The signature alone is not enough; what stands up to scrutiny is everything around it. In Wthaiq the signer draws their signature with a finger or a mouse and confirms it with an OTP code, and once every party has signed, the document is sealed automatically with a completion certificate bringing together the signers' details, the verification method, a full timestamped audit trail, a SHA-256 fingerprint, and a public verification page with a QR code. This page explains each of those components, why it matters in a dispute, and how to check it yourself.
A paper contract rests on one thing: the look of the signature. That is the weakest thing to rely on, because a signature can be forged, scanned and pasted, and carries in itself no proof of time, identity or the integrity of the text. The certificate turns this around: Instead of inferring the signature from the way it looks, the signature is surrounded by a chain of facts recorded as they happened.
So the certificate isn't read as a ceremonial sheet of paper but as a technical report: every field in it answers a question that really does come up in a review or a dispute. In the sections that follow we go through these fields one by one, then explain how the certificate is bound to the document itself by a mathematical link that cannot be broken, and how you — or your opponent — can verify it through The public verification page without an account.
And if you're starting from scratch and haven't created a contract yet, start from The contract's full journey explained then come back here to understand its authenticated outputs.
The signers' details, the verification method, the timestamps, the IP addresses, the fingerprint of the final text and a public verification code — all gathered into one document attached to the contract.
Any party can match what the certificate says against what the public verification page shows, without taking your word for it or ours.
The drawn signature is just one element of the certificate. If the image were removed and the log remained, the evidence would still stand; if the image alone remained with no log, nothing would be proved.
It is a document the platform issues about the signing that took place inside it. We don't present it as certification from any regulator or as external accreditation — its strength lies in how verifiable its facts are.
The certificate proves that this text was signed in this way at this time. Whether its clauses suit your situation is your lawyer's work; you can also read Ready-made templates as a starting point.
The certificate isn't written by hand and isn't requested from anyone; it is an automatic record of what the parties actually did inside the platform, assembled step by step during the signing round.
Open the contract and draw your signature with your finger or mouse — the drawing is captured and tied to you and to this document specifically.
You'll receive a one-time OTP code and enter it to confirm you own the channel tied to your invitation — proving the act and the identity together.
Each party receives a secure signing link by email, signs from any device, and the platform moves the turn along until the last signature.
The contract is sealed with a completion certificate, an event log, a SHA-256 fingerprint and a public verification page with a QR code — ready for archiving and for use as evidence.
This is an illustrative example of what the certificate looks like and how its information is arranged. The data shown in it is for display only; on your own certificate the fields are filled from the real facts of your signing.
Illustrative example: the names, numbers and timestamps shown above are for display only.
Read the table below once and you'll be able to read — or discuss — any completion certificate with confidence.
A practical addition: From the public verification page you can download the final signed copy, and you can also print the page or save it as a PDF — this is the output usually attached to a case file or an internal review file.
The weakest form of authentication is a “certificate stapled to a contract”: a sheet of paper that can be pulled off and placed on any document. Linking in Wthaiq rests on four loops, each pointing to the others. So the certificate means nothing apart from the document, and the document means nothing apart from its trail.
Every signed copy has its own document number and verification code. The certificate carries both of those numbers, so a search by either one leads to this document and no other.
The SHA-256 fingerprint is calculated over the final content and recorded on the certificate and in the platform's records. The fingerprint doesn't describe the file from the outside; it is derived from its content.
Every event in the log is tied to this document and to its parties: sending, opening, the verification code being sent, its success, then completion.
A QR code and a public link bring the examiner back to the verification page to compare what they hold with what the platform holds — so verification no longer depends on the file that reached them.
What this means in practice: If someone took the certificate for one contract and put it in front of another, the first check would expose them: the fingerprint on the certificate doesn't match the content of the new file, and the document number on the certificate leads, in Verification page to the details of a contract different from the one in their hands.
The closest analogy: a mill that only turns one way. Put a grain of wheat into the mill and flour comes out; from the flour you can never rebuild the grain. The SHA-256 function works on the same logic: you feed it the full contract text and it produces digital “flour” of fixed length — a string of 64 hexadecimal characters — from which the contract text can never be recovered.
And here's the useful part: The mill is extremely sensitive. Mill the same grain twice and you get exactly the same flour, letter for letter. Change the grain by the smallest amount — a digit, a comma, a single space — and the flour comes out completely different, bearing no resemblance to the first and giving no hint of how much was changed.
That is why the fingerprint is calculated the moment signing is complete and recorded on the certificate and on the public verification page. After that the check is simple: the fingerprint of the copy in your hands is calculated and compared with the original. If the two match, the content hasn't changed by so much as a character; if they differ, something has changed and it's worth stopping to look.
The fingerprint doesn't hide the content or encrypt it, and it doesn't stop anyone editing a copy on their own device. What it does, precisely, is make that edit detectable — so the claim “this is the original copy” collapses in the face of a mathematical comparison that leaves no room for argument.
«Contract value: EGP 250,000.»
«Contract value: EGP 350,000.»
The two texts differ by a single character (2 became 3) — and yet the fingerprints differ in 59 of the 64 in the fingerprint, while the length stayed constant as it always does. This is why a “small edit that goes unnoticed” is impossible.
This is the backbone of an electronic signature's legal standing: a precise chronological sequence that starts the moment the contract is sent and ends the moment it is completed, documenting the opening of the document, the sending of the verification code, its success and the completion of signing, with a timestamp and an IP address for every step — leaving no room for the question “did they really sign? and when?”.
The value of the log lies not in its existence but in their order: the events are numbered in sequence and shown exactly as they happened, so the trail tells a single story you can review line by line, and it stays an inseparable part of the final completion certificate and of the public verification page.
| Event | What is recorded with it | What it proves in a dispute |
|---|---|---|
| Send the contract for signature | The sequential event number, the timestamp, the sender's role, the IP address | That the invitation to sign came from the sender's account at a specific time — not after the fact. |
| Contract opened by the other party | The timestamp, the party who opened the document, the IP address | That the party read the text before signing — a direct answer to the claim “I never saw the contract”. |
| Send the verification code (OTP) | The timestamp, and the masked destination it was sent to (last digits only) | That the verification took place through a channel independent of the session in which the contract was opened. |
| Verification successful (OTP) | The timestamp, the IP address, and its link to the signer themselves | That whoever completed the signature controls the channel tied to the invitation — the basis for attributing the signature to that person. |
| Each party's signature | The timestamp of each individual signature, the order of the signatures, the IP address | Who signed first and who followed — settling any argument about when the agreement became binding. |
| Signing completed and certificate issued | The timestamp, the SHA-256 fingerprint of the final text, the verification code | The moment the text was frozen, and which version of it counts when comparisons are made. |
A merchant denies knowing about the commission clause in the onboarding agreement he signed electronically months ago, and asks for his dues to be recalculated.
A former employee claims outstanding payments on the basis of the original contract, and denies signing the addendum that changed the allowance clauses.
A PDF arrives at the office said to be the signed contract, but the amount of the commitment in it differs from the copy the client has on file.
What is PAdES? It is a technical standard for signing PDF files digitally, so that the signature is no longer a statement written on the file but is embedded inside the file's own structure along with a digital certificate. The result is that the signature “travels with the file”: wherever the file goes, its signature data goes with it.
Where it sits in Wthaiq: The platform offers three signature levels according to how sensitive the transaction is, and the highest of them is The accredited signing token: a digital signature using an accredited certificate held on the token, embedded in the file to the PAdES standard. Not every contract of yours is signed at this level automatically; it is the level you choose for transactions that deserve the strongest legal standing. For details see The three signature levels on the “How it works” page.
What does that mean in practice for the PDF? That the file's integrity becomes checkable from inside a PDF reader itself: the reader reads the embedded signature and tells you whether the content has changed since the moment of signing. Any later edit to the text, any deleted page, any regeneration of the file breaks that embedded signature, so the problem shows up instead of slipping past in silence.
Two layers that complete each other. The completion certificate and the audit trail answer “who signed, when, and how was their identity confirmed”; the fingerprint freezes the text; and PAdES adds an independent check inside the file itself that doesn't need the platform. Relying on these layers together is what makes the file resistant to silent editing.
A drawn signature + an OTP verification code. The fastest route for everyday contracts, and it still comes with a completion certificate, an event log, a fingerprint and a verification page.
Verify the signer with an official document and a live face scan before signing — for sensitive transactions.
A digital signature using an accredited certificate on the token, embedded in the file to the PAdES standard. The strongest legal standing.
An illustration of how the check result appears inside a PDF reader for a file signed to the PAdES standard.
You don't have to take our word for it. The check is open to anyone holding the verification code or the document number: no account, no software to install, no fee.
Scan the QR code on the certificate, or open The public verification page straight from any browser.
Type the verification code or the document number exactly as printed on the certificate. Scanning the QR code does this for you.
It shows the document's status, the result of the digital fingerprint comparison, the parties' details and how each of them was verified, and the full event log.
Download the final signed copy, and print the verification page or save it as a PDF to attach to the case file or the review file.
The document was signed through the platform, all of its parties have signed, and its current content matches the original digital fingerprint exactly. This is the result that means: what you are holding is what was signed.
The contract is valid and on record, but not all of its parties have signed yet. The document and party details are shown, and no completion certificate is issued before the last signature.
The document is signed and on record with us, but its current content does not match the original fingerprint — meaning it may have been altered after signing. In practice this is the most important result on the page, because it reveals what the eye cannot.
The number entered is incorrect, or the document is incomplete. In practice it means the file in your hands has no authenticated record with us under that number.
Privacy first: The public verification page does not reveal the contract text. It shows the document's status, its fingerprint, its parties and its event log, and displays sensitive data masked — so a third party can confirm the document is genuine without seeing its commercial secrets. For more on data handling see The compliance and conformity page andTrust centre. A notice may also appear saying the document is old and has no digital fingerprint on record for comparison — a case we show exactly as it is, with no dressing up.
Any party — a court, a lawyer, a partner — can confirm the certificate is genuine by entering the verification code or scanning the QR code, with no account and no fee.
The straight answer: nothing stops your opponent editing their copy on their own device — preventing that is technically impossible. What the platform does is make the edit exposed, and that is what matters in litigation. Below are four common scenarios and what happens in each.
One of the parties opens the file in an editor, changes a number or a date or deletes a phrase, then resends it as “the original”.
A part of the document is cut out, or a new clause slipped in, in the hope that the change passes because the rest of the pages are unchanged.
A PDF carrying an embedded digital signature is edited, then saved again.
A new contract is written in different wording, with the signature image and a certificate copied from another contract pasted into it.
A signed document is never edited — an addendum or a new version is issued and signed by the parties as a separate document with its own number, certificate and log. You end up with an authenticated chain to be read in order, rather than one text whose date is in doubt. Start that from Contract editor or from Ready-made templates.
Many companies think they are “signing electronically” when in fact they are swapping scanned signature images. The difference doesn't show on signing day — it shows on the day of the dispute.
| Point of comparison | A scanned signature (image) | An authenticated electronic signature through Wthaiq |
|---|---|---|
| what it actually is | A signature image pasted into a file, detached from any actual event | An act of signing tied to a session, a specific signer and a specific document |
| Proof of the signer's identity | None — the image can be copied from any old document | A one-time OTP verification code that ties the signature to the owner of the channel |
| Time of signing | A date written by hand or in the file name — changeable | A timestamp recorded by the system for each individual event |
| Source of the signature | Unknown | An IP address recorded for every event in the audit trail |
| Detecting changes made after signing | Almost impossible — scanning hides the traces of editing | A SHA-256 fingerprint reveals any change, down to a single character |
| Event log | None; all that's known is what the parties remember | A numbered log from sending through to completion, attached to the certificate |
| Third-party verification | Needs a paper original and real effort to prove attribution | A public verification page with a QR code: no account, no fee |
| Resistance to impersonation | Copying and pasting a signature image takes no skill at all | The signature is bound to one document, with its own number and verification code |
| Archiving | Multiple conflicting copies in inboxes and device folders | One final copy + a completion certificate + a permanent verification link |
| Where you stand in a dispute | Word against word, and the burden falls heavily on whoever makes the claim | An evidence pack ready to submit: copy + certificate + log + verification output |
For anyone comparing at the operational level: The difference shows in cycle time and follow-up too — collecting signatures goes from days of back-and-forth to minutes, with a clear view of where each party stands. More on this in How we help.
The strength of an electronic signature comes not from the picture of the signature but from the evidence around it. That is why Wthaiq ties every signature to a drawing the signer makes themselves, an OTP verification proving they own the channel their invitation was sent to, a timestamped log documenting every event, and a cryptographic fingerprint that freezes the final text — making it almost impossible to deny or alter the signature later.
The signer draws their signature with a finger or a mouse, then confirms it with a one-time verification code — so the act of signing and the proof of identity come together in a single step.
With every completed contract comes a certificate gathering each signer's name, email and role, the verification method used, and the time of each signature — one document telling the whole story of the signing.
From sending the contract to the last signature: every event is recorded with its time and the IP address it came from, in a chronological sequence that cannot be deleted or reordered.
On completion, a mathematical fingerprint of the final text is calculated and recorded on the certificate. Changing a single character afterwards changes the fingerprint completely and exposes the tampering immediately.
A QR code and a public link on every document let any party — a court, a lawyer, a partner — confirm the contract is genuine without signing in and without any fee.
Connections are encrypted with TLS 1.3 and documents are stored encrypted, with fine-grained access permissions and an audit trail for every action — details in Trust centre.
After the signer draws their signature, the platform sends a one-time secret code (OTP) to the channel linked to their invitation. The code is produced by a cryptographic random generator, is valid for a few minutes only, and is protected by strict limits on the number of attempts and the sending rate so that it cannot be guessed. When the signer enters the correct code, they prove that they own the channel linked to their invitation — so the act of signing and the proof of identity come together in a single moment, and the successful verification is recorded in the audit trail with its time and IP address.
The completion certificate is the document that summarises the entire signing process and is attached to the final contract. It includes a unique document number, the name, email, and capacity of each signer, the verification method used for each party, and the precise timestamp of every signature along with the IP address, in addition to the verification code, the SHA-256 fingerprint of the final text, and a QR code for the public verification page. In short, it is the contract's identity card, answering every question that might be raised when the contract is relied upon: who signed, how their identity was verified, when, and whether the document changed afterwards.
A SHA-256 fingerprint is a «digital fingerprint» produced by running the final text of the contract through a mathematical process that yields a fixed-length string representing the content of the file precisely. Any change, however small — a single character, a space, or a comma — produces a completely different fingerprint. Because the fingerprint is calculated at the moment of completion and fixed inside the completion certificate and the public verification page, comparing the fingerprint of any later copy with the original one reveals immediately whether the file has been tampered with. That is how the integrity of the contract turns from a claim into something that can be proven mathematically at any time.
The person checking needs neither an account on the platform nor a fee. Every verified document carries a QR code and a public verification link; when the code is scanned or the reference number is entered on the verification page, the platform displays the document's status, its validity, its fingerprint, and the time it was completed — without revealing the contents of the contract itself, to preserve privacy. A judge, a lawyer, or a partner can therefore confirm in seconds that the certificate is genuine and that the file has not been altered since it was signed, which gives the contract evidentiary weight that is hard to deny.
Electronic signatures are recognised in Egypt under Electronic Signature Law No. 15 of 2004 and its executive regulations. Every contract signed to completion on the platform receives a completion certificate with the signers' details and verification methods, a full timestamped event log, a SHA-256 fingerprint and a public verification page — together these give the signature evidential weight that is hard to deny, while the assessment of evidence in any given case remains for the court to decide.
After drawing their signature, the signer receives a one-time OTP verification code to enter, confirming they own the channel linked to their invitation. The successful verification is recorded with its time and IP address in the event log, so the act of signing is tied to proof of identity.
A unique document number; each signer's name, email and capacity; the verification method used; the timestamp and IP address of every signature; the verification code; the SHA-256 hash of the final file; the numbered event log; and a QR code for the public verification page — all in a single document attached to the contract.
It is a mathematical fingerprint calculated over the final text the moment signing completes and fixed in the certificate. Any later change, even a single character, alters the fingerprint completely, so comparing it against the original fingerprint reveals that the file has been tampered with.
No — they get a secure signing link by email, open and review the contract, draw their signature from any device and confirm with an OTP code — with no account to create and no app to install.
On the public verification page they scan the QR code or enter the reference number, and the platform shows the document's validity, its hash and when it was completed — without revealing its content, with no account and no fee, for any party that needs to verify.
These are the questions that actually come up in legal review meetings. The answers describe what the platform provides, no more.
Egyptian Electronic Signature Law No. 15 of 2004 and its executive regulations, together with Personal Data Protection Law No. 151 of 2020 as regards processing the parties' data. The details are in The compliance and conformity page.
And we say it plainly: what the platform provides is An evidence pack anyone can examine — a certificate, a log, a fingerprint and a verification page. How much weight this evidence carries in a particular case rests with the trial court's assessment of the evidence, and it would not be right for anyone to promise a court outcome.
Four connected outputs: the final signed copy as you can download it from the platform, the completion certificate attached to it, the numbered event log, and the output of The public verification page printed or saved as a PDF.
The advantage of that last output is that it is Verifiable by the opposing party themselves: nobody is asked to trust what you printed, because the code written on it brings any examiner back to the same result.
that a signature here is not judged as a picture. The drawing is only one element, surrounded by things that cannot be copied and pasted: a timestamp for the opening and for the signing, a verification code sent to the signer's channel and entered successfully, an IP address for every event, and all of it tied to one document number.
and anyone claiming impersonation has to explain how they obtained the verification code sent to the signer's channel at that exact minute.
By mathematical comparison: a SHA-256 fingerprint is recorded on the certificate at the moment of completion, and the verification page states plainly whether the content matches or not. A match knocks the claim down; a mismatch turns the question into: who is holding the altered copy?
And if the file is signed at the accredited signing token level to the PAdES standard, its integrity can be checked from inside the PDF reader directly, as an extra independent piece of evidence.
No. The verification page is public: it opens from a link or a QR scan, and asks for no sign-in and no fee. That is deliberate — a proof tool that needs permission from the interested party is a weak one.
The public page shows only what verification requires: the document's status, its fingerprint, its parties and how each of them was verified, and the event log — with sensitive data masked, and without revealing the contract text.
and data processing is governed by Personal Data Protection Law No. 151 of 2020; the details and the data subject's rights are in The compliance page.
The platform offers three levels: an electronic signature with a drawing and an OTP code for everyday contracts; signing with identity verification using an official document and a live face scan for sensitive transactions; and the accredited signing token, with a digital certificate embedded to the PAdES standard, which carries the strongest legal standing.
The practical rule: raise the level as the value of the commitment or the likelihood of a dispute rises. The full comparison is in The “How it works” page.
The platform does not give legal advice, does not assess whether a contract's clauses suit your situation, does not guarantee that any particular piece of evidence will be accepted by any particular body, and does not present the completion certificate as an endorsement issued by an external regulator.
What we say, precisely: these are the facts of the signing as they happened inside the platform, and these are the tools that let any party examine them for themselves.
This plain speaking is deliberate: a signing platform that sells trust can't build it on overstatement. For more on our security and privacy principles see Trust centre, and for general questions about the service The FAQ page.
Start signing electronically now — every contract comes out automatically with a completion certificate, an event log, a SHA-256 fingerprint and a public verification page with a QR code.