Skip to main content
NEW Didit KYC Identity Verification is live, verify signers with government ID & biometrics for eIDAS Advanced signatures Learn more

Compliance

Legal Compliance

Legally binding signatures under ESIGN, UETA and eIDAS

Meet US and EU e-signature frameworks with digital certificates, trusted timestamps, long-term validation and HIPAA-ready security — self-hosted on WordPress.

ESIGN · UETA · eIDAS · PKI · RFC 3161 · LTV · HIPAA-ready

Compliance built into every signature

WPsigner combines legal frameworks with cryptographic evidence so signed PDFs stand up to audit, verification and dispute.

ESIGN & UETA

US federal ESIGN Act and state UETA recognition for electronic signatures with equal legal weight to wet ink.

eIDAS levels

Support Simple, Advanced and Qualified paths — including AdES with Didit KYC identity verification before signing.

Cryptographic proof

X.509 PKI signatures, AATL-compatible certificates, RFC 3161 timestamps and Long-Term Validation (LTV).

How compliance evidence is captured

From intent to archive, each signing session produces verifiable artifacts on your WordPress server.

  1. 1

    Capture intent to sign

    Signers review the document and apply a drawn, typed or uploaded signature with clear consent.

  2. 2

    Apply cryptographic controls

    Optional PKI certificates, RFC 3161 timestamps and identity checks strengthen evidential value.

  3. 3

    Embed validation data

    LTV packs certificates, revocation data and timestamps into the PDF so signatures stay verifiable for years.

  4. 4

    Retain the audit trail

    Keep signer identity, IP, timestamps and document hash with the signed PDF for disputes and audits.

HIPAA-ready controls and AdES identity

Healthcare and regulated teams can combine self-hosted storage with security controls, while KYC (government ID, selfie and liveness via Didit) helps reach eIDAS Advanced Electronic Signature (AdES) before signing.

  • ESIGN Act and UETA alignment for US documents
  • eIDAS SES, AdES (with KYC) and QTSP path for QES
  • AATL-compatible certificates for Adobe verification
  • RFC 3161 TSA timestamps embedded in the PDF
  • Long-Term Validation so signatures outlive certificates
Explore compliance →

What compliance covers

  • ESIGN Act compliance
  • UETA compliance across adopting states
  • eIDAS SES / AdES / QES support model
  • PKI digital ID signing (X.509)
  • RFC 3161 trusted timestamping
  • Long-Term Validation (LTV)
  • HIPAA-ready security controls
  • KYC identity verification for AdES

Where legal compliance matters most

US commercial contracts

Rely on ESIGN and UETA for NDAs, sales agreements and service contracts.

EU and cross-border deals

Use eIDAS-aligned flows, including AdES with identity verification when needed.

Healthcare & regulated data

Keep documents on your server with HIPAA-ready security controls.

Long-retention archives

LTV and timestamps keep signatures verifiable after certificates expire.

Frequently asked questions

Are electronic signatures legally binding?

Yes. In the United States, electronic signatures are legally binding under the ESIGN Act (federal) and UETA (state level). In the European Union, the eIDAS Regulation provides a legal framework for electronic signatures. In most jurisdictions, electronic signatures carry the same legal weight as handwritten signatures for the vast majority of documents.

What is the difference between ESIGN and UETA?

The ESIGN Act is a federal law that applies across all US states. UETA is a model state law adopted by 47 states (plus DC and the US Virgin Islands). Both establish that electronic signatures have the same legal standing as handwritten signatures. ESIGN serves as a federal backstop for states that have not adopted UETA.

Does WPsigner support eIDAS compliance?

Yes. WPsigner supports all three eIDAS levels. Simple Electronic Signatures (SES) are the default. Advanced Electronic Signatures (AdES) under eIDAS Article 26 are achieved by enabling Didit KYC identity verification with government ID, selfie and liveness before signing. Qualified Electronic Signatures (QES) require an external Qualified Trust Service Provider (QTSP).

What is Long-Term Validation (LTV)?

LTV ensures a digital signature can be verified long after it was created, even if the signing certificate has expired or been revoked. WPsigner embeds validation data, certificates, revocation information and timestamps into the signed PDF so the signature remains valid indefinitely.

Does WPsigner help with HIPAA?

WPsigner provides HIPAA-ready security controls and self-hosted storage on your WordPress server. You remain responsible for your overall HIPAA program, BAAs and operational policies.

Are court-admissible timestamps included?

Yes. RFC 3161 timestamps from a Time Stamp Authority can be embedded in signed PDFs as independent proof of signing time — included in WPsigner plans.

Legally binding e-signatures on WordPress

ESIGN, UETA, eIDAS, PKI and timestamps — meet global e-signature standards without a per-envelope SaaS.

Unlimited Usage · Self-Hosted

Stop paying per envelope

Choose an annual or lifetime license with unlimited documents and no per-envelope fees. Keep control of your data and signing workflows.