Skip to main content
NEW Didit KYC Identity Verification is live, verify signers with government ID & biometrics for eIDAS Advanced signatures Learn more

Security & integrity

Document Security

Tamper-proof documents that never leave your server

WPsigner seals every signed PDF with SHA-256 hashing, encrypts data in transit and at rest, and keeps full sovereignty on your self-hosted WordPress stack.

SHA-256 seal · TLS in transit · encrypted at rest · your server

Security that stays under your control

Cloud e-signature vendors hold your files. WPsigner keeps documents, signatures, and hashes on infrastructure you operate.

SHA-256 document hashing

Every signed document gets a unique cryptographic fingerprint. A one-byte change is instantly detectable.

Encryption end to end

TLS 1.2+ in transit and encrypted storage at rest — even direct database access does not expose plaintext files.

Self-hosted sovereignty

No mandatory third-party document vault. Optional cloud backups stay under your configuration.

How document protection works

Integrity checks and access controls run alongside the signing flow — not as an afterthought.

  1. 1

    Hash on create and seal

    WPsigner fingerprints the document and refreshes the hash when the signed PDF is sealed.

  2. 2

    Encrypt and restrict access

    Files are stored encrypted on your server. WordPress roles control who can create, view, edit, or delete.

  3. 3

    Log every access

    Views, downloads, and admin actions are logged with IP, user agent, and timestamp for forensics.

  4. 4

    Detect tampering

    Any post-signing modification invalidates the hash. PDF readers warn when a sealed signature is broken.

Built for GDPR-friendly control

Because WPsigner is self-hosted, you decide where data lives, how long it is retained, and who can access it — you remain controller and processor of your signing data.

  • Documents stay on your WordPress server
  • Role-based permissions via WordPress roles
  • Secure delete removes files, signatures, and related audit data
  • Optional backups (Drive, S3, etc.) only if you configure them
Read legal compliance →

Protection layers

  • SHA-256 fingerprint in the audit trail
  • Tamper-proof sealed PDFs
  • Encrypted at rest and in transit
  • IP access logging for every view and download
  • Secure delete of associated signing artifacts

Where document security matters

Confidential contracts

NDAs, M&A packs, and vendor agreements that cannot sit in a shared SaaS vault.

Regulated data

Healthcare, finance, and public-sector workflows that require residency and access control.

Internal policies

HR and legal teams that need clear retention, deletion, and auditability.

Customer trust

Tell clients their signed files never leave infrastructure you operate.

Frequently asked questions

How does SHA-256 hashing protect documents?

SHA-256 generates a unique fingerprint of the document’s binary content. After signing, that hash is stored in the audit trail and tied to the sealed PDF. If anyone changes even a single character, the hash changes completely — proving tampering.

Where are my documents stored?

Exclusively on your WordPress server by default. WPsigner does not send or sync documents to an external vault. Optional cloud backups (Google Drive, S3, etc.) are under your control.

Is WPsigner GDPR compliant?

Self-hosting keeps personal data under your control: you decide storage location, retention, and access. That makes GDPR compliance straightforward because you remain data controller and processor for signing data on your site.

Can I audit who accessed a document?

Yes. WPsigner logs views, downloads, signature actions, and admin operations with timestamp, user identity, IP address, and user agent — available in the audit trail and exportable.

What happens when I delete a document?

Secure delete permanently removes associated files, signatures, and related audit trail data from your server according to your retention settings.

Are PDFs tamper-proof after signing?

Signed documents are sealed so PDF readers can warn if the file is modified after signing. Combined with SHA-256 hashing, alterations are detectable.

Keep signed documents under your control

SHA-256 hashing, encryption, and self-hosted storage — without handing your contracts to a third-party cloud.

Unlimited Usage · Self-Hosted

Stop paying per envelope

Choose an annual or lifetime license with unlimited documents and no per-envelope fees. Keep control of your data and signing workflows.