Remix.run Logo
JCBird1012 2 hours ago

In my opinion, all of these open source/free/open document signing tools are neat on paper (and technically fulfill the goal of being able to verify a document's chain-of-custody/signature provenance) - but won't take off in any meaningful way legally because there's no entity behind them taking the responsibility for accuracy and culpability.

DocuSign/Adobe/whomever is trust anchor, it's an entity you can sue or subpoena if something goes wrong. Someone who's actually on the hook for making sure whatever's signed is accurate and truthful (outside of the reputational risk of fraud completely obliterating any trust in your platform)...

No amount of cryptographic verification substitutes for having a legal person on the other end who can be held accountable for actually verifying the document was signed accurately/process was followed.

layer8 an hour ago | parent | next [-]

Indeed. It doesn’t meet the requirements of EU qualified signatures or seals, for example.

EGreg 42 minutes ago | parent [-]

What are the actual requirements?

In USA we only have a few requirements from the E-SIGN act:

Key Legal Requirements

Intent to Sign: Parties must show a clear, provable action to sign the document. Electronic Consent: Parties must agree to use electronic records, with consumer transactions requiring specific advance disclosures.

Signature Association: The system must capture an audit trail or text linking the signature to the specific document.

Record Retention: Contracts must be accurately stored and remain accessible for future reference by all authorized parties.

Consumer Disclosure Rules

Hardware/Software Notice: Tell users what tools they need to access and save the records.

Paper Copy Rights: Inform users how to get paper copies and whether any fees apply.

Withdrawal Details: Explain how consumers can change their mind and cancel their electronic consent.

nsokin 25 minutes ago | parent [-]

[flagged]

hnscum an hour ago | parent | prev | next [-]

that's true. i think that if it's obvious that the audit is finding everything, every detail, every file, piece of data touched.... at what level do we need to verify?

nsokin an hour ago | parent | prev [-]

[dead]