Back to Products
SignVault

SignVault

Document execution with an audit trail that any party can verify independently. API-first, embeddable, and built so that what happened to a document can be proven rather than asserted.

Key Features

  • Hash-chained audit log with a public verification endpoint
  • Affirmative e-consent capture, IP and user-agent stamped
  • PAdES-signed completion artifacts and Certificates of Completion
  • Data-subject erasure via crypto-shredding, without breaking verification
  • Retention realms, legal hold, and scheduled purge
  • WCAG 2.2 AA signer experience

Most electronic signature tools ask you to trust their audit trail. SignVault is built so you don’t have to.

Every state change on a document writes an audit event whose hash commits to the event before it. The chain is appended under lock, in one fixed timestamp format, so it cannot fork under concurrency — and any party holding a completed document can verify the entire sequence independently through a public endpoint. Tamper-evidence is a property of the data structure, not a claim in our marketing.

A core service, not another application

SignVault is deliberately scoped as infrastructure. One organisation, one API key, its own documents. No admin dashboards, no template libraries, no CRM integrations competing with the ones you already have.

That scope is the point. It means SignVault disappears inside the product you are already building, instead of becoming another system your users have to visit and another login they have to remember.

Designed from the obligation backwards

Signer personal data is held encrypted and outside the hashed payload, so an erasure request can be honoured in full without invalidating anyone else’s audit chain. The consent disclosure a signer was shown is immutable once published, because their consent record has to keep resolving to the exact text they saw. Transaction type and jurisdiction have no defaults, because a default is a legal determination made silently on a customer’s behalf.

These are the details that decide whether a record holds up when someone contests it, and they are difficult to retrofit. Building them in from the start costs almost nothing; adding them later is close to a rewrite.

Every capability, and every boundary, in writing

SignVault ships with a published limitations document and a per-jurisdiction compliance matrix covering the US, EU, UK, Brazil, India and China. What the service establishes, and what it does not, is written down before you integrate — not discovered during an audit.

Advanced and Qualified electronic signature tiers, RFC 3161 timestamping, and qualified trust service provider integration are on the roadmap.

Available for integration and design-partner engagements.

EPL Solutions Logo

EPL Solutions Inc. Your partner in digital transformation, providing tailored solutions to drive your business forward.

© 2026 EPL Solutions Inc. All rights reserved.