Home // FORENSIC UNITS // DIGITAL EVIDENCE

Electronic Signatures and Digital Contracts

From an acceptance click to an ICP-Brasil certificate: each level of electronic signature leaves traces of its own, and each one calls for its own examination when authorship is challenged.

The legal map

Three levels of signature, three different examinations

Brazilian Law 14,063/2020 organised electronic signatures into three levels, and that classification decides the fate of any challenge: what each level proves on its own, what depends on a forensic examination and which method the examination must follow. The qualified signature, backed by an ICP-Brasil certificate, further carries the presumption of truthfulness of art. 10 of Provisional Measure 2,200-2/2001, a presumption that is rebuttable: it admits evidence to the contrary, and that evidence is technical.

The three levels of electronic signature: simple, advanced and qualified
SimpleAcceptance by click, e-mail or password: it identifies the signer in a basic way. It counts as a signature, but once challenged, nearly all the evidence comes from the context and from the systems involved
AdvancedPlatforms with an audit trail (DocuSign, Clicksign, D4Sign, Autentique and the like): it binds the signer through evidence. The strength of the proof is the quality of the trail, and it is the trail that the forensic examination dissects
QualifiedICP-Brasil digital certificate: legal presumption of truthfulness (Provisional Measure 2,200-2, art. 10). Challenging it requires a cryptographic and structural examination, from the certificate to the content covered by the signature

Gov.br accounts, the Brazilian federal digital identity, follow a similar layered logic: the account level defines the robustness of the identification behind the signature. Knowing at which level the document was signed is the first step in any feasibility assessment.

Gov.br BronzeRegistration with basic data: weaker identification, more room for challenge
Gov.br SilverValidation through an accredited bank or biometrics: intermediate identification
Gov.br GoldFacial biometrics checked against an official database or a digital certificate: the most robust tier of the account
From the pen on the screen to the certificate chain: the electronic signature under examination
What the examination covers at each level

Each level leaves a trace; each trace calls for a method

Qualified

The full cryptographic examination

Certification chain up to the root CA, status of the certificate at the moment of signing (OCSP and revocation lists), RFC 3161 time stamp, PAdES conformity and the coverage of the signature over the content (byte range): does the signature cover everything it should cover?

Advanced

The audit trail dissected

IP address, geolocation, device, authentication method and hash of every platform event, and also the typical weaknesses: a signing link forwarded to a third party, a compromised e-mail account, a fragile selfie check. The trail proves the process; the examination checks whether the process proves the person.

Simple

When there is no trail

What remains is the context and the systems: logs, access records, the behaviour of the parties before and after signing, traces on devices. This is where the examination meets computer forensics, and where feasibility must be assessed frankly before any promise is made.

A valid signature does not mean
an intact contract

The most treacherous case in the field: a cryptographically perfect signature over a document tampered with before signing, or with dynamic content that changes depending on who opens it. The certificate attests to the operation; as for the content, the answer comes from the examination, comparing byte range, file versions and audit trail.

Have a case like this assessed
The highlight of this unit

Handwritten signature on a screen: the writer's hand is still the writer's hand

When the signature is written with a pen on a tablet or screen, many platforms record the dynamics of the gesture: coordinates, timing and, on certain devices, pressure. The paper is gone, but the gesture is not: the neuromotor automatism that individualises handwriting remains fully present in the captured data.

The examination brings the two disciplines together: forensic handwriting examination reads the gesture (initial attacks, terminal strokes, rhythm, proportions), and computational analysis reads the data that recorded it. An imitation that fools the eye in a static image usually betrays itself in the dynamics: the forger's slow, watched stroke does not reproduce the rhythm of a practised hand.

The most common scenario, however, is a different one, and the market rarely explains it: many contracts, including banking ones, are signed on ordinary tablets, which capture neither pressure nor speed nor the evolution of the movement. These are graphic signing devices, not biometric recording devices: what they produce is only a rasterised image of the stroke. The difference from a signature capture tablet, which records the artefacts and metadata essential to technical forensic analysis, is the difference between a photograph of the gesture and the gesture itself.

In a challenge, this changes everything: on a rasterised image, the examination works with the caveats attaching to any reproduction, and the expert report states that limitation; on dynamic data, the examination reaches the writer's hand. Knowing which device captured the signature is very often the first question of the case. It is "the same expert masters both the paper and the system" in its most literal form. Explore forensic handwriting examination →

CoordinatesThe path of the stroke point by point, with the real order and direction of the movements
TimingSpeed and rhythm of the gesture, invisible in a static image: a slow imitation gives itself away here
PressureThe pressure axis of the writer's hand, when the hardware records it: one of the most individual elements of handwriting
No dynamicsSignature drawn with a fingertip, with no captured data: examination is possible, with stated limits
Signature capture tablet at the Doc Lab, with pen and the dynamics of the gesture under analysis on the monitor
DOC LAB · Signature capture tabletSignature collection
Digital transplant

The genuine signature on the wrong document

An authentic signature, scanned from a legitimate document and digitally pasted onto another, looks perfect precisely because it is genuine. This is what the laboratory calls a digital transplant, and it has been appearing in cases with growing frequency, mainly in digital documents.

The mechanism is simple, and that is what makes it dangerous: the victim has signed some legitimate document at some point in life, an old contract, a power of attorney, a form. That document circulates as a PDF or an image, and in it the signature is just a set of pixels. The fraudster crops it with any editor, adjusts the size and drops it onto the new document: a contract that never existed, an amendment nobody agreed to, an authorisation that was never given. Printed or filed with the court, the result fools the eye, and it even fools a handwriting comparison carried out in isolation, because the stroke itself is genuine.

The defence lies in a combined examination. On the stroke, the handwriting comparison checks what the copy carries; on the file, the structural examination looks for what the paste-in cannot hide: the cropping halo around the signature, the difference in resolution and compression between it and the rest of the page, the exact point-by-point duplication when the same signature appears in more than one document (no person signs twice in an identical way), and the internal layers of the file, which reveal the inserted image object and the moment it was added.

Digital transplant: the genuine signature cropped from one document and pasted onto another
Cropping haloThe background around the signature clashes with the rest of the page: the edge of the paste-in
ResolutionA signature whose definition, compression or noise differs from the document that received it
Exact duplicationTwo signatures identical point by point indicate mechanical reproduction: no hand repeats itself exactly
LayersThe image object inserted into the file and the moment it was added, revealed by the internal structure of the PDF

This is why a digital transplant requires a combined examination: handwriting analysis on the stroke, structural analysis on the file. Digital Questioned Document Examination →   Forensic Handwriting and Questioned Documents →

Regulatory basis

The technical and legal grounding of the examination

Law 14,063/2020The three levels of electronic signature under Brazilian law: simple, advanced and qualified
MP 2,200-2/2001The Brazilian public key infrastructure (ICP-Brasil) and the presumption of art. 10
RFC 3161Time stamp: proof that the signature existed at a given moment
ETSI PAdESStandards for signatures in PDF and long-term validation (LTV)
OCSP / CRLChecking the status of the certificate: valid, revoked or expired at the instant that matters
eIDASThe European regulation: the relevant parallel for contracts with a party abroad
Frequently asked questions in this unit
What is the difference between an electronic signature and a digital signature?
Electronic signature is the genus: any way of expressing agreement by electronic means (a click, a password, biometrics, a platform). Digital signature is the most robust species: it uses a cryptographic certificate, such as ICP-Brasil, which mathematically binds the signer to the document. Law 14,063/2020 organised all of this into three levels, and the forensic examination treats each one with its own method.
Is a simple electronic signature valid in court?
It is: the law admits the simple signature between private parties who accept it. The issue arises when one of the parties challenges it: without a robust trail, showing authorship becomes technical evidence drawn from context, logs and devices. The simpler the signature, the more the case depends on the forensic examination.
The platform says the document is valid. Do I still need a forensic examination?
The platform's completion certificate attests to its own process: that a link was opened, a click recorded, a hash generated. It does not answer who was on the other side of the screen, nor whether the process withstood a forwarded link, a compromised e-mail account or a weak verification. That is precisely the question the examination addresses.
I signed through the platform, but the content was swapped. Can that be proven?
This is one of the most important examinations in the field: a signature may be technically valid and still cover content that was tampered with beforehand, or content that is dynamic. The analysis compares the byte range covered by the signature, the hash of the document, the file versions and the platform's audit trail.
Is a contract signed through Gov.br valid?
Yes, according to the level of the account and of the signature used: bronze, silver and gold represent different tiers of identification. What the forensic examination checks is whether that specific signature is authentic, intact and timely, by examining the technical trail of the operation and the level actually employed.
Can a signature made with a pen on a tablet be examined forensically?
It can, and with an advantage: when the platform records the dynamics of the gesture (coordinates, timing, pressure), the examination combines forensic handwriting analysis with the analysis of the captured data. Without dynamic data, what remains is the image, examinable with the caveats attaching to any reproduction, and the expert report states that difference.
I denied entering into the agreement. Who bears the burden of proving authenticity?
In banking contracts, the Brazilian Superior Court of Justice settled the matter in Repetitive Appeal Theme 1061: once the signature (physical or electronic) is challenged, it is for the financial institution to prove its authenticity and to bear the cost of the forensic examination (CPC, arts. 369 and 429, II, Brazilian Code of Civil Procedure). With electronic signatures, that proof runs through the audit trail and the technical traces of the operation, which is exactly the object of this examination.
What if the contract was signed with a party abroad?
Cross-border contracts often involve eIDAS, the European regulation on identification and trust services, and foreign platforms with trails of their own. The examination takes into account the regime applicable to each signature and the compatibility between the technical standards involved.

See also

Digital Questioned Document Examination →   Forensic Handwriting and Questioned Documents →   Computer Forensics →   International Practice →

Completed cases
ANONYMISED CASE

Civil action against a financial institution involving electronic signature fraud

Acting as party-appointed expert (technical assistant). Forensic analysis of the electronic signature platform revealed flaws in the authentication process, supporting a favourable decision at first instance.

Representative cases

The level of work you are engaging

Before deciding, it is worth seeing what has already come through this laboratory: cases described without identifying the parties, in the format of challenge, method and result.

See all representative cases →

The technical evidence your case requires. The authority courts respect.

Initial feasibility consultation at no cost. Reply within 24h on business days.
Request an Examination