The difference between a drawn signature image and a cryptographic signature — and which one your counterparty needs.
The two terms get used interchangeably and they are not the same thing. One is a picture of intent. The other is a mathematical claim about the document's integrity and the signer's identity. Most agreements are fine with the first; some are not.
Electronic signatures
An electronic signature is any electronic mark made with intent to sign: a typed name, a drawn squiggle, a checkbox, a click on an 'I agree' button. In most jurisdictions — including the EU under eIDAS, the US under ESIGN/UETA, and South Africa under ECTA — a plain electronic signature is legally valid for the large majority of commercial contracts.
What makes it defensible is not the image; it is the surrounding evidence. Timestamp, IP address, email verification, an unbroken audit trail, and a copy of what the signer actually saw at the moment of signing. If a signature is challenged, the audit trail is the exhibit — not the squiggle.
Digital signatures
A digital signature is a specific cryptographic mechanism: a hash of the document is encrypted with the signer's private key, and a certificate from a trusted authority binds that key to an identity. Any change to the file after signing invalidates the signature, visibly, in any compliant reader.
This gives you two things a drawn signature cannot: tamper-evidence, and identity attested by a third party rather than by the signer's own claim.
Which do you need?
- Standard commercial contracts, NDAs, engagement letters, quotes: electronic signature with a solid audit trail is normal and accepted.
- Documents filed with a court or public registry: check the specific requirement — many mandate a qualified digital certificate.
- Wills, certain property transfers, some notarial acts: frequently excluded from electronic signing entirely. Check local law.
- Cross-border deals into the EU where the contract specifies a Qualified Electronic Signature: you need a QES from a listed trust service provider. Nothing else satisfies it.
Practical mistakes to avoid
- Signing, then editing. Any post-signature edit — even adding page numbers — invalidates a digital signature and undermines an electronic one.
- Flattening a signed PDF. It destroys the signature object while leaving the visual mark, which looks fine and proves nothing.
- Merging signed documents. Merging always breaks digital signatures. Attach them as separate files instead.
- Keeping only the final PDF. Keep the audit trail alongside it; the PDF alone is weak evidence.
A reasonable default
For everyday business documents: sign electronically, capture a timestamped audit record, lock the document afterwards so nothing can be edited, and store the signed file and its trail together. Escalate to a certificate-based digital signature only when a counterparty or a regulator asks for one — and when they do, ask them exactly which standard they require, because 'digitally signed' means at least four different things in practice.
Try it on your own PDF
Upload a document and put these ideas to work in under a minute.
Open PDFalot →