Security

What Is an Electronic Signature Audit Trail?

An audit trail is the evidence behind an electronic signature. Here is what one records, what tamper-evident actually means, and what Tarchos Sign captures.

The Tarchos Sign TeamPublished July 3, 2026 · Updated August 24, 20266 min read

An electronic signature audit trail is the chronological record of everything that happened to a document: when it was created, when it was sent, when each recipient opened it, when they agreed to sign electronically, when they signed, and when it was completed.

The signature itself is only a mark on a page. The audit trail is what turns it into evidence.

Why it matters

Most signed documents are never disputed. The audit trail exists for the ones that are.

When a client says they never received the agreement, or does not recall accepting those terms, an image of a signature is weak on its own. A timestamped record showing the document was delivered to a named email address, opened from a particular device, that a disclosure was accepted, and that signing followed shortly afterwards, is a considerably stronger account of what happened.

What an audit trail usually records

Implementations vary, but a useful audit trail generally covers:

  • •Document events — created, uploaded, sent, completed, downloaded, or voided.
  • •Recipient events — opened, consented to electronic signing, signed, or declined.
  • •A timestamp on every event, rather than only a final signing date.
  • •The identity each event belongs to: the sending user, or the recipient's email address.
  • •Technical context such as IP address and browser or device information.
  • •A completion certificate summarising the above in a form you can store.

What Tarchos Sign records

Rather than describe the category in the abstract, here is what this product actually stores. Each event in Tarchos Sign records the action, a timestamp, who it belongs to — either the signed-in user's email address or the recipient's — the IP address and browser or device string of the request, and structured context specific to that event.

The events captured across a document's life include: uploaded, recipient added, sent, email delivered, opened by the recipient, consent given, signed, declined, completed, downloaded, and voided.

Two of those carry extra detail worth knowing about. When a recipient consents, the version of the electronic record and signature disclosure they were shown is stored with the consent event, so it is possible to establish later exactly which disclosure they accepted. When they sign, the signing method used is recorded alongside it.

Deliberately, the audit trail never stores document contents or signature images. It records that an event happened and its circumstances, not the material itself.

Tamper-evident is not tamper-proof

This distinction is worth being precise about, because vendors are often careless with it.

Tamper-proof would mean records cannot be altered. Tamper-evident means alteration can be detected afterwards. The second is an honest claim about software running on a database; the first usually is not.

Tarchos Sign stores a SHA-256 hash of each audit event's contents when the event is written. If a stored row is later modified, its hash no longer matches what the row now contains, and the modification is detectable.

It is equally important to be clear about the limits of that. A per-event hash detects modification of an event. On its own it does not prevent tampering, and it does not detect an event being deleted outright or the order of events being changed — detecting those requires chaining each record's hash to the previous one. We would rather write that down than let a security page imply more than the architecture delivers.

Audit trails and enforceability

A strong audit trail supports the enforceability of an electronic signature. It does not guarantee it.

In the United States, electronic signatures are addressed principally by the federal ESIGN Act and, at state level, by the Uniform Electronic Transactions Act. Both broadly provide that a signature or record is not denied legal effect merely because it is electronic. Both also set conditions — around consent to do business electronically, the signer's intent, and the ability to retain and reproduce the record — and both carve out categories of document, such as wills and certain notices, that are treated differently.

Whether any particular signature holds up depends on the jurisdiction, the type of document, whether the parties consented, whether the signer intended to sign, and the circumstances around the transaction. An audit trail helps you evidence several of those. It cannot supply the ones that are matters of law.

The authoritative sources here are the ESIGN Act itself (15 U.S.C. ch. 96) and the Uniform Law Commission's UETA materials, rather than vendor marketing. We cover this in more depth in Are electronic signatures legally binding?.

What to ask a vendor

  • •Which events are recorded, and is opening tracked separately from signing?
  • •Is the disclosure the signer accepted recorded, including which version of it?
  • •Can the audit trail be exported, and does the completion certificate travel inside the signed PDF?
  • •Is the record tamper-evident, and by what mechanism?
  • •What is explicitly not covered by that mechanism?

The last question is the most revealing. A vendor that can answer it precisely has thought about the problem. Ours is answered on the security page.

This article is for general information and is not legal advice.

See the record for yourself

Sign a test document and watch what gets captured — no account needed. Every document sent with Tarchos Sign carries a tamper-evident audit trail and a completion certificate, on the free plan too.