Security & Compliance

Built to the letter of the Electronic Transactions Act 1999 (Cth).

Siggy gives you a signing record you — and your clients — can independently verify: real consent, a tamper-evident seal, an unbroken audit trail and a certificate. Here is exactly how it works, and exactly what we do and don't claim.

The Act, mapped to the product

What ETA 1999 asks for — and how Siggy delivers it

New to the Act? Start with how the Electronic Transactions Act applies to everyday documents.

Consent to sign electronically

Before any signature, the signer is shown an electronic-signing consent notice and must explicitly agree. Declining records the choice and signs nothing.

Identification of the signer & their intention

Each signer reaches the document through a unique, single-use tokenised link sent to their email. They affirm their intention to be bound before submitting, and their IP address and UTC timestamps are recorded.

Reliability appropriate to the purpose

The completed PDF is sealed with a PAdES digital signature. A single altered byte invalidates the seal — so the signed record is demonstrably the one the parties saw.

A retained, verifiable record

Every event is written to an append-only, hash-chained audit trail and summarised in a Certificate of Completion delivered to all parties. Any tampering breaks the chain on verification.

The technical guarantees

Evidence you can verify, not just trust

Append-only, hash-chained audit

Each audit event embeds the hash of the one before it. Re-ordering, editing or deleting any event is detectable — verification fails loudly.

PAdES tamper-evident seal

On completion the document is cryptographically sealed. The seal covers the exact signed bytes; alteration is mathematically detectable.

SHA-256 from the first second

We hash the original PDF the moment it is uploaded and the sealed PDF on completion, so the chain of custody is provable end-to-end.

Certificate of Completion

An auto-generated certificate lists every recipient, their consent and signing times, IP addresses and the audit trail — independently of any single document.

Australian data sovereignty

Hosted in Australia. Your documents and your clients' details never leave infrastructure you can name to your own clients.

Privacy by architecture

Your signers are never tracked, profiled or advertised to — the signing experience, identity verification and the signed-in app carry no analytics of any kind. We use Google Analytics on our public marketing pages only; see our privacy policy.

What we don't claim

Honest about the boundaries

Trust is earned by being precise about limits, not by overstating them. So, plainly:

  • Siggy documents the electronic signing method used. It does not — and cannot — determine that any particular document is legally binding. Where a transaction needs specific formalities or witnessing (see when a deed needs a witness), obtain independent legal advice.
  • We do not currently hold Adobe Approved Trust List (AATL) or eIDAS trust-list membership, and we do not assert an ISO 27001 certification. Instead of asking you to trust a badge, we give you a self-contained, independently verifiable seal and audit trail.
  • Some documents (certain wills, some statutory declarations and a small set of other instruments) are excluded from electronic signing by law. Siggy is for the everyday engagement letters, authorisations and agreements that are not.

Where Siggy is strong

  • A verifiable record you control, hosted in Australia
  • No per-seat pricing, and no tracking of any kind on signing pages
  • Tamper-evidence that fails loudly, not silently
  • A certificate your clients receive automatically
Try for free