Valid and admissible under ECTA for most commercial agreements.
This page says what a Vumasign signature is, what it is not, and how a document is checked years after everyone has moved on. It is written plainly and it is not legal advice — have your attorney read it.
Cryptographically sealed and timestamped, so tampering is detectable.
When an envelope completes, Vumasign applies a PAdES seal with a trusted timestamp to the PDF. Change a single byte afterwards and the seal breaks. The seal is checked by the reader, not by us — Adobe Reader shows it as valid with no Vumasign account and no Vumasign server involved.
A sealed PDF is the evidence. Vumasign is how it was made.
- Signed by
- Vumasign (Pty) Ltd — document seal
- Signing time
- 2026-09-09 14:02:41 SAST · trusted timestamp
- Certificate
- AATL-chained · valid to 2028-03-14
- Standard
- PAdES B-LT
A complete record you can put in front of a court.
Every action on an envelope is recorded with who, when, from which address, and how they were identified. The trail is embedded in the sealed PDF and exportable on its own.
| Time (SAST) | Event | Who | Identified by |
|---|---|---|---|
| 09 Sep 13:41:07 | Envelope sent | Thandi M. (sender) | Account login |
| 09 Sep 13:41:09 | Email delivered | s.dlamini@… | — |
| 09 Sep 13:52:30 | Document opened | Sipho D. (employee) | Email link · SMS code · 196.25.x.x |
| 09 Sep 13:58:12 | Signature applied · p.2 field employee.signature | Sipho D. (employee) | Same session |
| 09 Sep 14:01:55 | Approved | Thandi M. (employer_hr) | Account login |
| 09 Sep 14:02:41 | Envelope completed · PAdES seal applied | Vumasign | Trusted timestamp |
We do not say "POPIA compliant". Here is what we say instead.
Compliance is a property of your processing, not of software. What a platform can do is remove obligations from your list. Sending a document through an offshore platform moves personal information out of South Africa and engages POPIA s72: you must justify the transfer on one of five grounds and evidence it.
Vumasign stores and processes in Google Cloud africa-south1, Johannesburg, and the operator is a South African company. There is no cross-border transfer to justify. We act as your operator under a written operator agreement; you remain the responsible party.
- Data stored and processed in South Africa, for every account, on every plan
- A written operator agreement (s21) you can attach to your records
- A South African operator with a registered company, named people and a physical address
- Export of every document and audit trail, documented, so you can leave
Lawful basis, purpose, retention, and the rest of your processing. Compliance is yours; we make one line of it shorter.
What we say, and what we do not.
A company that tells you exactly what its product is makes a credibility claim about everything else it says. So:
| We say | We do not say |
|---|---|
| Valid and admissible under ECTA for most commercial agreements | “ECTA compliant” · “legally binding”, unqualified |
| Cryptographically sealed and timestamped, so tampering is detectable | “Advanced electronic signature” |
| A complete audit trail you can put in front of a court | “Court-proof” · “guarantees enforceability” |
| Hosted in South Africa, so there is no s72 transfer to justify | “POPIA compliant” · “POPIA certified” |
Where a statute requires a specific signature type, or a document must be signed in a particular form, that is a question for your attorney — and the same is true on every signing platform sold in South Africa.
Sign a real document. Then check the seal yourself.
No account. Sign, download the sealed PDF, open it in Adobe Reader and watch the signature validate. That is what a recipient's lawyer will do in two years.