A factual description of the controls CLMSign currently uses to preserve attribution, intent, integrity, timing and audit evidence for ordinary U.S. commercial electronic-signature workflows.
CLMSign records the recipient name/email and transaction context. New external-signature envelopes default to email one-time-password (OTP) verification, which adds corroborating evidence that the signer had access to the invited mailbox. Senders may disable OTP when their workflow does not require that additional layer. Email OTP is not represented as government-ID or biometric verification.
The signing process records electronic-record/signature consent and the later signing act as transaction events. A stored or displayed signature image is not treated as the entire evidence record by itself.
CLMSign calculates SHA-256 fingerprints for retained document states. The finalized signed PDF is maintained separately from editable source material such as a Google Doc. The U.S. Evidence Package recomputes the retained hashes and reports whether they match the recorded values.
Audit events are linked using SHA-256 hashes anchored to the specific document. Re-verification can detect later modification, deletion or reordering of recorded events. Audit records can include event time, signer context, IP address and browser/user-agent information.
Completed PDFs are sealed with a PKCS#7 signature so post-finalization modification can be detected by compatible PDF-verification software. CLMSign now supports deployment of an externally issued PKCS#12/PFX document-signing identity. Until a publicly trusted CA-issued certificate is actually installed and independently validated, the current application-managed certificate is described only as cryptographic tamper evidence.
CLMSign supports RFC 3161 timestamps from an independent timestamp authority and now supports an authenticated commercial TSA as the primary provider. A transaction is described as independently timestamped only when the stored record contains the actual RFC 3161 token and timestamp-authority time.
Owners of completed documents can download a ZIP containing the final and original PDFs, a structured evidence manifest, the hash-linked audit trail, a human-readable verification summary, the public PDF-seal certificate and the RFC 3161 token when available. The package is designed to help explain and authenticate the process/system under Federal Rule of Evidence 901(a) and 901(b)(9).
The package is not automatically self-authenticating under Federal Rules of Evidence 902(13) or 902(14). Those provisions require a certification by a qualified person and applicable notice requirements.
The completed signed record is stored as a finalized PDF separately from editable source documents and can be reproduced by download while retained. The legally required retention duration can depend on the transaction, governing law and industry; CLMSign does not determine that period for the customer.
The Google Docs add-on is designed to operate on the active document and request the minimum Google permissions needed for the feature. CLMSign does not need to browse or index the user's entire Drive for the Docs signing workflow.
Stored + recomputed hashes for evidence review.
Detects modification, deletion or reordering of recorded events.
Corroborating mailbox-access evidence for new external signer envelopes.
Detects post-finalization changes to the completed PDF.
Independent time evidence when a TSA successfully issues a token.
Portable technical record for counsel, experts or a qualified witness.
Unless explicitly updated after independent validation, CLMSign does not claim SOC 2, ISO 27001, government-ID verification, a qualified electronic signature (QES), or that its current application-managed PDF-seal certificate is publicly trusted.
Federal Rule of Evidence 901 · Federal Rule of Evidence 902 · ESIGN Act, 15 U.S.C. Chapter 96
If you believe you found a security issue, report it privately to support@signatureflow.com. Do not publicly disclose sensitive exploit details before we have had a reasonable opportunity to investigate.