Scribe
← Insights

2026-06-22

How to get a document signed online securely

Sending a contract for signature online is fast, but doing it securely means verifying who signed, recording every action, and preserving proof that the final document was never altered.

Getting a document signed online takes minutes, yet the difference between a casual e-signature and a defensible one lies in the process. This guide walks through the steps that produce a record you can rely on if the agreement is ever questioned.

Step 1: Prepare the document and signing fields

Upload the final PDF and place signature, initial and date fields for each party. Assigning fields to named recipients prevents the wrong person from signing in the wrong place and keeps the layout unambiguous.

Step 2: Add recipients and set the signing order

  • List every signatory with their full legal name and email address.
  • Choose sequential signing when order matters (for example, employee before manager) or parallel signing when it does not.
  • Add viewers or approvers who should receive a copy without signing.

Step 3: Verify identity before signing

Identity verification is the step most often skipped and the one that matters most. A one-time passcode (OTP) sent to the signer's email confirms control of that address at signing time. For higher-value documents you can layer additional checks, but email OTP already raises assurance well above a bare click-to-sign.

In BAScribe each signer receives a unique, single-use link and confirms an email OTP before they can sign. Every verification event is written to the audit trail with a timestamp, so the record shows not just that a party signed but how their identity was checked.

Step 4: Sign, then lock and preserve the evidence

Once all parties have signed, the document should be sealed so no further changes are possible, and every party should receive the same finalised copy. The audit trail should record each recipient, verification method, timestamp and IP address.

BAScribe finalises the executed PDF and anchors its cryptographic hash on a public blockchain. That anchor lets anyone confirm the exact file was the one signed, independently of the platform, which is the strongest form of tamper-evidence you can attach to a signed document.

Frequently asked questions

Do I need to verify identity for every document?

Not always, but it is strongly recommended. Email OTP verification is a low-friction way to confirm the signer controls the address, and it materially strengthens the evidence if the signature is later disputed.

What should a good audit trail contain?

At minimum: each recipient's name and email, the identity-verification method and result, timestamps for viewing and signing, IP addresses, and proof that the finalised document was not altered afterwards.

Can I control the order in which people sign?

Yes. Sequential signing enforces a defined order, which is useful when one party must review or countersign after another. Parallel signing lets everyone sign independently when order is irrelevant.

Keep reading