Document security & verification
Print/copy permissions, the certificate of completion, PDF metadata, the public verification page and its optional passcode, and where documents are actually stored.
Signed PDF protection
Completed documents are encrypted so editing, annotating, and page reassembly are always disabled. Printing and copying text are independently configurable per envelope at send time (both default on).
Certificate of completion
An optional final page lists every recipient's name, email, IP address, and completion time, plus a SHA-256 hash of the signed content so any later alteration is detectable.
Every signature captured this way is a simple electronic signature under UK ECA 2000 / eIDAS and US ESIGN/UETA - the same legal basis used across everyday commercial contracts, property sale and service agreements, and countless business-to-business dealings. The certificate of completion and audit trail give it the evidential weight to be relied on and, if it's ever questioned, verified independently. It isn't a substitute for a qualified/advanced electronic signature or a wet-ink signature where one is specifically mandated (certain deeds, wills, and a handful of other document types) - for everything else, it stands on its own.
Verification page
Every completed envelope gets its own public verification link (also printed on the certificate page) - open it to confirm who sent the document, when it completed, and see its SHA-256 integrity hash, straight away and for years to come. Completed documents are kept safely for at least 5 years, so a signed agreement stays a trusted, checkable record long after the ink (or pixels) have dried.
Confirming a document is genuine and downloading it are deliberately separate: the plain verification link (org, title, completion time, hash) is always safe to share with anyone who needs to check a document is real. Actually downloading the file needs the envelope's own unguessable token too - which is already part of that link unless you turn on "Require a passcode to download" at send time (Admin > compose). With that on, the file itself needs a short passcode as well, given out however you choose - it's included automatically in the completion email, and appending it to the end of the verification link (as a single link, or entered separately on the page) is what actually unlocks the download.
Where documents live, and who can reach them
Documents are stored on Noviqent's own servers, not a shared third-party cloud, and every organisation's files are kept in their own isolated space - nothing is ever loose across organisations. Every path to a document requires its own credential: your own logged-in session for anything in the dashboard, an API key for integration traffic, a recipient's own unguessable signing link while an envelope is in progress, and (once completed) the verification token - plus its passcode, if you've required one - for the public verification page. Nothing is ever served without one of these checks passing first.
All traffic runs over HTTPS, and the signed PDF itself carries its own encryption on top of the platform's access controls - printing and copying permissions are set per document, and editing, annotating, and page reassembly are always disabled, regardless of how the file is obtained.
PDF metadata
The signed PDF's own document properties (Title, Author, Copyright Notice, Copyright Info URL, and so on) reflect the sending organisation, not Noviqent - set your organisation's website in Admin to have it used as the Copyright Info URL.