Element 90 · tamper-evident signing

Anyone can collect a signature.
Thorium can prove it.

Every event on a document is hash-chained to the one before it, so the record cannot be edited, reordered or quietly trimmed without the chain breaking. Signers get an expiring link with no account and nothing to install, and when the last signature lands the executed copy is sealed against itsSHA-256 hash.

And when somebody wants a pen instead, they can have one — print it, sign it in ink, photograph it back in, and the ink lands on the same chain as everything else.

Free to set up · no credit card required · two-minute setup

Commercial in Confidence

TH-1042

Master Services Agreement

3 / 3

Client

Harry Campbell

Supplier
Awaiting

Kenji Sato

Commercial in Confidence
Hash-chained · 14 Sep 2026
  • 09:12:40Zuploaded the document
    John Guy82.14.209.6
    hasha91c…4f2e
  • 09:14:02Zsent for signature
    John Guy82.14.209.6
    hash7d30…b8a1
  • 09:31:55Zopened the document
    Harry Campbell104.28.61.19
    hashe55f…0c94
  • 09:41:02Zsigned all fields
    Harry Campbell104.28.61.19
    hash3b17…d6aa

sha256 75476fb2edfafa15756431c73ca22299e1b91ef3248f990710323f52cc80b0a4

Try editing the record

Open the audit trail, then change one field and watch the chain refuse it.

  • Hash-chained audit trail
  • SHA-256 on upload
  • HMAC links · 30-day TTL
  • Revision-locked paper
  • Sealed certificate
How it works

Four steps from upload to sealed.

No template to configure first, no recipient onboarding, no chasing a countersignature through email threads.

  1. Step 1

    Upload

    Drop in a PDF. Thorium parses it, counts the pages and takes a SHA-256 of the bytes before anything is stored.

  2. Step 2

    Place

    Drag signature, initials, date, text, number, checkbox, dropdown and radio fields onto the rendered page, and set who signs in what order.

  3. Step 3

    Send

    One at a time or all at once. Each recipient gets their own expiring link, and anyone copied in gets the outcome without owning a field.

  4. Step 4

    Seal

    Every event is chained to the one before it as it happens. When the last signature lands, the executed copy is sealed and the certificate goes out to everyone.

Ways to sign

Meet them where they are.

Most signatures are somebody clicking a link in their inbox. The ones that hold deals up are the other ones — the person sat across the desk, the counterparty who will not put a signature into a browser, the document that cannot go out with the code in the same email as the link. All four routes land on the same record.

By link

The ordinary way.

Each recipient gets their own expiring link, scoped to them and to this one document. No account, no password, nothing to install.

In person

They are stood in front of you.

Open their session from the document on your own device. Nothing is emailed, the session lives for minutes, and the member who ran it is named on the trail beside the signature.

Behind a code

The link is not enough.

Set a per-signer access code and pass it another way — down the phone, in person. Only its scrypt hash is stored, so the code cannot be read back out of Thorium. Every miss is counted and recorded.

On paper

They want a pen.

Print it, sign it in ink, photograph the pages back in. The camera checks it is this document, at this revision, with every page present.

Paper execution

Some people are going to want a pen.

Usually that means the document leaves the system: printed, signed, scanned, and emailed back as an attachment nobody can check. Thorium keeps it inside. The pack it prints is laid out so a photograph of a signed page is evidence rather than a picture, and the ink joins the same hash chain as every click.

  1. 1

    Print the pack

    Everything already agreed is burned in first, so the paper carries the electronic signatures collected so far. Four registration marks and a page code go on top, and a ruled line lands wherever the paper signer has a field.

  2. 2

    Sign it in ink

    Away from the screen, on a desk, with a pen. The pack says on every page what it is and what to do with it.

  3. 3

    Photograph every page

    The camera finds the four marks, straightens the photograph onto them, reads the printed code, and then knows exactly where the signature boxes were. A page held upside down is turned rather than read backwards.

  4. 4

    Confirm the original is held

    A photograph proves what was on a page, not that anybody has the page. The signature counts once a member confirms the original is in hand — named on the record beside whoever photographed it, and deliberately allowed to be somebody else.

What comes back is refused

  • A page from a different document
  • A page from an earlier revision of this one
  • A set with a page missing
  • A box with no ink in it
  • A photograph too skewed to straighten

Every photograph is read again on the server after the camera has had its go. What the browser says it saw decides what to show the person holding the phone. It does not decide what goes on the record.

Signature · Harry CampbellPage 2 of 4 · Mutual NDASigned on paper — photograph every page to return it
Page 2 of 4, as Thorium prints it. The marks and the code are drawn here from the same constants the camera reads back.
The record

A record that answers back.

The trail is append-only and every entry is chained to the one before it. Status is derived from signer state rather than set by hand, so the badge, the progress bar and the record can never disagree with each other. When the last signature lands, the certificate is bound to the document’s SHA-256 hash.

  • 26 distinct events, from upload to seal
  • Timestamp, actor, device and source IP on every event
  • Refusals recorded too: a wrong code, a closed window, a spent view
  • Signing links scoped to one signer on one document
  • Private storage: PDFs are never publicly addressable
  • Certificate of completion, print ready
  • Export to CSV, or post every event to your own systems
Audit trailSealed
2026-09-14 09:12:40uploaded the document
John Guy82.14.209.6
2026-09-14 09:14:02sent for signature
John Guy82.14.209.6
2026-09-14 09:31:55opened the document
Harry Campbell104.28.61.19
2026-09-14 09:33:10access code accepted
Harry Campbell104.28.61.19
2026-09-14 09:41:02signed all assigned fields
Harry Campbell104.28.61.19
2026-09-14 09:41:02sealed the executed copy
Systemcertificate issued
sha256 75476fb2edfafa15756431c73ca22299e1b91ef3248f990710323f52cc80b0a4
The chain

Verify it yourself.

Each entry commits to the whole of itself and to the hash of the entry before it. That is the difference between a log, which is a list somebody could edit, and a chain, where changing one entry invalidates every entry after it. Export the trail and check the arithmetic against your own copy.

Intact4 of 4 verified

John Guy uploaded the document

prev 0000…0000a91c…4f2e

John Guy sent for signature

prev a91c…4f2e7d30…b8a1

Harry Campbell opened the document

prev 7d30…b8a1e55f…0c94

Harry Campbell signed all assigned fields

prev e55f…0c943b17…d6aa

One IP address altered2 broken

John Guy uploaded the document

prev 0000…0000a91c…4f2e

John Guy sent for signature

prev a91c…4f2e7d30…b8a1

Harry Campbell opened the document

prev 7d30…b8a1does not match

Harry Campbell signed all assigned fields

prev e55f…0c94does not match

Editing the third entry changes its digest, so the fourth no longer follows from it. The tampering is visible without needing the original to compare against.

Export the whole trail

Download it as CSV with the entry count, the chain status and the seal in the trailer.

Deletions show up too

Removing an entry leaves a gap the next link cannot bridge, so a quiet trim is as visible as an edit.

Redaction is not tampering

Detail that ages out under your retention period is reported as unverifiable, never as altered.

Somebody sent you a Thorium trail?

Check it without an account, and without us. The file is read in your own browser and never uploaded, so the answer does not depend on us being honest at the moment you ask.

Verify a trail
Document controls

Decide what happens after you send it.

Sending a document for signature means handing it to someone. These controls set how long they have it, how many times they can open it, what they agree to before the first page renders, and what gets written down if they try to take a copy. All of them are optional, and all of them are per document.

Handling conditions

Write the terms they accept before the first page renders. The acceptance is recorded against their name and the time they gave it.

Access code

Lock a recipient's link behind a code you pass another way. Stored as a scrypt hash with its own salt, so a copy of the database is not a copy of the code.

Access window

Set when the link opens and when it closes. Outside that window the document does not render, and the refusal is recorded.

Open limit

Cap how many times each recipient may open it. The count is per signer, so forwarding the link does not buy anyone more views.

Recipient watermark

Tiles their name and email across every page, so any copy that leaves carries who it was given to.

Copy and print

Blocks selection, copying and right-click, and prints a notice instead of the document. Both attempts are written to the trail.

Screen capture

Catches the usual capture shortcuts, obscures the page and records the attempt. Best effort: an OS tool, an extension or a phone camera will not be caught.

Handling marking

One of 14 presets, or a house marking templated to your workspace name. It bands the document, the certificate and every email about it.

What none of this does

Nothing here stops a determined reader photographing their screen, and we will not pretend otherwise. What these controls do is narrow the window, make the attempt visible, and put a name on any copy that gets out. That is the part a dispute actually turns on.

Underneath, by default

  • PDFs are served through short-lived signed URLs, never a public address
  • Uploads carrying JavaScript, launch actions or embedded files are rejected
  • The signing page cannot be framed by another site
  • Signing and sign-in endpoints are rate limited, with backoff on repeated failures
While it is out

A document out for signature is not finished with you.

The address was wrong. The signatory left. It has been sitting there eleven days. None of that should mean voiding the thing and starting again, and none of it should happen off the record.

Correct it without starting over

Fix a wrong address, a misplaced block or the wrong deadline on a document already out. Recipients are told what changed and given a fresh link; the old one stops working.

Reassign or let them delegate

Send it to the right person yourself, or let the recipient pass it on from inside the signing page. Either way it is recorded as a hand-off, not an email nobody can see.

Chase it on a schedule

Daily, every two days, weekly, or never. The sweep chases what is outstanding and expires what has run out of time, and every reminder is an entry on the trail.

Send the same thing to many

Up to 200 recipients from one document, each getting their own copy and their own link. The run walks the list in batches and resumes where it stopped.

Keep who you send to

Contacts carry the company, the person and the address, so the second document to somebody is faster than the first. Templates keep the fields and the roles as well.

Close it down

Withdraw a document with a reason, or let it expire. Either way it stops rendering for every recipient at once and the closure is on the record.

Wire it in

Your systems hear about it before you do.

Point an endpoint at Thorium and pick which of the 25 events it wants. Each delivery is signed with that endpoint’s own secret, so your receiver can tell a real one from a replay, and the secret rotates without touching the endpoint. Send it as Thorium JSON for your own code, or as a Discord embed straight into a channel.

  • Subscribe per endpoint, per event — not all or nothing
  • Signed payloads, with a test delivery before you trust it
  • Rotate a secret without changing the URL
  • Or take the whole trail as CSV whenever you want it
Delivery200 OK
POST /hooks/thorium
x-thorium-event:     document.completed
x-thorium-timestamp: 1789382462
x-thorium-signature: sha256=4f2e…b8a1

{
  "event": "document.completed",
  "at": "2026-09-14T09:41:02Z",
  "workspaceId": "ws_4c81",
  "document": {
    "id": "doc_8f2a41c7",
    "reference": "THO-0042",
    "name": "Mutual NDA",
    "status": "completed"
  },
  "actor": { "name": "Harry Campbell", "kind": "signer" }
}
Two audiences, two surfaces

Dense where you work. Calm where they sign.

You live in this product all day, so your side is an instrument panel: four destinations, one composer, everything status-led. Your recipient sees it once, so their side is the opposite. Light, roomy, one thing to do.

Your desk

Home, Documents, Contacts, Settings. Drafts, what needs you, templates and the archive are tabs, not four more places to look. A bell tells you when something moved, and the team comes with you: invite an owner, a sender or a viewer.

Their page

A link from their inbox opens the real document, highlights only their fields, and counts them down to done. They can sign, decline with a reason, or pass it to the right person. Nothing to install, nothing to sign up for.

Also built in

If your documents carry a marking, it travels with them.

Optional, and off unless you want it. Pick a marking when you prepare the document, drop it as a band at the top or bottom, and choose whether it repeats on every page. Recipients see it above the content before they read a word, and it is carried on the certificate of completion and on every email about the document, rather than living in a covering note nobody keeps. Use one of the presets or template a house marking to your workspace name.

Presets14 built in
CONFIDENTIALCOMMERCIAL IN CONFIDENCEPRIVILEGED & CONFIDENTIALINTERNAL USE ONLYACME PROPRIETARYACME CONFIDENTIAL
Business
$39per sender / month

Unlimited documents, templates and contacts. Paper execution, access codes, reminders, webhooks and the full audit trail are included. There is no tier that withholds the evidence.

No card required to start