← All articles
SecurityTrust

What Actually Makes an E-Signature Tamper-Proof?

Rajeev Kistoo, Founder, MauriSign · 23 April 2026 · 7 min read

Here's an uncomfortable truth about a scanned signature: it proves almost nothing. A picture of someone's autograph pasted onto a PDF can be copied, moved to another document, or lifted off entirely. And the document underneath? You could change a number, a date, a clause, and re-save it, and the signature image would sit there looking just as convincing as before. If it ever came to a dispute, "but they signed it" wouldn't get you very far without a way to show what they signed.

A real electronic signature solves a harder and more useful problem. It doesn't just record that someone signed — it locks in exactly what they signed, so that any later change becomes obvious. Let's walk through how that actually works, in plain terms.

First, a snapshot of the exact document

When a document is completed on MauriSign, the system takes a precise snapshot of it — the final content, every signer, the order they signed in, the specific signature each person made. Think of it as freezing the document at the instant of completion and writing down its exact fingerprint. Not "roughly this contract" but "this contract, these words, these people, nothing else."

That snapshot is what gets protected. It's the difference between a witness saying "yes, that looks like the agreement" and a witness who can recite it word-for-word and swear nothing's moved.

Then, a cryptographic seal

Over that snapshot, MauriSign applies a digital signature — an RSA-2048 seal, to be specific, computed over a SHA-256 fingerprint of the document. You don't need to know the maths. Here's the intuition: the seal is a number that could only have been produced from this exact document and MauriSign's private signing key. Change a single character of the document afterwards — one comma, one digit — and the fingerprint changes, which means the seal no longer matches. The tampering doesn't just fail quietly; it announces itself.

You can't forge the seal without the private key, and you can't change the document without breaking the seal. That's the whole trick.

And the private key that produces those seals is kept offline, deliberately. It signs documents that may need to hold up for years, so it's guarded accordingly rather than left sitting on a web server.

And an audit trail that can't be rewritten

The seal protects the document. But you also want to prove the story around it: that this person opened it at this time, verified their identity with a one-time code, viewed it, and signed. So every meaningful event is recorded in a tamper-evident audit trail — and here's the clever part — each entry is cryptographically chained to the one before it, a bit like links in a chain where every link is stamped with the shape of the previous one.

Why does that matter? Because it means you can't discreetly edit history. You can't delete the awkward event in the middle, or slip a new one in, without breaking every link that follows. The whole sequence has to be internally consistent, or the tampering shows. It's the same idea that makes blockchains hard to falsify, applied to the humble question of "what happened to this document, and when?"

Identity: tying the signature to a real person

All of that guards the document's integrity. The last piece is attribution — showing it was really them. Before anyone signs on MauriSign, they have to enter a one-time code sent to their email address. It's a modest check, but it's a meaningful one: it ties the act of signing to control of a specific inbox, and it's recorded in that same unforgeable audit trail. Combined with timestamps and the events around the signing, it builds a picture that's genuinely hard to dispute after the fact.

The part that matters most: you can prove it without us

Plenty of systems can claim a document is secure. The real test is whether a sceptical outsider can confirm it independently. With MauriSign, anyone can take a completed document to maurisign.mu/verify and check the seal and the audit trail themselves — no account, no calling support, no taking our word for it. If the document is genuine and untouched, it confirms. If someone altered so much as a full stop, it won't.

That's what "tamper-proof" actually means in practice. Not a promise on a marketing page, but a document that carries its own proof — one that a client, a lawyer, or a court can inspect on their own and reach the same conclusion you would. Being built on the ETA 2000 makes an e-signature legal in Mauritius; this is what makes it defensible.

If you'd like to see it work, the honest way is to try it. MauriSign has a free 14-day trial — send a document, seal it, then change one character of the downloaded file and watch the verifier catch you. It's oddly satisfying.

Ready to sign smarter?

Send your next document for signature in minutes — legally recognised under the ETA 2000, cryptographically sealed, and free to try for 14 days. No card required.

Start your free trial