Reviewed by lawyers Secure & confidential Digital, anywhere Satisfaction guarantee📞 +46 10-189 69 20 Sweden's leading legal document service

Security

What actually happens when you sign

“Secure” is a word every signing service uses, so it carries no information. Here is the specific mechanism instead, in enough detail that you could check our work.

Cryptographic sealingEvery signed document is hashed with SHA-256 into a unique fingerprint. Change a single character afterwards — one digit in an amount, one letter in a name — and the fingerprint stops matching. Forging a signed document without it being detectable is not difficult here; it is mathematically infeasible.
Anyone can verify it, not just youUnlike closed signing services where authenticity is something the provider asserts, our verification page is open. Anybody holding the document — a bank, a counterparty, a court, an opposing lawyer — can recalculate the fingerprint and compare it against the original. You do not have to be the customer to check.
Email verified with a one-time codeWhen parties are invited to sign remotely, we send a one-time code to the email address the invitation went to, and it has to be entered before signing completes. That ties the signature to control of a specific mailbox rather than to a link anyone could have forwarded.
Biometric confirmation, where the device supports itSigners can confirm with their phone's fingerprint reader or face recognition. The biometric data never leaves the device — the phone attests that the check passed, and that attestation is what we record.
A transparent audit trailWe log IP address, device and timestamp for every signature, independently of what the browser reports about itself. If several separately named parties sign from the same network, that is noted openly in the document's signature record — not because it is forbidden (the same household or office is entirely normal) but because every party should be able to see it.
Proof that outlives usWhen a document is sealed through remote signing, its fingerprint is also anchored publicly via OpenTimestamps, in the Bitcoin blockchain. The proof that the document existed unchanged at the moment of signing can then be checked by anyone, with free tools, without trusting us at all — even if Avtalsfrid ceased to exist tomorrow. Only the hash value ever leaves our servers, never the content and never personal data.

Why the open verification matters more than it sounds

The point of a signature is not that you believe it. It is that a third party who has no reason to trust either of you can be satisfied by it. A closed signing service can only ever say “we confirm this is genuine”, which turns the whole thing into a question of how much that company is trusted, and for how long it will exist. A published fingerprint that anyone can recompute removes us from the equation entirely, which is precisely the property you want from evidence.

Your data

Documents are stored encrypted and are visible to you and to the parties you invite. We do not sell data, and we do not use the contents of your documents to train anything. You can export or delete your data from your account at any time, which is your right under the GDPR and also simply how the account works.

Den svenska säkerhetssidan, med fler tekniska detaljer →

How signing works, and when Swedish law still wants ink →