Skip to content
Security and compliance

The record standing behind the signature

Anyone can email a PDF and hope. What makes a signature enforceable is the evidence attached to it, so here is precisely what gets recorded, how it is sealed, and how you can check it without taking our word for anything.

The trail

Nothing is reconstructed afterwards

Every event closeit.fast is capable of recording, written the moment it happens.

  • Envelope created
  • Document uploaded
  • Document replaced
  • Document removed
  • Sent for signature
  • Invitation resent
  • New signing link issued
  • Next signer notified
  • Envelope voided
  • Email address verified
  • Document viewed
  • Consented to electronic signing
  • Signature completed
  • Signing declined
  • All signatures collected
  • Signed document emailed to all parties

Actor

Who caused the event, by name and email address where one is known.

IP address

The address the request arrived from.

User agent

The browser and operating system that made the request.

Timestamp

A UTC timestamp written when the event happened, not when it was read.

When the final signature lands, the whole trail is rendered into a certificate of completion and appended to the document as its last page, so the evidence travels with the file rather than living in an account somebody has to still have access to.

Check it yourself

The seal is a plain SHA-256 digest of the finished file, so checking it needs nothing from us and no software you do not already have.

  1. 1. Download the sealed document

    Open the envelope in your dashboard and download the completed PDF. Its last page is the certificate of completion, and the digest is shown alongside the envelope.

  2. 2. Hash the file on your own machine

    macOS or Linux

    shasum -a 256 agreement.pdf

    Windows

    certutil -hashfile agreement.pdf SHA256
  3. 3. Compare the two digests

    They match character for character, or the file in your hands is not the file that was signed. There is no third outcome, and no interpretation involved.

Documents

Handling and access

How a file is stored, who can reach it, and what happens to it afterwards.

Encrypted before it is stored

Uploaded and completed documents are encrypted with AES-256-GCM before they are written, and the key for each one is held separately from the file. Nothing is served straight from a bucket: every read goes through an authenticated route, and a stored file on its own is unreadable.

Single-use recipient links

A recipient is identified by a unique token rather than a shared password or a link you forward. The token opens one envelope for one person and nothing else in the account.

Sealed with SHA-256

The finished PDF is hashed the moment it is sealed and the digest is stored next to the envelope. Change one byte of the file and it stops matching the record — which is what makes the trail evidence rather than a log.

Append-only by construction

Audit entries are written as events occur and there is no edit path to them, for you or for us. Delete an envelope and the file goes; the record that it was deleted stays, because a record you can quietly erase is not a record.

What we do not claim

Every gap below is real. You would find each of them during procurement anyway, and finding one after an inflated claim is what ends an evaluation.

  • No SOC 2 or ISO 27001 report

    Neither audit has been carried out. If your procurement process requires one, we do not have it and cannot supply a bridge letter.

  • No HIPAA business associate agreement

    closeit.fast is not set up to handle protected health information and we will not sign a BAA. Do not put PHI through it.

  • Simple electronic signatures only

    Under eIDAS these are simple electronic signatures. They are not advanced or qualified signatures: there is no certificate issued to the signer and no qualified trust service provider involved.

  • No identity document verification

    Access is proved by a unique link emailed to one address, not by a passport. That shows the signer received the message sent to that address; it does not prove who they are, and a forwarded link carries its access with it. If your use case needs proof of who a person is rather than proof of what they did, it needs an identity provider in front of the signing step.

  • No notarisation

    There is no remote online notarisation, no notary session and no witnessing. Documents that legally require a notary are not documents this tool can finish.

If something here is a blocker for your team, say so before you build a process around it. Reply to any closeit.fast email and it reaches a person.

Your first envelope is three minutes away.

Upload a PDF, place the fields, send the links — and get back a sealed document with a certificate of completion attached to the end of it.

One free envelope every monthNo card, no sales call, no per-signature fee