The cutting edge of compliant signing

SignVault brings regulated signature workflows into the modern era: tamper evident hash chains, explicit signature meaning, automatic audit certificates and retention that follows your SOPs, all delivered through an API first platform engineered for regulated teams.

90 days
Default document retention
30 years
Audit record retention
Every event
Chained, timestamped, attributable

Platform

Engineered around the regulation, not bolted onto it

Two component signing

Every signature pairs identification with a second component: account re authentication or an emailed one time passcode, selected per recipient.

Hash chained audit trail

Append only events, each hashing the one before it. Any insertion, edit or deletion breaks the chain and surfaces instantly on verification.

Audit certificate page

On completion the document is flattened, an audit certificate page is appended and the file is sealed with SHA-256 plus HMAC.

Retention you control

Document binaries purge after 90 days by default, configurable per workspace or per envelope, with legal hold override.

30 year audit retention

Signature meaning, signer identity, timestamp and reason are retained for three decades, independent of the document lifecycle.

Built to integrate

REST API with scoped keys, HMAC signed webhooks and embeddable signing so SignVault drops into your QMS, LIMS or ERP.

How it works

Four steps, fully evidenced

01

Prepare

Upload the PDF, hash it on arrival, place signature, initial, date and text fields visually.

02

Route

Assign recipients, signature meaning and the identity method each signer must satisfy.

03

Sign

Signers authenticate twice, attest to the meaning and sign, with every action written to the chain.

04

Seal

The completed file is flattened, certified, sealed and retained to your policy.

Compliance

Evidence your quality unit can inspect

Every envelope carries a complete, verifiable record: who signed, what the signature meant, when it happened, from where, and how identity was proven. Export an audit pack at any time and hand the inspector a single sealed PDF.

  • 21 CFR Part 11 electronic signature controls
  • EU Annex 11 aligned record keeping
  • Append only events with cryptographic chain verification
  • Exportable, timestamped and sealed audit packs
  • Legal hold that suspends retention purges

Wire signing into the systems you already run

Scoped REST keys, HMAC signed webhooks and embedded signing views, all configurable from the tenant admin console. No integration tickets, no waiting.