Skip to content

They say they never signed it. What happens next?

The most useful thing an audit trail does is answer a question nobody wants to be asked. Here is how a disputed electronic signature is actually resolved, which statute decides it, and what your record has to be able to show.

Legality11 min read
A single sheet of cream paper with five small paper evidence tags fanned beneath it, each attached by a fine thread, photographed from above in hard raking light.

Almost everything written about electronic signatures answers a question that was settled twenty-five years ago: are they legal? They are. The question that actually decides cases is a different one, and it gets far less attention.

It is this. The document is signed. Months later the other side says: that was not me.

What the statute actually settles, and what it leaves open

The federal E-SIGN Act was enacted on 30 June 2000 and took effect on 1 October 2000. It is codified at 15 U.S.C. §§ 7001–7031. The sentence everyone quotes is § 7001(a), and it says a signature or contract may not be denied legal effect, validity, or enforceability solely because it is in electronic form.

Read that carefully, because the operative word is solely. The statute removes exactly one objection: that the signature was electronic. It does not make an unauthenticated signature enforceable. It does not shift the burden of proof. It does not say anything at all about whether the person you think signed is the person who signed.

Almost every vendor page blurs this, because the blurred version is a better sales line. The precise version is more useful to you.

The real question is attribution

Alongside E-SIGN sits the Uniform Electronic Transactions Act, promulgated in 1999 and now adopted in 49 states plus the District of Columbia, Puerto Rico and the US Virgin Islands. New York is the sole holdout and runs its own statute, the Electronic Signatures and Records Act, at Article 3 of the State Technology Law.

UETA is where the argument actually happens. Two sections matter.

§ 2(8) defines an electronic signature as an electronic sound, symbol, or process attached to or logically associated with a record and executed or adopted by a person with the intent to sign the record. Intent is the operative element, not the technology. A typed name with intent is a signature. A cryptographic key applied by accident is not.

§ 9 is the one to know by heart. An electronic signature is attributable to a person if it was the act of that person, and that act may be shown in any manner, including a showing of the efficacy of any security procedure applied.

That clause is the entire legal reason an audit trail exists. It is the statutory hook that turns a log file into evidence.

Note what § 9 does not do. It does not presume the signature was that person's act. It tells you what kind of showing is available once somebody puts it in issue.

What that looks like when it is tested

The case worth reading is Ruiz v. Moss Bros. Auto Group, Inc., 232 Cal. App. 4th 836 (2014). An employer tried to compel arbitration on the strength of an electronically signed agreement. The employee said he did not recall signing it.

The employer filed a declaration stating that the employee had signed. The court held that was not enough. Once the signature is genuinely disputed, the party relying on it carries the burden of showing the signature was the act of that person, and a conclusory assertion does not discharge it. A username and password alone did not carry it either.

The lesson is not that electronic signatures are weak. It is that the signature is not the evidence. The record around it is. The party who can describe their process in detail wins that argument. The party who can only assert loses it.

What your record needs to be able to say

If you are ever the party holding the document, these are the things you will be asked to demonstrate, and they map exactly onto what a trail should be recording as it happens:

  • That this specific person was sent this specific document, and when.
  • That the invitation went to an address they controlled, and that it was opened from somewhere.
  • That they were shown the document before any field became signable.
  • That they consented to sign electronically as a distinct, timestamped step rather than a line of small print.
  • That the signature was placed in a specific field, on a specific page, at specific coordinates.
  • That the file has not changed since, and that this can be demonstrated arithmetically rather than asserted.

Every one of those is a fact recorded at the moment it occurred. None of them can be reconstructed afterwards, which is exactly why a record assembled after a dispute begins is worth so much less than one written as the events happened.

Getting the record in front of a court

This is the part that almost no vendor content covers, and it is the part where a hash earns its keep.

Two rules of evidence were added to the Federal Rules on 1 December 2017. Rule 902(13) allows a record generated by an electronic process or system to be self-authenticating, on a certification from a qualified person. Rule 902(14) does the same for data copied from an electronic device or file when it is authenticated by a hash value compared by a qualified person.

Rule 902(14) is, functionally, a rule written for exactly this: a document sealed with a digest that anybody can recompute. Both rules require a written certification and reasonable advance notice to the other side, following the Rule 902(11) procedure. Separately, Rule 901(b)(9) allows authentication by describing a process or system that produces an accurate result.

Self-authenticating means you may not need a live witness to get the record admitted. It does not mean the record wins. Those are different things, and the difference is worth keeping straight.

What none of this does

An audit trail is evidence. It is not a guarantee, and anyone who tells you their trail makes a document court-admissible is describing a decision that belongs to a court, not to a vendor.

Specifically:

  • An IP address identifies a network, at roughly the granularity of an internet provider and a city. It is not a person, and it is trivially changed by a VPN.
  • Control of an email inbox is not identity. It is good evidence that the invited party acted, and it is not proof of who they are.
  • A hash proves a file has not changed since it was sealed. It proves nothing about who signed or whether they meant to.
  • None of it survives a document that never should have been signed electronically in the first place.

On that last point: E-SIGN § 7003 excludes whole categories outright. Wills, codicils and testamentary trusts. State law governing adoption, divorce and other family law. Most of the Uniform Commercial Code. Court orders and official court documents. Utility cancellation notices. Default, foreclosure, repossession and eviction notices under a credit or rental agreement secured by a primary residence. Cancellation of health or life insurance benefits. Product recalls. Documents accompanying the transport of hazardous materials.

If your document is on that list, no amount of audit trail helps. The honest answer is that you need a different instrument, and often a notary.

The short version

Being legal was never the hard part. Being provable is the hard part, and it is decided by what your system recorded at the moment it happened, not by what anyone is willing to assert afterwards.

That is the whole reason closeit.fast writes an entry per event, seals the finished file with SHA-256, and puts the digest where you can check it yourself. Not because it is a nice feature. Because § 9 says the showing may be made in any manner, and this is the manner that holds up.

Try it on a real document

Everything described here is what closeit.fast does on every envelope, including on the free tier. Send one and read the trail it produces.

Start signing free

Your first envelope is three minutes away.

Upload a PDF, place the fields, send the links — and get back a sealed document with a certificate of completion attached to the end of it.

One free envelope every monthNo card, no sales call, no per-signature fee