

Ended contracts are kept for 7 years by default. The workspace owner can choose from 1 to 10 years. The evidence copy of each sealed contract is locked until that date and cannot be deleted sooner. After the period has passed, the owner can permanently delete a contract: the document, signatures and values are removed, while the seal record and event history remain so the verify page can still confirm the file was issued.

What Contracts does not do

  • Qualified electronic signatures, or checking government ID documents.
  • Verification codes by text message.
  • Taking payments during signing.
  • Notarization or witnessing.

Was this article useful?

Your answer helps us decide what to clarify next.