Skip to content
Request access
Legal compliance · United States US

Electronic signatures in the United States, with attribution evidence built in.

The ESIGN Act and the Uniform Electronic Transactions Act (UETA), adopted in 49 states (New York has its own ESRA), give electronic signatures the same effect as handwritten ones. US law has no signature tiers: under UETA §9 a signature is attributable to a person if it was "the act of the person", and the party relying on it must prove that. Courts have rejected e-signatures when the platform could not show who signed (Ruiz v. Moss Bros.). Our evidence package is built for that burden. Biometric data is regulated state by state, with Illinois BIPA as the strictest.

MeetsE-signature with legal effectMeetsTraceability and audit trailMeetsImmutable integrity and timestampsPartialBiometrics with consentMeetsEvidence retentionPartialPromissory notes / negotiable instruments

Legal review as of 2026-10-01. Legal information on this site is for guidance only and is not legal advice.

Applicable law

The legal framework, law by law.

ESIGN Act (15 U.S.C. §7001 et seq.)

Federal: a signature or contract may not be denied effect solely because it is electronic. §101(c) consumer consent disclosures. §7003 exclusions.

Uniform Electronic Transactions Act (UETA)

Adopted in 49 states, DC and territories. §9 attribution; §12 record retention; §16 transferable records.

New York ESRA (State Technology Law, art. 3)

New York’s own e-signature statute, in place of UETA.

Illinois BIPA (740 ILCS 14)

Written release before collecting biometrics, a public retention and destruction policy, and a private right of action. Since 2024, one violation per person.

Texas CUBI and Washington RCW 19.375 / MHMDA

Notice and consent for biometric identifiers; destruction within set periods. Washington’s My Health My Data Act also covers biometrics.

CCPA / CPRA regulations

Biometrics are sensitive personal information. Risk assessments required from 1 Jan 2026 for processing that includes biometric identity verification.

What we offer

Electronic signatures with traceability, audit trail and immutable integrity.

Traceability

Every step is recorded: sending, opening, identity check, consent and signature, with date, time, IP and device.

Audit trail

A complete evidence package and a verifier any expert runs on their own machine, without relying on us.

Immutable integrity

PAdES signature, a SHA-256 event chain that rejects changes and deletions, timestamps, Bitcoin anchors and 10-year custody.

Compliance table

Requirement by requirement.

RequirementLawHow we meet itStatus
Legal effect of electronic signaturesESIGN §101(a); UETA §7Signature with verified identity, explicit intent to sign and a complete evidence package.Meets
Attribution to the signerUETA §9Identity check, one-time codes, IP and device data, optional liveness video and an independent verifier.Meets
Record retention and accurate reproductionESIGN §101(d); UETA §12Signed PDF, SHA-256 fingerprint, RFC 3161 timestamps, Bitcoin anchors and WORM custody for 10 years.Meets
Consumer consent disclosuresESIGN §101(c)Not yet built in. Required before delivering legally required information to consumers electronically.Partial
Excluded documentsESIGN §7003; UETA §3Wills, family law, most UCC articles, court documents and certain notices are outside the scope. The issuer chooses the document.N/A
Biometrics: written release (Illinois)BIPA §15(b)Separate, optional biometric consent signed electronically, with a non-biometric alternative.Meets
Biometrics: public retention and destruction policyBIPA §15(a); Texas CUBIBIPA requires destruction when the purpose ends and within 3 years of the last interaction. This conflicts with 10-year evidence retention, so we recommend standard verification for Illinois signers.Partial
Sensitive personal information risk assessmentCCPA regulations (2026)The business using biometric identity verification must complete it.Partial
Electronic promissory notesUETA §16; ESIGN §201Enforceable as a signed contract; transferability as an eNote requires a control system we do not provide.Partial
Data protection

Personal data and biometrics.

LawNo general federal privacy law. State laws: CCPA/CPRA (California) and about twenty comprehensive state laws; biometric laws in Illinois (BIPA), Texas (CUBI) and Washington.
AuthorityFederal Trade Commission (FTC) and state attorneys general; California Privacy Protection Agency
Biometric dataBIPA: written release, public retention and destruction schedule, no sale, private right of action ($1,000 to $5,000 per violation). CCPA: sensitive personal information with the right to limit its use.
RightsCCPA: respond within 45 days, extendable by 45 more.
Security breachesState breach-notification laws in all 50 states; deadlines vary (often "without unreasonable delay", 30 to 60 days in many states).
International transfersNo general restriction on transfers abroad. The DOJ bulk sensitive data rule (28 CFR Part 202) restricts transfers of bulk biometric data to countries of concern.
What you should know
  • US law has no presumption for any electronic signature: under UETA §9 the relying party proves attribution. The evidence package is built for that.
  • Consumer disclosures under ESIGN §101(c) are not built in yet.
  • Illinois signers: BIPA’s destruction deadline conflicts with long evidence retention. We recommend standard (non-biometric) verification.
  • Excluded by statute: wills and testamentary trusts, family law, court orders, utility cut-off and foreclosure notices, product recalls, and most UCC articles other than 2 and 2A.
Recommended uses
  • Commercial agreements, NDAs, and service contracts.
  • Employment onboarding, policies and acknowledgments.
  • Consents and authorizations.
  • Purchase orders, invoices and internal approvals.
FAQ
Is an electronic signature legally binding in the US?

Yes. ESIGN and UETA give it the same effect as a handwritten signature, except for excluded documents such as wills and family-law matters.

Who has to prove that the signer really signed?

The party relying on the signature (UETA §9). Courts look at the security procedure used. That is why we record identity checks, one-time codes, device data and timestamps.

Can I use liveness checks with Illinois residents?

BIPA requires a written release and a public policy to destroy biometrics within set periods. We offer it as optional with a non-biometric alternative, and recommend the standard path for Illinois.

What is the difference between an electronic signature and a digital signature?
Electronic signatureDigital signature
What it isAny method that identifies the signer and shows they approve the document.A type of electronic signature that uses a certificate issued in the signer’s name by a certification authority.
How the person is identifiedAt signing time: personal data, a one-time code and, if chosen, an ID document and a liveness check.When the certificate is issued; afterwards the person signs with a key, token or app.
What the signer needsA phone or computer. Nothing to install or buy.A valid, paid, renewable certificate, often with a token or an app.
How it is proved in a disputeWith a full audit trail: who signed, when, from where and what, in an immutable record.In many countries the certificate gives a legal presumption of authorship.
IntegrityPAdES signature, SHA-256 fingerprint and an immutable event chain: any change is detected.Cryptographic signature with the certificate: any change is detected.
Typical usesThe vast majority of private contracts and documents.Procedures and documents where a law or the other party requires it.

Both are legally valid. For most private documents, an electronic signature is enough. In the United States there are no signature tiers: ESIGN and UETA treat every electronic signature the same, and certificate-based signatures are mostly used where a counterparty asks for them.