Security & evidence
E-Signature Audit Trail
Every signature leaves a complete evidence chain
WPsigner records who signed, when, where, and how — with timestamps, IP addresses, device data, and SHA-256 document hashes that stay on your server.
Actions, timestamps, IP, hash — exportable Certificate of Completion
What the audit trail captures
More evidence than most SaaS platforms — and none of it leaves your WordPress server.
Full action logging
Opened, viewed, signed, declined — every step is recorded with precision.
Identity & location signals
IP address, device and browser info, plus optional geolocation for high-security workflows.
Integrity fingerprint
SHA-256 hashing and tamper detection prove the document was not altered after signing.
How the evidence chain builds
The trail starts when you create the document and ends with a sealed Certificate of Completion.
- 1
Document created
Creation time, uploader identity, and the initial document hash are recorded.
- 2
Invitation sent
Each signer invitation logs email, send time, and the unique access link.
- 3
Signer actions tracked
Opening the link, viewing pages, filling fields, and signing — each with timestamp, IP, and device info.
- 4
Document sealed
When all parties sign, WPsigner seals the PDF with SHA-256 and generates the Certificate of Completion.
Certificate of Completion
Download a PDF that summarizes the full audit trail alongside the signed document — ready for disputes, compliance reviews, or long-term archiving.
- All signer actions with timestamps
- IP addresses and device / browser strings
- Document SHA-256 hash for integrity checks
- Stored on your self-hosted WordPress server
Evidence included
- Who signed and in which order
- When each action occurred
- Where (IP and optional geolocation)
- What device and browser were used
- Cryptographic hash of the final document
Where audit trails matter most
Legal disputes
Show a clear chain of custody if a signature is challenged in court.
Regulated industries
Finance, healthcare, and HR workflows that need attribution evidence.
Enterprise contracts
High-value agreements where incomplete logs create unnecessary risk.
Internal audits
Export Certificates of Completion for compliance and retention policies.
Frequently asked questions
What is an e-signature audit trail?
An audit trail is a comprehensive log of every action during document signing — who signed, when, their IP address, device information, and a cryptographic hash of the document. It creates a chain of evidence that supports authenticity and integrity.
Are audit trails legally required?
They are not always mandated by statute, but they are best practice. Under the ESIGN Act and eIDAS, attributing a signature to a specific person is essential — audit trails provide that attribution if a signature is challenged.
Can I download the audit trail?
Yes. WPsigner generates a Certificate of Completion PDF for every signed document, including signer actions, timestamps, IP addresses, and the SHA-256 hash. Store it with the signed PDF.
How does document hashing work?
When a document is signed, WPsigner generates a SHA-256 hash of its contents. If even a single byte changes later, the hash changes completely — making post-signing tampering detectable.
Where is the audit trail stored?
On your WordPress server with the rest of your WPsigner data. It is not sent to a third-party SaaS vault unless you optionally configure your own backups.
Does every plan include audit trails?
Yes. Full audit trails with timestamps, IP logging, and SHA-256 hashing are included on every WPsigner plan.
Get complete audit trails on WordPress
Every WPsigner plan includes full evidence logging — timestamps, IP addresses, device data, and SHA-256 document hashing.
Stop paying per envelope
Choose an annual or lifetime license with unlimited documents and no per-envelope fees. Keep control of your data and signing workflows.