What makes an electronic signature trustworthy?
Identity, integrity and time: the three questions every signature has to answer, and how PQC Imza answers each one.
3 min read
A handwritten signature earns trust in a quiet way: the paper is in front of you, the ink is on it, and a court knows how to examine both. An electronic signature has none of that physical evidence. It has to earn trust by answering three questions clearly, whenever someone asks, for as long as the document matters.
Who signed? What exactly did they sign? And when?
Who signed: identity
The weakest electronic signatures stop at an email address or a typed name. Those are claims, and anyone who can open an inbox can make them.
PQC Imza ties each signature to a verified person. The PQC Wallet app reads the chip inside an ID card or passport over NFC, the same chip border control reads. The chip's data is signed by the issuing country, and the app checks that signature against the country's own certificates. A photocopy, a screenshot or an edited scan cannot pass that check, because they have no chip to sign it.
PQC Imza accepts chip ID cards and passports from over a hundred countries. Each signature also records how strongly its signer was identified: one made after a verified chip reads differently from one where the signer's identity was only claimed, and the difference is shown wherever the signature is.
What they signed: integrity
A signature has to be bound to one exact document, not to "the contract" in general. Otherwise a signature given to one version could be carried over to another.
Every document on PQC Imza has a SHA-256 fingerprint, a short value computed from its contents. Change a comma and the fingerprint changes completely. What each signer signs includes that fingerprint, and the server refuses a signature that does not. Anyone can later upload the PDF to the verification page: the site recomputes the fingerprint and says plainly whether the file is the one that was signed.
When: time
Dates matter: a signature can be valid only because it was made before a deadline, or before a key was replaced.
PQC Imza records when each signature was made, and when the last one is in, it writes the document's fingerprint and the fingerprints of its signatures to the SciChain blockchain. That record takes its time from the ledger, which several validators keep in step, rather than from our servers. It shows that these signatures existed by that time, whatever happens to any one server later.
And for as long as it matters
These three answers only hold while the signature itself cannot be forged. Most signatures today use RSA or elliptic-curve cryptography, which a large quantum computer would break. PQC Imza signs with ML-DSA, the post-quantum standard NIST published in 2024, so the answers stay true for the lifetime of the document. Why that matters is explained here.
A short checklist
Whatever service you use, ask it these questions:
- Identity: is the signer verified from an official document, or only by an email address?
- Integrity: is the signature bound to the exact file, and can anyone check that later?
- Time: is there an independent record of when it was signed?
- Longevity: will the signature still be unforgeable in ten years?
Whether a particular signature meets a particular legal requirement depends on where and how it is used. For documents that need a specific kind of signature by law, ask your legal adviser.