At most tables, contracts are no longer signed with a pen. They are signed with a click, a code received by SMS, a digital certificate, a finger sliding across a phone screen. The migration happened fast, and with it a new generation of disputes arrived in the courts: the party who denies having signed, the electronic contract enforced as an instrument of debt, the company that needs to prove the acceptance existed. The good news, which surprises many people: a well-examined electronic signature usually carries more evidence than the pen-and-ink one.
Before the examination, the legal map. Provisional Measure 2,200-2/2001 created ICP-Brasil (the Brazilian public key infrastructure) and gave documents signed with a digital certificate from that chain a presumption of veracity with respect to the signatories. Law 14,063/2020 organized the vocabulary into three tiers: simple electronic signature (the basic acceptance, which identifies the signatory in an elementary way), advanced (with means that robustly prove authorship and integrity, even without an ICP certificate), and qualified (with an ICP-Brasil certificate, the tier of greatest evidentiary force). Case law has settled the essential point: a signature outside ICP-Brasil is not invalid; it is valid and effective, merely under a different evidentiary regime.
What exists behind the click
Whoever signs through a signature platform leaves a far richer trail than they imagine. The evidence dossier of a typical transaction records the IP address from which each acceptance originated, the date and time to the second, the linked email and phone number, the authentication result (code sent and confirmed, facial biometrics, validated data), the geolocation when authorized, and the intact sequence of envelope events: created, sent, viewed, signed. Over the whole, the document's cryptographic hash freezes the content: any comma altered after signing changes the hash and exposes the tampering.
"The pen leaves the stroke. The click leaves the IP, the time, the device, the email, the hash, and the audit trail. Denying an electronic signature means arguing with a registry office of evidence."
When someone says "it wasn't me"
The authorship challenge is the heart of these cases, and the forensic examination answers with correlation. Does the acceptance IP match the challenger's residential or corporate connection? Is the email that received the envelope the same one the person used in other communications of the period? Does the identified device coincide with the one they were using? Is the time compatible with their demonstrable routine? Independent sources pointing in the same direction build a conclusion that withstands adversarial scrutiny. The reverse also happens, and matters just as much: when the traces diverge, the examination demonstrates the fraud, the acceptance given by a third party, the scam run with a victim's documents.
At the qualified tier, the debate shifts axis. The ICP-Brasil certificate enjoys a presumption of veracity, and the serious challenge moves to the custody of the key: who had access to the certificate, on which media, with which password, and whether demonstrable misuse occurred. The technical examination verifies the validity of the cryptographic signature, the certification chain, the timestamp, and the integrity of the signed document.
What the examination covers, in practice
- Cryptographic validation: does the signature check out against the document and the certificate? Does the hash match?
- Platform dossier: is the audit trail intact, complete, and consistent with the metadata?
- Authorship correlation: do IP, device, email, phone, and time converge on the signatory?
- Document integrity: did the signed PDF undergo any subsequent modification?
- Transaction context: did the acceptance flow follow the design declared by the platform?
The typical case: the contract enforced and denied
The script reaches the laboratory frequently. A loan agreement signed through a platform becomes an enforcement action; the debtor claims never to have signed and pleads forgery. The examination begins with integrity: the hash of the enforced document matches the one recorded in the platform's trail, ruling out subsequent tampering. It proceeds to the audit trail: the envelope was opened from a link sent to the email the debtor has used for years, the acceptance came from an IP assigned by the provider that serves him, in the neighborhood where he lives, on a device consistent with what he displays in other evidence in the record, and the SMS code authentication was completed on the number listed in his own complaint. None of these elements, alone, would settle the question. The convergence of all of them, documented one by one in the expert opinion, settled it. The reverse case also exists, and the same method serves it: when IP, device, and time diverge from the supposed signatory's demonstrable life, it is the fraud that stands exposed.
The handwritten signature captured on screen
Between the click and the pen there is a hybrid territory growing in banks, insurers, and logistics: the handwritten signature entered with a finger or stylus on the screen of a tablet or delivery terminal. Examining this material is doubly technical. On the handwriting side, the captured stroke preserves analyzable hand characteristics: form, proportion, slant, connections. On the computational side, the best systems record the biometrics of the gesture: pressure, speed, and acceleration of the stroke, data that a pasted image will never contain. The examiner who masters both examinations, of the hand and of the data, distinguishes the signature actually entered on the screen from a figure imported from another document, a question that decides delivery, credit, and insurance disputes.
A warning that prevents lawsuits
An electronic signature is not the same as a digitized signature. The image of a pen signature scanned and pasted into a document carries no trail, no hash, and no authentication: it is a picture, reproducible by anyone with access to a previous document. Important contracts closed that way are invitations to litigation. When in doubt about which tier to use, the yardstick is risk: the higher the value and the likelihood of challenge, the higher the recommended tier, up to the qualified certificate.
Digital process did not weaken signature evidence; it multiplied it. What changed is the kind of eye needed to read it. The examination that once measured stroke pressure and pen slant now correlates connection records, validates cryptography, and reconstructs audit trails. The laboratory that masters both worlds, paper and click, examines the signature wherever it was entered. And in either world, the conclusion is only worth the method that sustains it.
