CYBERSYGNverify

Public signature check.

Verify any CyberSygn signature.

A fingerprint is the SHA-256 of a file, 64 hexadecimal characters. Paste one below to check it against the public record of completed CyberSygn signings. Hashing your own copy of a document is the point of this page, so the section under the form tells you exactly which file to hash and how.

64 hexadecimal characters (0 to 9, a to f). Spaces and line breaks are ignored, so the two rows printed on an audit certificate paste in as they are. A full verify link, or a whole line of shasum output, works too.

Which file to hash

A signing can have two fingerprints, and they are not interchangeable. The signed PDF is the copy CyberSygn produced when the last signer finished, with every signature drawn into it. The original is the file as it was uploaded, before anyone signed. If you are not sure which one you are holding, paste it and see.

Hash the copy you downloaded from CyberSygn, exactly as you downloaded it. Re-saving, re-exporting, printing to PDF, or flattening the document again in another tool rewrites the bytes and produces a different fingerprint, which is not a sign of tampering, just a different file.

To fingerprint a file on your own machine:

macOS or Linux: shasum -a 256 your-document.pdf
Windows PowerShell: Get-FileHash your-document.pdf -Algorithm SHA256

The audit certificate for a document prints every fingerprint that exists for it, each one labelled with the file it belongs to. If a document has no signed PDF of its own, the certificate says so in words, and the original fingerprint is the only one to check.

What this proves

A match confirms the fingerprint corresponds to a document that reached completion on CyberSygn, and that the file carrying that fingerprint has not changed by a single byte since. That is an integrity check, not a legal opinion on the agreement itself.

The public record is deliberately minimal. It shows the fingerprint, how many people signed, and when signing finished. It never exposes names, email addresses, document titles, or any of the content.

A document signed by one person alone in the browser is flattened on that device and never reaches our servers, so it has no public record here and never will.

Read how the tamper-evident audit trail works.