Security that
shows its work
LedgerSign is built so you never have to take our word for it. Every document carries its own evidence: a consent record, an audit trail, and a fingerprint on a public blockchain.
Legally sound from the first click
Consent is captured, versioned, and preserved before a single field is filled.
ESIGN & UETA consent
Before anyone signs, LedgerSign captures their consent to use electronic records and signatures, as the ESIGN Act and UETA require.
Disclosure versioning
We record which version of the electronic-records disclosure each signer accepted, so you can show exactly what they agreed to.
Certificate of Completion
Every completed document ships with a certificate generated directly from the audit record.

The Certificate of Completion, generated from the audit record
An audit trail that cannot be edited
Every action on a document is logged: who did it, when, from which IP address, and with which browser. The log is append-only, and the Certificate of Completion is generated from it, not from anything a user can touch.
- Actor, timestamp, IP address, and user agent on every event
- Covers creation, sending, viewing, signing, and completion
- Append-only: nothing is rewritten after the fact
- Exportable for reviews and disputes

From the product: a document's audit timeline
Proof that lives outside our servers
On completion, the signed document is hashed with SHA-256 and the hash is anchored on Hedera, a public blockchain. The transaction id is yours to keep. Anyone can re-hash the document and check it against the on-chain record, with or without us.
- SHA-256 fingerprint of the final signed PDF
- Anchored on Hedera with a public transaction id
- Timestamped and permanent once written
- Independently verifiable by any third party
Anchor record
- network
- hedera
- transaction
- 0.0.481…@1753…
- anchored
- 2026-07-24 14:02:14 UTC
- status
- ✓ verifiable
Protected at rest, in transit, and at sign-in
Encrypted storage
Documents are stored encrypted on AWS S3.
Time-limited access
Files are served through presigned URLs that expire.
TLS in transit
Every connection to LedgerSign is encrypted with TLS.
AWS Cognito authentication
Account sign-in is handled by AWS Cognito.
Four roles, clear boundaries
Every member of your organization gets exactly the access their role requires.
| Role | Access |
|---|---|
| Owner | Full control of the organization, including billing and deletion. |
| Admin | Manages documents, templates, and members. No billing access. |
| Member | Creates and sends documents, uses templates. |
| Viewer | Read-only access. Useful for auditors and reviewers. |
Questions about our security practices?
Talk to our teamMake your next signature
impossible to dispute
Start free and send your first blockchain-verifiable document in minutes.
No credit card required · Free plan includes 5 documents to try · Cancel anytime