What a signature is worth: the anatomy of signing infrastructure
Electronic signing is treated as a solved problem: a service, a click, a certificate. The click is the easy part. What the signature is worth depends on everything around it, and the surroundings are where most signing arrangements are weakest.
01What a signature has to prove
Strip away the interfaces and a signature is a claim that must survive challenge. It has to establish four things. Who signed: a specific person, not an email inbox that several people can open. What exactly was signed: this document, in this exact form, down to the last character, not a near version of it. When: a moment in time that a third party can rely on, not a timestamp taken from a clock anyone could set. And that nothing has changed since: the document in front of the examiner today is, demonstrably, the document that was signed.
Every one of these is a question of evidence, not of ceremony. A signature that cannot answer all four is not a weaker signature. In a dispute it is barely a signature at all, because the challenge will simply be aimed at the question it cannot answer.
02The weakest link is not the mathematics
The cryptography inside a modern signature is, for practical purposes, sound. It is also, for practical purposes, never where a signature fails. Signatures fail in the surroundings: in what was actually known about the signer's identity at the moment of signing, as opposed to at account creation months earlier; in what happened to the document between drafting, sending, viewing and signing, and whether that lifecycle is recorded or merely assumed; in where the evidence of all this is kept, by whom, and under what discipline. An examiner does not attack the seal. The examiner asks who held the pen, what page was actually on the table, and who has been keeping the file since. The mathematics answers none of those questions. The record around it does, or does not.
03Custody of the evidence
Here the anatomy becomes uncomfortable. In the common arrangement, the signed document, the audit trail, the identity record and the timestamps all live inside a service the parties merely subscribe to. The signature is expected to prove things for ten or twenty years; the subscription runs month to month. If the service is discontinued, restructured, acquired, or simply changes what its records look like and what it will export, the evidence beneath the signature changes with it, and the parties learn about it afterwards. This is what it means to say that such a signature is a promise about someone else's business continuity. The commitment is yours. The proof of it belongs, in every practical sense, to an organisation with no stake in your dispute and no duty to still exist when the dispute arrives.
Periodic exports are the usual reassurance, and they miss the point. An export is a copy of what the custodian chose to make exportable, in the format it chose, complete only to the extent that anyone ever verified it. The audit trail behind the signature, the identity checks, the exact sequence of events, rarely travel whole. What arrives is a document with a receipt, when what was needed was the file that proves the receipt. Custody delegated and custody exercised are different states, and an examiner recognises the difference at a glance, because only one of the two can be questioned in the room.
04End to end, taken seriously
The phrase "end to end" is used loosely in this industry. Taken seriously, it names an unbroken chain with four links. The request: who asked whom to sign what, recorded before anything is signed. The act: the moment of signing itself, with identity established at that moment and bound to that exact document. The seal: the making of the record tamper-evident, so any later alteration is detectable by anyone who examines it. The archive: the keeping of the whole file, act and evidence together, under one custody, for as long as the commitment lasts. The chain is only as strong as its custody. If the four links live in four places, or in one place you do not control, the chain has a fifth link nobody signed: trust in an outsider's continuity.
05The house position
Mulium's answer to this anatomy was to build its own signing infrastructure in-house, end to end, and to keep the entire chain, request, act, seal and archive, in its own custody. The reasons are the ones set out above, and they are not unique to this firm. Any organisation whose signed commitments outlast its software subscriptions faces the same question, whether or not it has asked it yet. The question is worth asking while things are quiet: for each signature your organisation relies on, who could answer the four proofs today, and would they still be there, and still answerable, in the year the signature is challenged. Where the answer depends on someone else's continuity, that is not a detail. It is the actual worth of the signature.
The line's records on this domain date from 2011. If your organisation relies on signatures whose evidence it does not hold, the time to examine that chain is before it is tested.