Intent to sign
A signer places their own signature into a field that was drawn for them and then submits it deliberately. Nothing is pre-filled, nothing is signed on their behalf, and closing the tab signs nothing.
Anyone can email a PDF and hope. What makes a signature enforceable is the evidence attached to it, so here is precisely what gets recorded, how it is sealed, and how you can check it without taking our word for anything.
In the United States an electronic signature has the same standing as a pen-and-ink one when four conditions hold. Each is answered by a step in the product, not by a claim on this page.
A signer places their own signature into a field that was drawn for them and then submits it deliberately. Nothing is pre-filled, nothing is signed on their behalf, and closing the tab signs nothing.
A recipient consents explicitly before a single field opens, and that consent is written into the audit trail as its own event with its own timestamp. It is a step in the flow, not a line of small print under a button.
Each signature is bound to the exact field, on the exact page, at the exact coordinates it was placed on. When the envelope completes, those values are flattened into the page itself rather than layered over it.
The completed document, its certificate of completion and its full audit trail stay in the account and stay downloadable, including after a subscription ends. Everyone entitled to the record can reproduce it.
The same four conditions underpin simple electronic signatures under eIDAS in the EU and the UK. This page describes how the product works and is not legal advice; whether a particular document may be signed electronically at all is a question for your own counsel.
Every event closeit.fast is capable of recording, written the moment it happens.
Who caused the event, by name and email address where one is known.
The address the request arrived from.
The browser and operating system that made the request.
A UTC timestamp written when the event happened, not when it was read.
When the final signature lands, the whole trail is rendered into a certificate of completion and appended to the document as its last page, so the evidence travels with the file rather than living in an account somebody has to still have access to.
The seal is a plain SHA-256 digest of the finished file, so checking it needs nothing from us and no software you do not already have.
Open the envelope in your dashboard and download the completed PDF. Its last page is the certificate of completion, and the digest is shown alongside the envelope.
macOS or Linux
shasum -a 256 agreement.pdfWindows
certutil -hashfile agreement.pdf SHA256They match character for character, or the file in your hands is not the file that was signed. There is no third outcome, and no interpretation involved.
How a file is stored, who can reach it, and what happens to it afterwards.
Uploaded and completed documents are encrypted with AES-256-GCM before they are written, and the key for each one is held separately from the file. Nothing is served straight from a bucket: every read goes through an authenticated route, and a stored file on its own is unreadable.
A recipient is identified by a unique token rather than a shared password or a link you forward. The token opens one envelope for one person and nothing else in the account.
The finished PDF is hashed the moment it is sealed and the digest is stored next to the envelope. Change one byte of the file and it stops matching the record — which is what makes the trail evidence rather than a log.
Audit entries are written as events occur and there is no edit path to them, for you or for us. Delete an envelope and the file goes; the record that it was deleted stays, because a record you can quietly erase is not a record.
Every gap below is real. You would find each of them during procurement anyway, and finding one after an inflated claim is what ends an evaluation.
Neither audit has been carried out. If your procurement process requires one, we do not have it and cannot supply a bridge letter.
closeit.fast is not set up to handle protected health information and we will not sign a BAA. Do not put PHI through it.
Under eIDAS these are simple electronic signatures. They are not advanced or qualified signatures: there is no certificate issued to the signer and no qualified trust service provider involved.
Access is proved by a unique link emailed to one address, not by a passport. That shows the signer received the message sent to that address; it does not prove who they are, and a forwarded link carries its access with it. If your use case needs proof of who a person is rather than proof of what they did, it needs an identity provider in front of the signing step.
There is no remote online notarisation, no notary session and no witnessing. Documents that legally require a notary are not documents this tool can finish.
If something here is a blocker for your team, say so before you build a process around it. Reply to any closeit.fast email and it reaches a person.
Upload a PDF, place the fields, send the links — and get back a sealed document with a certificate of completion attached to the end of it.
One free envelope every monthNo card, no sales call, no per-signature fee