Identity assurance
How confident you are that the person who signed is the person you named — and how much friction you accepted to get there.
Identity assurance is the strength of the evidence that the signer is who the envelope says they are. It is a dial, not a switch, and every step up costs completion rate.
Link only. The recipient holds a credential sent to one address. Weakest, and appropriate for low-value agreements between parties who already know each other.
One-time passcode. A code sent to an email address or phone number, entered before the document opens. Proves control of a second channel. Defences that matter here are a short expiry, a hard attempt limit that burns the challenge, and constant-time comparison — a six-digit code is guessable otherwise.
Knowledge-based or document-based checks. A third-party provider verifies identity against records or a photographed ID.
The level chosen should be recorded per recipient on the certificate, along with whether it was met. Failed attempts belong in the record too — the absence of them is what makes some audit trails weaker than they appear.
Last reviewed 2026-09-18. Pactlyra produces a detailed evidence record for every completed document. Electronic signature validity depends on your jurisdiction, the document type, and how the transaction is carried out; nothing here is legal advice.