Security
What is a certificate of completion, and why does it matter?
A certificate of completion is a report attached to the finished document listing every person involved, what they did, when, and from which address, plus the document's fingerprint. It is the evidence that the signing actually happened the way it appears to.
When everyone has finished a request sent with Request Signatures, the signed PDF comes back with extra pages at the end. That is the certificate of completion, and it is more important than most people realise.
Why the signature alone is not enough
Look at a signed page. You see a name in handwriting.
You cannot see when it was signed, whether the person actually opened the document or clicked through blindly, which address they came from, whether anyone else was involved, or whether the file you are holding is the one they signed.
The certificate of completion answers all of it.
What is on it
About the document
- The document title and file name, and its page count.
- Where it is part of a set, a note saying how many documents were signed together and which one this is.
- A request ID, printed on every page of the certificate.
- The fingerprint before signing: a SHA-256 value for the original document, so the starting point is fixed.
- When the request was completed.
About each recipient
- Name, email address and their role: signer, approver, witness or receives a copy.
- When they opened the document.
- When they signed or approved it.
- The IP address they were at, and a short device description such as "Chrome on Windows".
- How many fields they completed.
- For a witness, whose signature they witnessed.
- If someone passed their turn on, who to, when and why: and on the other side, who they took over from.
- If the sender hosted them signing in person, that too.
Attachments
If signers uploaded files into attachment fields, they are listed with their own fingerprints.
Timeline
Every event in order, with its time: created, sent, viewed, signed, approved, declined, reminders, reassignments, copies sent, completion. This is the part that answers "but when exactly did they...".
The seal
If the finished file could be sealed with a trusted timestamp, the certificate says so and explains what it means. If the seal could not be applied, the certificate says that instead, and tells you to compare the fingerprint. It never claims a seal that does not exist.
The everyday version
A signed contract is like a photograph of a handshake. It shows the moment.
The certificate of completion is the security camera footage: who walked in, at what time, from which door, what each of them did, and in what order.
One is the result. The other is the proof.
Why it matters in practice
- "I never received it." The timeline shows when it was sent to which address, and when it was opened.
- "I never agreed to that." The record shows the document opened, the fields filled in, the agreement confirmed, and the exact time.
- "That's not the version I signed." The fingerprint fixes exactly which file it was.
- "Someone signed on my behalf." The reassignment record shows who handed over, to whom, and the reason they gave.
The seal, and why it protects the certificate too
The finished file is sealed with a trusted timestamp when the timestamp service can be reached. That seal covers the whole file, including the certificate of completion, so the record cannot be edited any more easily than the document.
You can check it yourself. Open the finished PDF in Verify PDF Signature: a valid timestamp means nothing has changed since completion. See what a trusted timestamp is.
What it honestly does not claim
The certificate says this in its own words, and it is worth repeating: the signatures in the document are electronic signatures made in the signer's browser. They are not certificate-based digital signatures belonging to each signer. IP addresses are as seen by the server. And whether an electronic signature is sufficient for a particular document depends on the law that applies to it.
If you need each signer to hold their own certificate, that is the Digital Signature tool instead.
Practical advice
Keep the whole file. The document and the certificate are one PDF. Do not print just the first pages, do not re-export, do not "clean it up". That removes the seal.
Check it when you receive one. Thirty seconds reading the timeline tells you far more than looking at the signatures.
Common questions
What is a certificate of completion?
A report attached to the finished signed document listing everyone involved, what each of them did, when, from which IP address, along with the document's fingerprint and a full timeline of events.
Why do I need it if the document is already signed?
The signature shows the result; the certificate shows the process. It is what answers questions about when a document was opened, what was filled in, and whether anyone passed their turn on.
Can the certificate of completion be edited?
It is part of the same PDF and, when the timestamp service can be reached, the whole file is sealed. A checker will show the seal as broken if anything changed afterwards.
Does the certificate prove the signers' legal identity?
No. It records email addresses, times, IP addresses and devices. It states plainly that the signatures are electronic signatures made in the browser, not certificate-based digital signatures.
Should I keep the certificate with the document?
Yes. They are one file. Printing or re-exporting only part of it loses the record and the seal.
What if the file could not be sealed with a timestamp?
The certificate says so and tells you to compare the document's SHA-256 fingerprint with the one shown in the sender's account to confirm it is unchanged.