eSign.AIeSign.AI

Glossary

What Is a Sealed Envelope in E-Signature? Sealing Explained

When an e-signature workflow says a document is "sealed," what does that actually mean? Sealing, sealing certificates, and tamper-evidence explained.

eSign.AI Digital Trust Research Team8 min read

Sealed in 60 seconds

In e-signature products, "sealing" a document means applying a cryptographic lock so that any change to the document after signing is detectable. The document is wrapped with a digital seal — a signed hash or certificate — that binds the final signed state. Open it, and the seal is broken; tamper with it, and validation fails. Sealing is the mechanism that makes "signed and locked" more than a workflow feature: it is a cryptographic guarantee.

Tampering

Detects

Final signed state

Binds

Hash + signature

Backed by

Seal certificate / LTV

Typical output

Tamper-evidence

Purpose

How sealing works

Sealing is a chain of cryptographic steps that locks the document at the moment signing completes.

01

When all signers finish, the platform computes a cryptographic hash of the final document — a fixed-size fingerprint of the exact bytes. Any later change, even a single character, produces a different hash.

02

The hash is signed (by the platform's sealing key or a qualified seal certificate) and embedded in the document as a seal. The seal records the document's state at the moment of sealing.

03

A trusted timestamp is often added so the seal is provably valid at a specific time — critical for long-term validity after certificates expire (LTV).

04

To check integrity, a validator recomputes the document hash and compares it to the sealed value. If they match, the document is unaltered since sealing; if not, the seal is broken and the document fails validation.

Seal vs signature vs envelope: the vocabulary

Sealing, signing, and enveloping sound similar and are often used loosely. Here is the precise picture.

Signature = who and unaltered

A digital signature proves who signed and that the content was not altered since signing. It is the legal act — the signer's identity, intent, and consent.

Seal = the final lock

Sealing is the final lock applied by the platform (or a qualified seal creator) after all signatures are collected. It proves the completed document — with every signature in place — has not been modified since the workflow closed.

Envelope = secrecy, separate concern

An envelope encrypts content so only the intended recipient can read it. Sealing and signing prove integrity; enveloping provides confidentiality. A sealed signed document may still be readable by anyone who gets a copy — sealing is not encryption.

Product "envelope" is a container

In DocuSign and similar products, "envelope" refers to the whole sending container — recipients, documents, tabs, and status. "Sealed" in that context can mean the workflow is closed to changes, which is a workflow state, not necessarily a cryptographic seal.

Why sealing matters for compliance

Sealing is not just a nicety — it is what makes signed documents usable as evidence over time.

Evidence integrity over time

A signed contract is only useful if it can be shown to be exactly what the parties signed. Sealing creates a verifiable fingerprint of the final state, so years later the document can be proven unchanged — the essence of evidence integrity.

Qualified seals under eIDAS

eIDAS recognizes qualified electronic seals (QESeal) created with qualified seal-creation devices, giving sealed documents strong evidentiary weight — especially for documents created by legal entities rather than individuals.

Regulated record-keeping

Regulated industries (life sciences, financial services, healthcare) routinely require tamper-evident records — for example FDA 21 CFR Part 11. Sealing with a timestamp is a concrete way to demonstrate that requirement.

Long-term validation (LTV)

An LTV-sealed document carries the timestamp and certificate chain needed to remain valid after the sealing certificate expires — otherwise a document sealed today could become unverifiable in a few years.

Common questions about sealing

Sealing locks the completed document cryptographically so any modification after signing is detectable. In e-signature products it usually happens automatically when the workflow closes, and produces a seal certificate that can be validated later.

How eSign.AI handles sealing

eSign.AI seals completed documents with cryptographic tamper-evidence, trusted timestamps, and complete evidence packages — including the certificate chain needed for long-term validation — so a signed document stays provably authentic for as long as you need to keep it.

Quick sealing checklist

What to check when a vendor tells you your documents are sealed.

Cryptographic, not cosmetic

Confirm that sealing is cryptographic (hash + signed seal), not just a workflow state that blocks editing. Ask what exactly gets sealed and when.

Timestamp included?

Ask whether a trusted timestamp is embedded. Without one, the seal cannot prove the document existed in that state at a specific time.

LTV evidence package

Check that the evidence package contains the seal certificate and chain needed for validation years later (LTV).

Matches your regime

For regulated use (life sciences, finance, healthcare), verify the sealing design maps to your regime — e.g., FDA 21 CFR Part 11 or eIDAS qualified seals.

Team discussing the right eSignature approach for a business

Explore the right eSignature approach for your business

Talk to our team about eSignature requirements, compliance considerations, and document workflows across your target markets.