Features
E-signature and contract lifecycle for regulated industries
Send & sign
- Multi-document envelopes with multi-recipient routing — sequential or parallel stages
- Recipient roles: signer, approver (true approval gate — no signature captured), CC and viewer
- Signing groups — route a signature to a team, not a person, so an envelope stops stalling because one named individual is on leave. Give the slot a label ("Contracts Officers") and a list of members; every member gets their own link, and whoever is available signs. The moment one completes, the rest are locked out automatically — no parallel copies to void by hand. Exactly one human still signs, and the audit certificate records the specific individual plus the group they acted for ("Signed by Jane Doe as a member of Contracts Officers"), so provenance is stronger than a bare named recipient, not weaker
- Witness signing — add a witness who attests on the record for documents like affidavits and, where state law permits electronic execution, powers of attorney: add a witness bound to a specific signer, whose page unlocks only after that principal signs, captures the witness's own signature, and writes a "witnessed" event naming the principal into the tamper-evident audit trail and the Audit Certificate
- Approval workflow: approvers click Approve or Send back to sender, with a required reason; the envelope stays editable, not voided — the sender fixes and re-sends without starting over
- Drag-and-drop field placement: 13 types — signature, initial, text, number, date, checkbox, radio, dropdown, file upload, auto-fill name, auto-fill email, payment, and calculated
- Collect payment while you sign — add a Payment field to any envelope with a fixed amount, currency, and description, and the document can't complete until the card clears. The signer pays inline with a Stripe card form as a hard gate alongside signing; the charge is recorded on the tamper-evident audit certificate and linked to the signature it gated. Perfect for a deposit on a rental, a retainer on an engagement letter, a membership fee on a waiver, or an FFL transfer fee — signed and paid in one flow, no out-of-band invoice
- Auto-fill name + email fields — read-only fields pre-populated from recipient data, no re-typing
- Number field with min/max validation — ideal for pricing, quantities, and numeric IDs
- Field placeholder text + pre-filled default values for text and number fields
- Text-field validation rules — require email, phone, ZIP, numeric, or custom-pattern formats, with instant inline errors for signers (enforced on the server too, so garbage never reaches the signed PDF)
- Conditional fields — show a field only when another field has a matching value
- Smart fields keep working when you reuse a document — conditional questions and auto-calculated totals carry over intact when you send from a template, duplicate an envelope, run a CSV bulk send, or let someone sign from a public link, so a recurring monthly form behaves the same on send #12 as it did on send #1
- Calculated fields — totals that add themselves up. Place a Calculated field, pick add / subtract / multiply / divide and the fields to compute from, and quantity × rate, subtotals and grand totals update live as the signer fills the form. The signer can’t edit or typo the result, and the server recomputes every total from the submitted values before flattening — so the number in the signed PDF is the one your formula produced, not the one anybody typed
- Typed-name OR drawn-signature capture — signers pick what works on their device
- Saved-signature library — repeat signers reuse their signature in one tap
- Save & finish later — a signer working a long, multi-field agreement can save their in-progress entries and resume from the same link, instead of losing everything if they close the tab or lose connection; drafts are private to the signer and never touch the signed PDF or the tamper-evident audit certificate
- Signer-uploaded files attached to the signed PDF as PDF attachments
- Unique per-recipient signing links — no account required to sign
- In-person signing — hand your phone or tablet to a walk-in signer and capture a legally-binding signature on the spot, no email or signer account required
- Text the signing link — send the signing invitation (and every reminder) by SMS instead of, or alongside, email; meet mobile and field signers where they already are and watch completion rates climb. Every text is recorded in the tamper-evident audit trail
- Sign in your signers' language — set a language per recipient (English, Spanish, French, German, Portuguese) and the entire signing experience localizes: the signing-page chrome, every signer email (invitation, reminder, completion, OTP), and the ESIGN/UETA consent disclosure all render in their language on first paint, with no English flash. A workspace default applies when a recipient has no explicit language; your own document title, message and field labels are never machine-translated
- Signer comments & questions — a signer can flag a clause or ask "why does section 4 say net-60?" right on the signing page without declining or voiding the document. The sender is notified and replies in a thread that lives on the envelope, so every conversation stays on the record instead of scattered across email; each comment is recorded on the tamper-evident audit trail and signing/declining still work exactly as before
- Decline with a reason, and void or delete envelopes any time
- Reassign a signer — a recipient who got the wrong document can hand it to the right colleague in one click, no need to void and restart; the handoff is recorded in the tamper-evident audit trail
- Correct a sent envelope — fixed a typo'd signer email? Correct the name or address on a recipient who hasn't signed yet in one click, re-send the fresh link, and keep going — no need to void and start over; the correction is recorded in the audit trail
- Signer self-service downloads — the instant a signer finishes, the confirmation screen offers their signed copy and audit certificate to download right there; no waiting on an email that might bounce, and it works for in-person and public-template signers who never had an inbox in the loop
- Re-send the signed copy — lost the email or the 7-day link expired? Push a fresh copy of the finished, signed document to any recipient (including CC and viewer recipients) in one click, with a new short-lived download link
- Signing-order builder: validate multi-stage routing and preview the order before sending
- Completion redirect URL — return signers to your app or sibling product when done
- Scheduled send — queue an envelope now and have it go out automatically at the date and time you pick, so contracts land exactly when you want; it stays an editable draft until then, and you can reschedule or cancel any time
- Recurring envelopes — put periodic attestations on autopilot: attach a weekly, monthly, quarterly or annual schedule to any template and each run creates and sends its own brand-new envelope, with its own signing links, its own tamper-evident audit trail and its own certificate. Pick an anchor day (a 31st safely falls back to the last day of shorter months), end it never / on a date / after N runs, and pause or resume any time — resuming picks up from today rather than firing every run you missed. Each occurrence spends one credit exactly like a manual send, and a run skipped for an empty balance says so instead of failing quietly
- Recipient progress at a glance — every envelope in your list and on the dashboard shows a live "2/4 signed" progress chip and a "Waiting on <name>" indicator that points to the next signer in the routing order, so you can spot the bottleneck and nudge the right person without opening each envelope
- Duplicate any envelope — declined, voided, expired, or just need to send it again? Clone the whole envelope (same document, same signers, same field placement) into a fresh draft in one click, with brand-new signing links and a clean, independent audit trail. No re-uploading the PDF, no re-placing fields, no re-adding recipients
Contract lifecycle
- Never get blindsided by an auto-renewal again — capture each contract's effective, renewal and term-end dates the moment it's executed, right on the completed envelope, and Hitt Sign emails the owner before the clock runs out so a signed deal never auto-renews on unfavorable terms — or lapses — because nobody was watching the calendar
- Auto-renew flag + configurable notice lead-time (1–365 days) per contract — the reminder tells you whether the contract renews automatically unless you act, or lapses unless you renew, and fires that many days ahead of the date
- One reminder, provable and idempotent — the heads-up email is sent exactly once per date and recorded as a contract.renewal_reminder_sent event on the tamper-evident audit chain, so the notice is verifiable; a contract with no lifecycle dates set is never touched
- "Upcoming contract dates" dashboard — see every contract renewing or ending in the next 30 / 60 / 90 / 180 / 365 days at a glance, overdue items flagged, exportable to CSV alongside your envelope register; the read-only auditor role can view the dates without editing them
Tamper-evident audit
- Hash-chained audit trail capturing every event with signer IP and user agent
- One-click chain verification that recomputes every event hash
- Audit Ledger — one-click, org-wide integrity proof that re-verifies your entire signing history against a tamper-evident daily anchor, and flags any deleted or altered record
- Public verification portal — anyone can verify, no account needed. A counterparty, bank, title company, FFL, or auditor holding your signed PDF confirms at sign.hitthosting.com/verify that it's genuine and byte-for-byte unaltered, seeing who signed and when, backed by the same hash chain and trusted timestamp on the Audit Certificate. Every completed envelope gets a short verification code printed on the certificate; drop the PDF on the page and the browser checks its SHA-256 in-place (the file never leaves the device). Turns the tamper-evident audit trail from an internal reassurance into public, shareable proof — exactly what regulated-industry deals need when a signature is challenged
- RFC 3161 trusted timestamp from a public TSA on every completed PDF — verify offline with openssl
- Generated Audit Certificate PDF for every completed envelope (includes both the SHA-256 seal and the trusted timestamp)
- Complete, multi-page Audit Certificate — every event in the trail is recorded and never truncated, no matter how many recipients, reminders, or corrections an envelope accumulates; the log paginates across pages with a per-page running header and a "Page N of M" footer
- Flattened signed PDF with field values burned in, PDF/A-3b XMP metadata for long-term archival compliance
- One-click ZIP bundle — signed PDF + audit certificate + signer uploads, ready for legal/compliance
- Optional email-OTP or SMS-OTP identity verification: signer enters a 6-digit code before opening the document
- ESIGN/UETA consent capture — every signer affirmatively agrees to electronic records before signing, recorded in the tamper-evident audit trail and printed on the Audit Certificate
- Per-recipient access codes: gate any signer behind a private passcode you share off-channel — distinct from emailed one-time codes
- TOTP two-factor authentication for sender accounts (Authy, 1Password, Google Authenticator)
- GDPR right-to-be-forgotten: owner-initiated PII purge on completed envelopes
- Configurable data retention policy (minimum 30 days, null = keep forever)
- Legal Hold — freeze any executed contract against automatic retention purge, the GDPR right-to-be-forgotten purge, and deletion the moment it's subject to litigation, an audit, or a regulatory records request. An owner or admin places the hold with a reason; while held, both the retention sweep and every purge/delete attempt are refused until it's released — and the preservation itself is recorded on the tamper-evident audit trail, so the decision to hold is provable
- User security audit log: sign-in, 2FA enable/disable, API key lifecycle events
Templates & contacts
- Reusable templates — instantiate a ready-to-send envelope in one click
- Template roles — multi-party templates (offer letter + countersign, MSA, NDA with witness) carry named roles like Employee / Manager / Witness; clicking Use prompts for the real signer behind each role, then materializes a draft with the correct per-recipient field routing and signing order intact — fill real signers in one step, no hand-editing
- Field-tag API — upload a PDF with {{signature}} / {{text:Label}} / {{radio:A|B|C}} markers; fields auto-placed from the text layer
- Fillable-PDF (AcroForm) import — upload a PDF that is already a fillable form (a government W-9, an HR onboarding packet, a counterparty's vendor NDA) and its fields are already placed. Sign reads the PDF's own form definition and recreates every text box, checkbox, radio group (with its choices), dropdown and signature widget at exactly the position the document declares, on the right page, with the document's own required flags honoured — no redrawing a government form field by field. Everything lands as an ordinary Sign field, so you review, reassign to the right signer, move or delete anything before sending. Re-detecting never duplicates what you already imported, and a PDF with no form data is simply left alone
- Bulk send from CSV — blast a template to 500 recipients at once; every CSV blast is grouped as a named batch campaign so you can track signed/total progress and send a one-click reminder to all open envelopes in the batch
- Mail-merge bulk send — personalize dates, amounts and names for every recipient from one CSV: tag a field with a merge key (e.g. start_date, salary) in the builder, add that column to your CSV, and each envelope pre-fills its own value; a one-click "Download CSV template" gives you the exact header row for the template
- Public templates — publish any single-signer template at /t/<slug> and anyone can fill it out + sign
- Built-in HR onboarding template pack
- Nested folders + per-folder visibility — organise templates and envelopes for multi-department teams
- Contacts directory for frequent recipients
- Reporting dashboard: status counts and completion-time stats
- Envelope throughput trend: 12-week sent / completed / voided rollup with up/flat/down trend indicator
- Declines report: see exactly why signers say no. Every declined signer already types a reason — now they are grouped (case- and spacing-insensitive, so “Wrong signer” and “wrong signer ” are one bucket) and ranked, so “3 of your 7 declines said wrong signer” is a number you can act on rather than a bare “Declined: 7”. Each recent decline links to its envelope with one-click Duplicate & re-send to fix the clause or the recipient and win the deal back, and decline_reason is now a column in the per-recipient CSV export
- Export envelope register to CSV — pull your whole envelope list (status, sent/completed dates, signed/pending counts) into a spreadsheet in one click; filter by status, date range, or title; per-recipient detail view answers "who still hasn't signed?" across all open envelopes at once; available to owners, admins, and the read-only auditor role
Team & API
- Org roles: owner, admin, member, sender and auditor
- Email invitations to add teammates
- Scoped integration API keys, one per sibling product
- REST API to spawn envelopes from CRM, HR and other apps
- Embedded signing widget — drop the signer flow into your own app via JS SDK + iframe
- White-label embed — pass whitelabel: true to hide all Hitt Sign branding from the iframe
- Outbound webhooks — subscribe URLs to envelope.sent / completed / voided / declined / recipient.signed / recipient.reassigned events; HMAC-SHA-256 signed payloads; Zapier-compatible
- Webhook delivery log — inspect every outbound delivery with response code and attempt count, and one-click redeliver any failed event
- Completion callbacks back to the originating sibling app
- Email-OTP or SMS-OTP signer identity verification — 6-digit code before the document opens (per envelope)
- Custom email body templates — override invitation / reminder / completion copy per org
- Sender notifications — activity alerts (viewed, signed, declined, sent back, completed, commented) go to the teammate who actually sent the envelope, with an optional copy to the workspace owner for oversight; pick exactly which events you want, per workspace. Removed teammates stop receiving envelope activity the moment they leave the workspace
- CC / copy recipients — add people who automatically receive the finished copy with no signature and no clutter; they get a view-only document and a "no action needed" invite, never a signing prompt
- Automated reminders and envelope expiration — set a workspace default: auto-expire envelopes after N days and choose your reminder cadence once; every new envelope inherits it, override per send; and signers see the deadline and a live countdown on the signing page, so the clock is never a surprise
- One-click "Remind unsigned signers" on any sent envelope
- Email notifications for sent, reminder, completed and declined
- Per-recipient delivery status — see who got the email and who needs a copied link
Billing & flexibility
- Flat Pro and Business plans, monthly or annual (2 months free annually)
- 14-day free trial on every plan — no charge today, cancel any time
- Pay-per-envelope credit packs — no subscription required
- Self-serve Stripe billing portal to switch plan or update payment
- Promo codes at checkout — apply a coupon to your subscription (or arrive with one pre-filled from a link)
- Append-only billing audit log visible to owners and admins
Built for the suite
- Product-scoped data — Sign never bleeds into CRM/HR billing or records
- Envelopes can originate from sibling products via signed integration keys
- Source product tracked on every envelope for cross-product reporting
- Shared identity, isolated entitlements per product
- Sibling products can pass a completion_redirect_url so signers land back in the originating app
Workspace branding
- Upload your workspace logo (PNG/SVG/JPG/WebP — kept under 50 KB)
- Pick an accent color used on signer page buttons, links, and email CTAs
- Signers see your brand, not ours — fully white-labeled signing experience
- Branding applied to all signer-facing emails (sent / reminder / completed)
- One-click reset back to defaults at any time
Sender Alias
Available nowSend envelopes "From: legal@acme.com" instead of the individual sender's email. DKIM-verified aliases per workspace, with the original sender preserved in the audit trail. See your verified alias picker in the dashboard. Included on every pricing path — subscriptions and credit packs alike.