Reviewed by lawyers Secure & confidential Digital, anywhere Satisfaction guarantee📞 +46 10-189 69 20 Sweden's leading legal document service

Security

What actually happens when you sign

“Secure” is a word every signing service uses, so it carries no information. Here is the specific mechanism instead, in enough detail that you could check our work.

Cryptographic sealingEvery e-signed file is hashed with SHA-256 into a fingerprint. Change a single character afterwards — one digit in an amount, one letter in a name — and the fingerprint stops matching the registered version. This makes later file changes detectable; it does not by itself identify the signer or prove legal validity.
Anyone can verify it, not just youOur verification page is open. Anybody holding the document — a bank, a counterparty, a court or an opposing lawyer — can recalculate the fingerprint and compare it with the registered file. You do not have to be the customer to check whether the file content matches.
Email verified with a one-time codeWhen parties are invited to sign remotely, we send a one-time code to the email address the invitation went to, and it has to be entered before signing completes. That ties the signature to control of a specific mailbox rather than to a link anyone could have forwarded.
Biometric confirmation, where the device supports itSigners can confirm with their phone's fingerprint reader or face recognition. The biometric data never leaves the device — the phone attests that the check passed, and that attestation is what we record.
A transparent audit trailWe log IP address, device and timestamp for every signature, independently of what the browser reports about itself. If several separately named parties sign from the same network, that is noted openly in the document's signature record — not because it is forbidden (the same household or office is entirely normal) but because every party should be able to see it.
Proof that outlives usWhen a document is sealed through remote signing, its fingerprint is also anchored publicly via OpenTimestamps, in the Bitcoin blockchain. The proof that the document existed unchanged at the moment of signing can then be checked by anyone, with free tools, without trusting us at all — even if Avtalsfrid ceased to exist tomorrow. Only the hash value ever leaves our servers, never the content and never personal data.

Why the open verification matters more than it sounds

Open verification lets a third party check one important fact without access to your account: whether the file they hold has the same content as the registered version. That is useful evidence of file integrity, but it is only one part of the record. Signer identity, authority, intent and the document's legal formalities must still be assessed from the authentication data, audit trail and surrounding circumstances.

Your data

Documents are stored encrypted and are visible to you and to the parties you invite. We do not sell data, and we do not use the contents of your documents to train anything. You can export or delete your data from your account at any time, which is your right under the GDPR and also simply how the account works.

Den svenska säkerhetssidan, med fler tekniska detaljer →

How signing works, and when Swedish law still wants ink →