Reference guide · Knowledge centre

A guide to verifying electronically signed contracts

Everything you need to know about the verification tool: how it works computationally, what each result means, where to find the number, and why party data is shown masked. The verification itself is done straight from the tool.

Open the verification tool

How does verification actually work?

Verification is not an “opinion” the platform issues; it is a repeatable computation. The whole idea is that we fix a digital trace of the document at the moment of signing, then recompute it at every check and compare. If the result differs, something has changed.

At the moment of signing: a SHA-256 fingerprint is computed

When signing completes, a digital fingerprint is computed with the SHA-256 algorithm over the document content together with the signer’s name and the signing date, and that fingerprint is stored in the signature record. The fingerprint is a fixed-length string from which the text cannot be recovered.

Change a single letter — even a single space — in the contract text and the fingerprint is completely different. That is why the fingerprint is used to detect changes, not as a means of encryption.

Issue a unique verification number and a QR code

The document is given a unique verification number that appears on the signing completion certificate, accompanied by a QR code carrying a link to this very page. The number is a search key only: it holds no contract data and reveals nothing of its content to anyone who sees it.

Having the number on the certificate means that any party you share the contract with can run the check themselves, without your granting them any access to your account.

At inspection: recalculate and compare

When you enter the number here, we retrieve the matching document record, recompute the fingerprint from the content currently stored, then compare the result with the fingerprint stored at the moment of signing. The comparison is entirely automatic: no human intervenes, and the result is never edited by hand.

That is why three different results appear: match, no match, or “no stored fingerprint to compare against” for older documents.

The result: a clear verdict + the parties + the event log

The status appears at the top of the page in a colour with a definitive statement, then the document details, its number, signing date and full fingerprint, then the contract parties in masked form, then the event log: every event with who performed it, when, and a masked IP address.

You can print the result or save it as a PDF from the button at the top of the page, giving you a dated record of exactly what appeared on screen at the moment of the check.

Verification is public by design. The page does not ask for a sign-in, does not display the contract text, and does not reveal the parties' full details. Anyone holding the number can confirm Validity the document itself — and that is exactly what an outside party needs before doing business. For the full detail of the signing cycle, see How the platform works.

What does “intact” mean and what does “modified” mean?

This is the most important paragraph on the page. The two words look simple, but the difference between them is the difference between a document you can rely on and one that needs reviewing before any decision. The table below reads out every possible result precisely.

What appears on screenWhat it means preciselyWhat you do
Genuine · Unaltered The signing record exists and is complete, and the fingerprint recalculated just now matches the fingerprint stored at the moment of signing.

This means the text that was signed has not changed since signing.

Approve the document. Save the verification number and its link with your copy in the file.
Original and authenticated (no fingerprint) The document is signed and registered with us together with its time record, but it predates fingerprint registration, so there is no stored fingerprint to compare it against.

The signature and the time record stand; what is missing is the computational proof of “no modification”.

Rely on the signature and the audit trail, and ask the other party to issue a fresh copy if you need to compare fingerprints.
Content integrity could not be confirmed The signature is there, but the recomputed fingerprint does not match the stored one — meaning the current content is not the same content that was signed.

The text may have been edited or regenerated after signing.

Do not rely on the copy. Compare it with the version you hold, and check with the sending party before committing to anything.
Awaiting signature The document is valid and registered, but not all of its parties have signed yet (this appears with multi-party PDF contracts). Wait for completion. A contract missing a signature is not treated as a binding contract.
Not found No signed record matches the number entered: the number may be wrong, the document may not have been signed yet, or it may not have been issued by Wthaiq at all. Review the steps in the section What to do if verification fails.

“Valid” = a computational match

It does not mean that an employee reviewed the contract; it means the SHA-256 value computed now is exactly equal to the value stored at the moment of signing. Faking that match with different text is practically impossible.

“Modified” = a discrepancy detected

The new fingerprint differs from the stored one. The platform does not guess the reason for the difference, nor does it hide it; it raises it as an explicit warning so you can decide before relying on the copy.

What verification does not tell you

This page does not assess whether the contract's terms are fair, whether the parties had capacity, or whether the details each party wrote about themselves are accurate. It establishes the origin and the integrity of the content only.

Where do you find the document number or the verification number?

Most failed verification attempts come down to a number that is incomplete or copied wrongly. Here is where the number appears, and which route is quickest.

The QR code — the fastest and most accurate route

Point your phone camera at the code on the signing completion certificate, and this page opens with the number already filled in. No copying by hand, and no chance of getting a character wrong.

The signing completion certificate

The certificate attached to the signed contract carries the verification number in bold type, along with the digital fingerprint, the parties' details and the event log. Learn what it contains in E-signature certificate.

The signing completion email

The email that reaches the parties to the contract when signing is complete carries the number and the verification link. Search your inbox for the contract message rather than retyping the number from an image.

Your account on the platform

If you were the one who sent or signed the contract, you will find the document and its number inside Your document list after signing in to your account.

The shape of the number, and what does not affect it

The number usually starts with WTQ and it consists of groups of letters and numbers separated by dashes, such as WTQ-XXXX-XXXX-XXXX. When you search, we normalise the number automatically: letters are converted to upper case and dashes are ignored. So wtq1234abcd andWTQ-1234-ABCD lead to the same result.

What affects Indeed: look-alike characters when copying by hand — zero and the letter O, the digit 1 and the letter I — and any missing or extra character. That is why the QR code, or copy and paste, is always the safer route.

Why do we hide some names and details?

The verification page is public: anyone holding the number can open it. If we displayed full names, emails and IP addresses, the verification number would become a key for leaking the contract parties’ data. So we show only what proves validity, and mask what does not need to be shown.

Names anonymised

The first letter of each word in the name is shown and the rest is replaced with dots. That is enough for someone who knows the other party to recognise the name, and not enough for a stranger to gather data.

Mohamed Ahmed → M•••• A••••

Email partially masked

Part of the email is shown so you can recognise it if you already know it, without publishing it in a form that can be copied and used for spam or phishing attempts.

IP address masked

The event log shows that an event came from a particular address without revealing it in full, so the log stays useful for investigation without turning into tracking of people's whereabouts.

The page never displays the text of the contract

nor its amounts, its terms or its attachments. Whoever holds the number sees only the validity verdict and descriptive data. The contract’s content stays between its parties, in their accounts.

Who sees the full details?

the contract parties themselves from inside their accounts, and in their copy of the signing completion certificate. The public page is a deliberately reduced view.

Data minimisation is a principle, not a flourish

We publish the least that serves the purpose. This is consistent with Egypt's Personal Data Protection Law No. 151 of 2020, which is founded on limiting processing and publication to the legitimate purpose. Fuller details in Compliance and law andTrust centre.

What do you do if verification fails?

“Document not found” is not necessarily a sign of forgery; more often the cause is the number itself or the contract's status. Work through these steps in order before you escalate.

  • Check the number character by character

    Look for the usual confusions: zero versus O, the digit 1 versus I, and a missing character in the last group. Dashes and letter case are not a problem — we ignore them automatically.

  • Paste the number rather than typing it

    Copy it from the email or from the signing completion certificate, or scan the QR directly. Most failures end at this step.

  • Confirm that signing is complete

    A document becomes verifiable once it has actually been signed. If the contract is still out for signature, no signed record will show for it yet.

  • If the contract is a PDF file, search by the document number

    PDF contracts signed by overlay are checked by document number, not by verification number. Use the field below or open the original QR link exactly as it reached you.

  • Open the original link exactly as it reached you

    The link in the email or in the QR code carries the number in its correct form. Avoid rebuilding the link by hand.

  • Go back to the party who sent the contract

    Ask them to resend the signing completion certificate and the verification link from their account. If they cannot, the document may not have been issued by the platform at all.

A single box that accepts all three kinds: the verification number from the certificate, the document number issued for overlay-signed PDF contracts, or the number carried by the QR code. The result opens in the verification tool.

If the warning “Content integrity could not be confirmed” appears, the situation is entirely different. Here the document exists on our side but its content does not match its original fingerprint. Stop relying on the copy you hold, save a screenshot of the verification result with its date, compare your copy with the other party's, then contact them before any commitment or payment.

For lawyers and auditors: the value of this page as an evidentiary record

The value of the verification page is not the word “valid” but the fact that it is a technical trail a third party can inspect for themselves, with no intermediary and without relying on one party's word.

Linking the text to the signature

The fingerprint is computed over the content together with the signer’s name and the signing date, so a signature cannot be moved from one text to another without the discrepancy showing up on inspection.

A time-stamped event log

The log records the sequence of what happened: opening, signing, OTP verification and the rest, with the actor, the time and a masked IP address. This sequence is what is normally examined when a signature is denied.

Authenticating the signer's identity

When the signature is accompanied by OTP verification, that shows in the parties' row and in the log. It is an extra element linking the signature to a communication channel the signer controls.

Signature levels

PDF contracts produce a final copy with its own SHA-256 fingerprint, and they may be sealed with a PAdES digital signature that is checked inside the file itself. The differences are explained in detail in The signing certificate page.

What you attach to the file in practice

  • The final signed version of the contract.
  • The signing completion certificate with the fingerprint and the event log.
  • the verification number and the link to this page, for anyone who wants to check.
  • A printed or PDF copy of the verification result with the date it was checked.

The legal framework and its limits

Egypt's Electronic Signature Law No. 15 of 2004 and its executive regulations govern electronic signatures and the conditions for relying on them, while the Personal Data Protection Law No. 151 of 2020 restricts the processing and publication of data to the legitimate purpose — which is why the data on this page is masked.

By the same token, this page does not assess the substance of the contract, its enforceability or the capacity of its parties; what appears here explains how the platform works and is not legal advice.

Who actually uses this page?

Verification removes a great many steps that used to take calls and emails just to confirm one piece of paper.

Shipping company

A new supplier asks for confirmation of the service contract before the first shipment. You send them the verification number and they check it themselves in a minute, instead of you sending scans and photographed signatures.

Law firm

The copy of the contract, the completion certificate and a printed verification result with its date are added to the case file, so the technical trail is ready for examination by the opposing party or the expert.

Human resources department

A new employee wants to be sure the employment contract they signed is the very same final version the company kept, with no later changes.

Payments and collection

Before releasing a payment or settling an amount due, the finance team checks the contract the request rests on and confirms that its content has not changed since signing.

A useful habit: keep the verification number and its link in the same folder or the same email where you keep the contract. That way the check stays available years later without hunting for the certificate. Broader examples of using the platform are in How we help andUse cases.

Frequently asked questions about verification

Questions asked by anyone opening this page for the first time — external parties especially.

Do I need an account or a login to verify?

No. The page is entirely public, and the verification number, the document number or the QR code is all it takes. That is deliberate: the party that needs the reassurance is usually not a party to the contract and has no account.

Can whoever holds the number read the contract?

No. The contract text is not shown, nor its amounts, nor its attachments. What appears is: the validity verdict, the contract's name, its number, the signing date, the fingerprint, masked parties, and an event log with masked IP addresses.

Does the verification link stay valid over time?

The link is permanent and tied to the verification number itself, and it works for as long as the document's record exists on the platform. That is why we recommend saving the link with your copy of the contract rather than relying on searching for it later.

We signed a multi-party contract — can it be verified?

Yes. The contract’s verification number shows its status, its parties and its event log in exactly the same way. In multi-party PDF contracts, each party’s status appears — signed or awaiting — so you know where the cycle has stopped.

Is printing this page good enough as a document?

The print button saves the result of the check as it appeared, with its date, and is useful as a supporting record. But it complements the signing completion certificate rather than replacing it; the certificate is the document issued with the contract.

A fingerprint mismatch warning appeared — does that mean forgery?

means the current content does not match what was signed. The cause may be a later change or a regeneration of the text. The platform does not guess the cause; it states the discrepancy plainly. The right step: stop relying on the copy, save a snapshot of the result, and check with the other party.

Where do I find the rest of the questions about electronic signatures?

in FAQ, and in Resources which brings together every explanatory page, and in Blog for the detailed articles.

Verification is not an extra feature — it is what makes an electronic signature dependable

Any platform can print “signed electronically” on a page. The difference is letting a third party check that claim themselves, with a public tool, and get a result nobody can edit by hand. This page is that check.

Evidence anyone can inspect

A SHA-256 fingerprint stored at the moment of signing, recompared at every check.

A trail that does not rely on trust

A timestamped event log with an actor and a time for every step, not one party's word for it.

Available to everyone

No account, no permissions, and with masking that protects the parties' data.

Try it from the other side

Create a contract, walk through the full signing cycle, then check the result on this page yourself. The best way to trust a tool is to test it.

This page explains how the verification tool on the Wthaiq platform works, what it proves and what it does not prove. It is not legal advice, nor an opinion on the content of any contract.