Skip to main content
NEW Didit KYC Identity Verification is live, verify signers with government ID & biometrics for eIDAS Advanced signatures Learn more
🛡️ Compliance guidance & evidence controls

Electronic Signature Compliance for WordPress

WPsigner provides technical controls that can support legally enforceable electronic-signature workflows, including when a signer or operator uses the WPsigner mobile app connected to your WordPress site. Validity depends on the transaction, configuration, evidence, parties, and applicable law.

ESIGN Act
UETA
eIDAS / eIDAS 2.0
Audit trails
RFC 3161
PKI

Shared responsibility

Compliance depends on the complete workflow

WPsigner supplies product controls. The site owner decides how they are configured, which third parties receive data, and whether the process meets the law for a specific transaction.

WPsigner provides

  • Intent, consent and signer-event records
  • Document hashing and change detection
  • Audit trail and evidence export
  • Optional identity, timestamp and PKI controls
  • Self-hosted storage by default

Your organization controls

  • Legal basis and suitability of e-signatures
  • Signer identification and authentication policy
  • Hosting, TLS, access, backups and incident response
  • Retention, deletion and data-subject requests
  • DPAs, BAAs and external integration settings

Legal framework support

These laws define when electronic records and signatures can be recognized. WPsigner supplies evidence controls; it does not replace legal review or customer-side procedures.

🇺🇸

ESIGN Act

United States

Workflow controls available Framework since 2000

Electronic Signatures in Global and National Commerce Act. Federal law that grants legal recognition to electronic signatures and records.

  • Intent and consent evidence
  • Signer attribution records
  • Document integrity controls
  • Retention and export support
🇺🇸

UETA

49 states, DC & U.S. Virgin Islands

Workflow controls available Framework since 1999

Uniform Electronic Transactions Act. It provides a state-level framework for electronic records and signatures. New York uses its own Electronic Signatures and Records Act instead.

  • State-level enforcement
  • Electronic records validity
  • Attribution methods
  • Retention and production
🇪🇺

eIDAS / eIDAS 2.0

European Union

Workflow controls available Framework since 2014 / 2024

Regulation (EU) No 910/2014, as amended by Regulation (EU) 2024/1183, establishes the EU framework for electronic identification, signatures and trust services.

  • Simple Electronic Signature workflows
  • Identity assurance that can support AdES implementations
  • Cross-border trust-services framework
  • QES requires a qualified provider and device

eIDAS signature levels

SES, AdES and QES are not interchangeable

The required level depends on the transaction and jurisdiction. Identity verification alone does not automatically turn an electronic signature into AdES or QES.

SES WPsigner core workflow

Simple Electronic Signature

Electronic data used by a signer to sign. Common business agreements can use SES when the process captures intent, consent, attribution and reliable evidence.

AdES Implementation dependent

Advanced Electronic Signature

Must be uniquely linked to and capable of identifying the signer, remain under the signer's control, and make later changes detectable. KYC can support identity assurance but is only one part.

QES Qualified provider required

Qualified Electronic Signature

An AdES created with a qualified signature-creation device and based on a qualified certificate from a qualified trust service provider. WPsigner does not itself issue QES certificates.

Choose the signature level with qualified legal counsel for high-risk, regulated or cross-border transactions.

Evidence and security controls

Technical controls help preserve intent, attribution and document integrity. Their legal effect depends on how each workflow is configured and operated.

Digital ID (PKI)

Upload your organization's .p12/.pfx digital certificate. Documents are signed with your organization's verified identity, visible in Adobe Reader.

Learn more

RFC 3161 Timestamping

Documents receive cryptographically secure timestamps from trusted Time Stamp Authorities, proving exactly when signatures occurred.

Learn more

SHA-256 Hashing

Every document is hashed using SHA-256 algorithm. Any tampering is immediately detectable and invalidates the document.

Learn more

Complete Audit Trail

Every action is logged: IP address, geolocation, user agent, timestamp, and consent records. Exportable for legal proceedings.

Learn more

Self-Hosted Data

Documents remain on your WordPress infrastructure by default. Data may be shared when you explicitly configure external storage, CRM, messaging, KYC, payment or automation services.

Learn more

AATL Certificates

Use a compatible Adobe Approved Trust List certificate. Adobe Reader trust status depends on the certificate chain, configuration and validation environment.

Learn more

KYC Identity Verification

Add government ID checks, facial biometrics and liveness detection before signing. This can support signer identification in an AdES implementation but does not establish AdES by itself.

Learn more

Complete Audit Trail

Each signing workflow can produce an exportable evidence record. Admissibility and evidentiary weight remain subject to the facts, applicable law and court or regulator.

📍

IP Address

Client IP captured at signing time

🌍

Geolocation

Country and city when available

🖥️

Device Info

Browser, OS and device metadata

Timestamps

Precise UTC timestamps for all actions

Consent Records

When user agreed to terms

🔐

Authentication

How signer was verified

Review audit trail documentation
audit_trail.json
{
  "document_id": "DOC-2026-001",
  "signer": {
    "name": "John Smith",
    "email": "john@example.com"
  },
  "signature_event": {
    "type": "signed",
    "timestamp": "2026-07-22T14:32:18Z",
    "ip_address": "203.0.113.42",
    "geolocation": {
      "country": "United States",
      "city": "New York"
    },
    "device": {
      "browser": "Chrome 120.0",
      "os": "Windows 11",
      "screen": "1920x1080"
    },
    "consent_accepted": true,
    "consent_timestamp": "2026-07-22T14:31:55Z"
  },
  "hash": "sha256:a1b2c3d4e5f6..."
}

Compliance considerations

A WordPress plugin cannot make an organization compliant by itself. These frameworks require customer-side governance, configuration, risk assessment and documentation.

HIPAA

Customer action required

Health Insurance Portability and Accountability Act

WPsigner can contribute technical safeguards such as audit logs and access controls, but it is not HIPAA-certified. Covered entities and business associates must perform their own risk analysis and arrange any required BAAs with service providers handling ePHI.

SOC 2

Customer action required

System and Organization Controls

Product security features may support an organization's control environment, but they do not constitute a SOC 2 examination or report. Do not represent a deployment as SOC 2 compliant without the relevant independent audit.

ISO 27001

Customer action required

Information Security Management

WPsigner can be used within an ISO 27001-aligned ISMS, but the plugin is not an ISO 27001 certification. Certification applies to a defined organizational scope and requires an accredited audit.

GDPR

Customer action required

General Data Protection Regulation

Self-hosting supports data control but does not guarantee GDPR compliance. The site operator remains responsible for lawful basis, transparency, retention, data-subject rights, security, processor agreements and configured external services.

Official sources and regional guidance

Use primary legal sources and obtain qualified advice for your transaction and jurisdiction.

Legal content reviewed: July 22, 2026

This page provides general product and regulatory information, not legal advice. Laws and technical requirements change; consult qualified counsel before relying on electronic signatures for regulated or high-risk transactions.

Electronic signature compliance questions

Does WPsigner guarantee that every electronic signature is legally binding?

No software can guarantee validity for every transaction. WPsigner provides controls for intent, consent, attribution, integrity and evidence, while enforceability depends on the document, parties, process, configuration and applicable law.

Does Didit KYC automatically make a signature eIDAS Advanced?

No. KYC can support the identification requirement, but AdES also requires a unique link to the signer, signer control and detectable changes to the signed data. The complete implementation must be assessed.

Is WPsigner HIPAA-certified or SOC 2 certified?

WPsigner does not claim HIPAA certification, a SOC 2 report or ISO 27001 certification. Its controls may support a customer's compliance program, but the organization remains responsible for risk analysis, configuration, contracts and audits.

Do documents always remain inside WordPress?

They remain on your WordPress infrastructure by default, including documents created or completed through the mobile app. Data may leave the site when you enable an external provider for storage, CRM, messaging, identity verification, payment or automation.

Build an evidence-ready signing workflow

Review the technical controls, test the signing experience and configure WPsigner for your legal and operational requirements.