WorkOS by Befocusy WorkOS Help center

Signed documents: locking, seal and signature verification

When someone approves a document from the portal, WorkOS seals it: it keeps an exact copy of what was signed and a record that cannot be altered. That way it can later be shown what was signed, who signed it and when.

What is kept when signing

  • A sealed copy of the document as it was at that moment: content, title, type, date, amounts, images, attachments, the client's template and the text of the legal terms that were accepted.
  • A fingerprint (SHA-256) of all of it. If a single character changed, the fingerprint would be different.
  • A chained record: each signature is linked to the previous one, so no entry can be deleted or modified without it showing.
  • A third-party time stamp (RFC 3161) over the head of the record: an external authority certifies the date without seeing the content, only the fingerprint.
  • A sealed PDF, generated from the sealed copy. It is always the same file, wherever it is.

The signer's personal data (name, ID number, email, IP) is stored separately and is not part of the public record.

The document is locked

A signed document can no longer be modified: not its content, title, type, date, amounts, attachments, people or links, and it cannot be deleted. This applies to the app, to Kairos and to Claude or ChatGPT. You can still read it, share it, download its PDF and add comments.

What the signer (and anyone who opens the document in the portal or downloads its PDF) sees is always the sealed copy, even if someone later edits the working original in Notion.

If someone edits the original in Notion by hand, WorkOS detects it, records it, emails the Owners and shows a notice on the verification page. The sealed copy does not change and remains the valid one.

How to check a signature

The seal on the signed PDF has a reference and a verification link. Opening it (no login required) you will see:

  • whether the record is intact,
  • the document type, the version, the signer in abbreviated form, and the approval and sealing dates,
  • the content and PDF fingerprints,
  • the time stamp and its validity,
  • whether the signature was voided or whether the original changed afterwards.

To check that your PDF is the original, drag it onto the page: your browser computes its fingerprint and compares it with the registered one. The file never leaves your computer.

Voiding a signature or changing a signed document

Only the Owner and people with Technical administration permissions can void the signature, from the notice shown on the document's page. A reason is required and stays in the record. Voiding deletes nothing: the previous seal is kept and can still be verified, but it is no longer in force and the document becomes editable again. For it to count again it has to be signed again; that creates a new seal (next version).

Documents approved before this system

Documents that were already approved can be sealed afterwards. Their record shows them as retroactive seal: the content the document had at that moment was sealed, which is not necessarily what was signed. Their reference is the one already printed on them.

What kind of signature it is

It is a simple electronic signature: identity checked with a code sent to the email, name, ID number, date and IP. The seal, the fingerprint and the time stamp strengthen the proof of what was signed and when, but they do not make it an advanced or qualified electronic signature. If your case requires a qualified signature, consult your legal advisor.