Skip to main content

Document integrity & audit

A signed document is only worth as much as the proof that it wasn't altered after the fact. HridaSign keeps two records for that: a cryptographic fingerprint and an append-only audit trail.

The document fingerprint​

When every signer finishes, the backend computes a SHA-256 hash over a deterministic fingerprint of the document:

  • the title and the source file id
  • every signed field's value, in a fixed order (sorted by field id)
  • each recipient's signing metadata

The hash is stored on the SignDocument (document_hash).

Verifying it​

GET /api/sign/{docId}/integrity recomputes the fingerprint from the current state and compares it to the stored hash:

{
  "documentId": 42,
  "intact": true,
  "storedHash": "…",
  "computedHash": "…",
  "message": "Document integrity verified"
}

If a stored field value or recipient record has been changed, intact is false and the message reads TAMPERED — hash mismatch. The check itself is logged as INTEGRITY_CHECK_PASSED or INTEGRITY_CHECK_FAILED.

The audit trail​

GET /api/sign/{docId}/audit returns every event on the document, append-only, each row capturing the actor's email, IP address, user-agent, a timestamp, and optional metadata:

ActionWhen
DOCUMENT_CREATED · DOCUMENT_SENTThe owner sets it up and sends
DOCUMENT_VIEWEDA recipient opens their link
OTP_SENT · OTP_VERIFIED · OTP_FAILEDEmail-OTP identity checks
DOCUMENT_SIGNED · DOCUMENT_DECLINEDA recipient signs or refuses
DOCUMENT_COMPLETED · DOCUMENT_CANCELLED · DOCUMENT_EXPIREDTerminal states
INTEGRITY_CHECK_PASSED · INTEGRITY_CHECK_FAILEDA verification was run

Together the fingerprint answers "is this the document that was signed?" and the trail answers "who did what to it, from where, and when?".

Hrida.ai is proprietary software of Zlabs Innovation. See the license for terms. © 2026 Zlabs Innovation.