CLMSign Security & U.S. Evidence Controls

A factual description of the controls CLMSign currently uses to preserve attribution, intent, integrity, timing and audit evidence for ordinary U.S. commercial electronic-signature workflows.

Scope: CLMSign provides technical evidence and signing workflow controls. It does not guarantee admissibility, enforceability or a court outcome. Authentication under Federal Rule of Evidence 901 is only one potential evidentiary issue.

Signer attribution Supported

CLMSign records the recipient name/email and transaction context. New external-signature envelopes default to email one-time-password (OTP) verification, which adds corroborating evidence that the signer had access to the invited mailbox. Senders may disable OTP when their workflow does not require that additional layer. Email OTP is not represented as government-ID or biometric verification.

Intent and affirmative signing action Supported

The signing process records electronic-record/signature consent and the later signing act as transaction events. A stored or displayed signature image is not treated as the entire evidence record by itself.

Document integrity Supported

CLMSign calculates SHA-256 fingerprints for retained document states. The finalized signed PDF is maintained separately from editable source material such as a Google Doc. The U.S. Evidence Package recomputes the retained hashes and reports whether they match the recorded values.

Tamper-evident audit trail Supported

Audit events are linked using SHA-256 hashes anchored to the specific document. Re-verification can detect later modification, deletion or reordering of recorded events. Audit records can include event time, signer context, IP address and browser/user-agent information.

PDF cryptographic seal Supported

Completed PDFs are sealed with a PKCS#7 signature so post-finalization modification can be detected by compatible PDF-verification software. CLMSign now supports deployment of an externally issued PKCS#12/PFX document-signing identity. Until a publicly trusted CA-issued certificate is actually installed and independently validated, the current application-managed certificate is described only as cryptographic tamper evidence.

Independent RFC 3161 timestamping Transaction-dependent

CLMSign supports RFC 3161 timestamps from an independent timestamp authority and now supports an authenticated commercial TSA as the primary provider. A transaction is described as independently timestamped only when the stored record contains the actual RFC 3161 token and timestamp-authority time.

U.S. Evidence Package Supported

Owners of completed documents can download a ZIP containing the final and original PDFs, a structured evidence manifest, the hash-linked audit trail, a human-readable verification summary, the public PDF-seal certificate and the RFC 3161 token when available. The package is designed to help explain and authenticate the process/system under Federal Rule of Evidence 901(a) and 901(b)(9).

The package is not automatically self-authenticating under Federal Rules of Evidence 902(13) or 902(14). Those provisions require a certification by a qualified person and applicable notice requirements.

Record retention and reproducibility

The completed signed record is stored as a finalized PDF separately from editable source documents and can be reproduced by download while retained. The legally required retention duration can depend on the transaction, governing law and industry; CLMSign does not determine that period for the customer.

Google data minimization

The Google Docs add-on is designed to operate on the active document and request the minimum Google permissions needed for the feature. CLMSign does not need to browse or index the user's entire Drive for the Docs signing workflow.

Controls at a glance

SHA-256 document verification

Stored + recomputed hashes for evidence review.

Hash-linked audit events

Detects modification, deletion or reordering of recorded events.

Email OTP by default

Corroborating mailbox-access evidence for new external signer envelopes.

PKCS#7 PDF seal

Detects post-finalization changes to the completed PDF.

RFC 3161 support

Independent time evidence when a TSA successfully issues a token.

Evidence ZIP

Portable technical record for counsel, experts or a qualified witness.

External certifications we do not currently claim

Unless explicitly updated after independent validation, CLMSign does not claim SOC 2, ISO 27001, government-ID verification, a qualified electronic signature (QES), or that its current application-managed PDF-seal certificate is publicly trusted.

Primary U.S. evidence references

Federal Rule of Evidence 901 · Federal Rule of Evidence 902 · ESIGN Act, 15 U.S.C. Chapter 96

Vulnerability reports

If you believe you found a security issue, report it privately to support@signatureflow.com. Do not publicly disclose sensitive exploit details before we have had a reasonable opportunity to investigate.