Product Updates

Signature Methods, Strong Authentication – The How of eSigning with Circularo

Composite vs individual signatures

It can be difficult to understand the different signing options offered by our platform, let alone which of them would be best suited for the needs of your organization. Add different types of certificates into the mix and one’s head just keeps spinning.

But not to worry! We have prepared an overview all about signature options, their pros and cons, alongside an explanation of certificate types and how important audit trail and the Certificate of Fulfillment are for ensuring document authenticity. At the end, we will make a brief mention of our integration with UAE PASS and its benefits. 

Without further ado, let’s first look at signature types!

Signature types, Their Pros and Their Cons

There are two types of signatures differentiated in Circularo, the Composite and Individual Signatures, and they depend on the way electronic certificates are attached to the document. However, regardless of which type of signature is used, they are always legally binding and internationally recognized. Circularo signatures fall under the eIDAS framework, specifically the eIDAS Regulation (EU) No 910/2014, and based on the legislation are certified to the level of Advanced. Now let’s explore the signature options.

Composite signature

The Composite Signature type uses only one certificate to seal the document once all signatures are placed. It does not matter how many signatures there are on the document, the certificate is only visible with the very last one. Due to the document not being sealed until the end of the transaction.The certificates for each signature are applied in such a way, that with each signature a new sealed ‘revision’ of the PDF is created and other fields apart from the signature fields can be placed and filled out by other signatories during the signing process, while prior signatures remain intact and verifiable.

 On the other hand, without a detailed audit trail or a Certificate of Fulfillment, it can be difficult to determine which signatory is responsible for specific content within the document, and it might not meet the legal or regulatory requirements in certain jurisdictions or industries.

Individual Signature

The Individual Signature method attaches a certificate in the final PDF document to every individual signature. Often the certificate is personal or organizational, but we will come back to the differences in certificates a little later in this article. Due to each signature having its own certificate attached, it is easy to independently verify each one even without a detailed audit trail. This method provides a higher level of security and traceability, as it enables recipients to confirm the authenticity and integrity of each individual signature. 

The individual signature method ensures non-repudiation, as each signatory can be held accountable for their specific contributions to the document. This method is more likely to meet legal and regulatory requirements, particularly in situations where multiple signatories must provide explicit consent or approval. However, because the certificates also seal the document, it is not possible to have other fillable fields on the document, as filling them out would break the seal of the previously placed signatures.

To sum up, the Composite method is easier and more flexible but may lack detailed accountability. The Individual method provides stronger security and traceability, ideal for regulated environments.

Here’s a small table to better compare pros and cons of both methods.

FeatureComposite SignatureIndividual Signature
Number of CertificatesOne certificate applied after last signatureCertificate attached to each signature
Document SealingSealed once at the end of signing processSealed after each signature
Fillable Fields AllowedYes, other fields can be filled during signingNo, only signature-related fields allowed
Traceability & AccountabilityLower, difficult to assign responsibilityHigh, each signature independently verifiable
Use CaseSimpler workflows with multiple signatoriesSituations requiring explicit consent and legal accountability

Certificates: Their Types and When to Use Them

Unlike signature types, there are more than two types of certificates; luckily only by one. All of these certificates are issued by a Trusted Service Provider, such as Adobe or UAE PASS, and thus have to meet their standards. The key difference is to whose identity the certificate is tied to. The types are:

  • Organizational certificate: issued to a specific organization, meaning it contains identifying information about that organization. This can serve as proof that the document originated in that specific organization, without tying it to one specific person. The default Circularo certificate is organizational. 
  • Employee level certificate: tied to a specific person as an employee of an organization. The certificate contains information about both the company and the specific person, confirming they are actually employed at that organization and thus have the authority to speak on their behalf. 
  • Personal certificate: not tied to any organization, but is instead issued only to a specific person, thus holding identifying information about that person only. They serve as one of the most secure ways of proving an independent signatory’s identity and their legal intentions.  

Circularo is able to support all types of certificates and can also help with the issuing of organizational and employee level certificates for clients that might want to have them. 

Certificates and Signature Types

When using the Composite signature method, the most common practice is to use an organizational certificate, as using an employee or personal certificate would only contain information about the very last signatory and no other, rendering the method mostly pointless. These types of certificates are usually used with the Individual signature method, where the certificates are embedded in the document itself and carry information about each of the signatories. 

The organizational certificate is mostly used with the composite signature method, but when used in the Individual signatures, it carries timestamps that can help identify the sequence of events, making it useful as well. 

Which certificate is best suited depends on the use case and legal requirements of the specific situation.

The Importance of Audit Trails and Certificate of Fulfillment

Using an audit trail and digitally sealed certificate of fulfillment significantly enhances the security, traceability, and non-repudiation of a document. 

Audit trail

A detailed audit trail records all the actions and events related to the document, such as when it was created, accessed, modified, and signed, as well as by whom. This provides a comprehensive log of every interaction with the document, enabling recipients to verify the sequence of events and identify potential discrepancies or unauthorized access. In the Circularo application, an audit trail is automatically attached to each document, and is always generated upon request which ensures all actions, including the most recent ones, are recorded in it.

Certificate of Fulfillment

When a document has been completed (either successfully, or failed), a Certificate of Fulfillment is generated, sealed and stored with the document. It provides additional information about the transaction that is not included in the audit trail. Certificate of fulfillment is generated just once as a non-editable PDF and branded based on the organization where the document was created. It contains detailed information up to the moment of completion, and thus serves as proof of document status on point of completion. 

Both documents then serve to prove details about the transaction and document, enhancing security and non-repudiation of the document. The audit trail is always up to date with any changes and interactions with the document, while the Certificate of Fulfillment contains important information about the signing events taken during the document’s transaction. 

Secure eSigning: Authentication and Verification, Sealing and Timestamps

Circularo employs several measures to ensure the signing processes and the application are as secure as possible. That means several different ways for users to authenticate their identity when logging into the application, a number of options for verifying the identity of external recipients of your documents, and the ability to seal and timestamp documents, to serve as proof of contents, in addition to aforementioned audit trails and Certificate of Fulfillment. Let’s dive a little deeper into these measures.

Authentication

When it comes to user authentication to prevent unwanted access to the application, the standard email+password challenge is a default option. At any point, Multi-Factor Authentication can be turned on by the user or even enforced by the administrator. The MFA can be done via email, SMS, or 3rd party authentication software such as Microsoft Authenticator. Users can also use 3rd party accounts for login via OAuth 2.0 Single Sign-On with accounts from Microsoft, Google or Dropbox for example. Another option is using an organization’s own Active Directory, where Circularo integrates the AD using either SAML or LDAP protocols for accessing user details, which is often used for on-premise deployments. 

Verification

Sending a document for signing to an external recipient can call for extra security measures, to ensure your documents remain secure and confidential. The first of these measures that Circularo employs is the very email address used for sending the document. However, that is often not enough. Thus, you can set up a password to the document which the recipient will have to fill out before they can access the document – how you share the password is up to you. Sending a One-Time Password through email or SMS to allow access is another option available. Verification through OAuth SSO via 3rd party accounts such as Google, Dropbox or Microsoft is supported as well. One of the most secure ways to verify the identity of an external recipient is using a national identity provider like UAE PASS, Nafath or BankID, as the providers employ robust security measures during account creation and identity verification, before the recipient is able to access the document.

Sealing and Timestamping

Securing document’s contents against tampering can mean the difference between a huge success for a company or catastrophic failure. Sealing and timestamping a document makes it tamper-proof and court-admissible evidence when needed. A seal covers and protects the document’s content as any subsequent changes to it break the seal previously placed and make the changes visible. Timestamping then proves the authenticity and existence of the contents at a specific point in time. We have two detailed blog posts on this topic, one that focuses on Sealing, and one that dives deeper into Timestamps, if you want to know more.

UAE PASS and Circularo

It is important to mention the integration of the national identity provider UAE PASS with Circularo. UAE PASS is the UAE’s national digital identity platform, enabling citizens, residents, and visitors to securely access online services across sectors such as government, banking, and healthcare. It also allows users to digitally sign and verify documents, request official digital documents, and apply for services from participating organizations. 

In Circularo, UAE PASS can be used in three ways. The first is for user authentication during login into the application, where the users use their UAE PASS account to access their Circularo account. The second is for identity verification of external recipients, where you can choose to use their email address, phone number or Emirates ID as the identifying element.

The last use case for the integration is using UAE PASS to sign documents. This can be done using both the Composite Signature and Individual Signature method, but most often the Individual Signature method is preferred, because it ensures each signatory’s details and certificate are embedded in the document. When a document is signed with UAE PASS, it is sealed with a certificate issued to UAE PASS and not the Circularo default one. 

This integration thus serves to enhance security and non-repudiation of the documents, while ensuring they meet the legal requirements and standards by local and international regulations and laws. A deeper dive is available on our blog about the UAE PASS integration.

Summary

It is important to know how to best leverage Circularo for your organization, and we have walked you through the differences between Composite and Individual Signature methods, the types of certificates used during eSigning and when they are most useful, spent some time on the importance of audit trails and Certificate of Fulfillment for security and legality, added more information about measures of security against unwanted access to documents and the application itself, and mentioned the advantages of our integration with UAE PASS.

Now, you can make informed decisions about your use of Circularo and what configuration might best suit the needs of your organization. 


We’re always open to new opportunities and excited to explore how we can help your business thrive in this fast-evolving digital landscape.

01184