US · ESIGN Act

ESIGN Act Compliant E-Signatures

The Electronic Signatures in Global and National Commerce Act (ESIGN Act) was signed into law in the United States on June 30, 2000. It grants electronic signatures the same legal standing as handwritten signatures in interstate and foreign commerce, provided certain conditions are met.

ESIGN Act

United States · Enacted 2000

Key Provisions

Grants electronic signatures the same legal weight as ink-on-paper signatures for interstate and foreign commerce

Requires clear intent to sign — the signer must demonstrate willingness to be bound

Requires consent to conduct business electronically — signers must agree to use e-signatures

Requires identity attribution — each signature must be linked to a specific person

Mandates record retention — signed documents must be accessible and reproducible

Applies to all commercial, consumer, and business transactions unless specifically exempted

The Electronic Signatures in Global and National Commerce Act (ESIGN Act) was signed into law in the United States on June 30, 2000. It grants electronic signatures the same legal standing as handwritten signatures in interstate and foreign commerce, provided certain conditions are met. These conditions include clear intent to sign, consent to conduct business electronically, proper identity attribution, and record retention. What SignForge records against each of these is set out below. Every signature captured on SignForge includes a full audit trail with timestamps, IP addresses, user-agent strings, and signer consent confirmation. Documents are hashed with SHA-256 at upload and after signing to prove integrity. ECDSA P-256 cryptographic verification provides an additional layer of non-repudiation that goes beyond what the ESIGN Act requires.

What we record

What SignForge records

These are the facts we capture and store for every signature. ESIGN Act sets the requirements above — whether what we record satisfies them for a given transaction is a legal question that depends on the circumstances.

Explicit consent checkbox before signing confirms intent and e-signature agreement

Signer identity captured via email address, IP address, and user-agent string

SHA-256 document hashing at upload and after signing ensures tamper detection

Immutable audit trail records every action with timestamps — cannot be edited or deleted

Signed documents stored securely with 30-day download availability and Document Locker for long-term retention

ECDSA P-256 signature on every verification record

What SignForge does not provide here

  • SignForge is not a certification authority and does not issue digital certificates to signers
  • No notarization, witnessing, or identity proofing against a government-issued document
  • Documents the Act places outside its scope — including wills, testamentary trusts, and certain family-law matters — cannot be executed on any e-signature platform

256-bit Encryption

TLS 1.3 + SHA-256

ECDSA P-256

Cryptographic proof

Audit Trail

Append-only, immutable

ISO 27001

Certified infrastructure

Frequently asked questions

Are SignForge e-signatures legally binding under the ESIGN Act?

The ESIGN Act asks for intent to sign, consent to conduct business electronically, identity attribution, and a record that remains accessible. SignForge records a consent checkbox before signing, the signer's email, IP address and user-agent, a SHA-256 hash of the document before and after signing, and an immutable timestamped audit trail. Whether a particular signature is enforceable depends on the transaction, the document type and the parties — that is a legal question for your own advisers, and we state what we record rather than what a court would conclude.

What types of documents can be signed electronically under the ESIGN Act?

Most commercial and business documents can be signed electronically, including contracts, NDAs, employment agreements, lease agreements, and purchase orders. Certain documents are excluded, such as wills, family law matters, court orders, and documents requiring notarization.

How does SignForge prove a document wasn't tampered with after signing?

SignForge computes a SHA-256 hash of the document at upload and again after signing. Any modification to even a single byte would change the hash. Additionally, ECDSA P-256 cryptographic signatures are embedded in verification records, and every signed document includes a QR code linking to a public verification page.

Do signers need a SignForge account to sign documents?

No. Signers receive a secure, unique link via email. They can view and sign the document without creating an account. The signing link uses a 32-byte cryptographically random token, and only the SHA-256 hash of the token is stored in the database.

General information — not legal advice

This page summarizes electronic signature legislation drawn from primary legal sources and international bodies including UNCITRAL and UNCTAD. It is not legal advice and creates no solicitor–client or attorney–client relationship. Laws change, and how they apply depends on the transaction, the parties, and the document type. Before relying on electronic signatures for a regulated, high-value, or cross-border transaction — or for any document type listed as excluded — take advice from qualified counsel in the jurisdiction whose law governs that transaction. That is a separate question from the governing law of your agreement with SignForge, which is set out in our Terms of Service.

Last reviewed: 10 August 2026

Ready to sign with confidence?

Legally binding e-signatures with 256-bit encryption, cryptographic verification, and an immutable audit trail. Free forever.

Get started free

No credit card required.