Articles

Practical guides for e-signatures & contracts

Honest writing on e-signature law, contract lifecycle management, compliance, signing workflows, and the realities of running a paperless, defensible signing process.

11 articles
Security10 min read

Signing with CAC and PIV Smart Cards: Digital Signatures for Government

Federal employees, military personnel, and government contractors sign a different way than the rest of the world. Instead of clicking to apply a mark, they insert a smart card — a CAC or a PIV — that holds a private cryptographic key, and produce a true digital signature bound to a government-issued certificate. Here is how CAC and PIV signing actually works, why it is a digital signature rather than an ordinary e-signature, and where each fits.

Paul HittJul 11, 2026
Security7 min read

Proving When a Document Was Signed: Timestamps and Why Timing Is Evidence

Who signed and what they signed get all the attention, but when a document was signed is often just as decisive — for deadlines, priority, and disputes. A trustworthy timestamp turns "we think it was Tuesday" into provable fact. Here is how signing time becomes evidence, and why it belongs in the audit record.

Paul HittJul 6, 2026
Security7 min read

Is This Signature Request Real? How to Tell a Legitimate E-Sign Email From Phishing

Signature-request emails are a favorite disguise for phishing — a fake "please sign" is exactly the kind of message people click without thinking. How to verify a signing request is genuine before you open it, and what a legitimate request will and won't ask you to do.

Paul HittJul 1, 2026
Security7 min read

Where Are Signed Documents Stored? Encryption, Retention, and Data Residency

When you sign electronically, the document and its proof live somewhere — and for regulated teams, "where" and "for how long" are real questions. A plain explanation of how signed documents are stored, encrypted at rest, retained, and what data residency does and does not mean.

Paul HittJun 29, 2026
Security6 min read

Team Roles and Permissions: Who Should See and Send What

In a shared signing workspace, "everyone can do everything" is how a sensitive contract ends up in the wrong inbox. A plain guide to roles, least-privilege access, the read-only auditor role, and per-folder visibility — and how to set them so the right people can act and the rest can only see what they should.

Paul HittJun 25, 2026
Security6 min read

How to Verify a Signed Document Someone Sent You

You are on the receiving end: a counterparty emails you a "signed" PDF and asks you to rely on it. How to check that it is genuine, unaltered, and actually signed by who it claims — using the audit certificate, not just a trusting eye.

Paul HittJun 24, 2026