TL;DR
- Yes. In the United States an electronic signature is legally binding under the federal ESIGN Act (15 U.S.C. ch. 96, from §7001) and, in almost every state, under the Uniform Electronic Transactions Act.
- ESIGN and UETA define an electronic signature in nearly identical terms: a sound, symbol, or process attached to or logically associated with a record and adopted by a person with the intent to sign it.
- New York is the only state that has not adopted UETA; it uses its own Electronic Signatures and Records Act instead. Illinois adopted UETA in 2021, so any article still listing Illinois as a holdout is out of date.
- ESIGN §7003 carves out specific categories: wills, codicils and testamentary trusts, most of the Uniform Commercial Code, family law, and notices such as eviction, foreclosure and utility shutoff.
- Signature disputes turn on attribution rather than on validity: the question is whether you can prove this person made this mark on this document.
- A scanned image of a signature pasted into a PDF is the weakest common form, because it carries no evidence of who placed it there, when, or whether the document changed afterward.
Yes. An electronic signature is legally binding in the United States, and it has been since ESIGN took effect on October 1, 2000. The federal statute and the state statutes both say, in nearly identical words, that a signature cannot be denied legal effect solely because it is electronic. What varies is not validity. It is proof.
That distinction runs through everything below. The law settled whether an electronic signature counts two decades ago. What it left open, deliberately, is how you show a given signature was made by a given person, which the record your signing tool keeps has to answer.
An electronic signature is a mark plus a record of the act that made it
The definition is short and nearly the same in both statutes. ESIGN §7006(5) defines an electronic signature as "an electronic sound, symbol, or process, attached to or logically associated with a contract or other record and executed or adopted by a person with the intent to sign the record." UETA §2(8) is identical but for saying "a record" where ESIGN says "a contract or other record."
Three things fall out of it. The form is wide open: a typed name, a squiggle drawn on a trackpad, a checkbox, a click on a button labeled "I agree". The statute is technology neutral on purpose.
The mark must be attached to or logically associated with the record. A signature floating free of the document it signs is not a signature, which is why a signing platform binds the mark, the document and the evidence into one artifact.
And it must have been executed or adopted with the intent to sign. Intent is a state of mind, and state of mind is proved with facts. A short definition imports an entire evidentiary burden.
An electronic signature is a mark plus a record of the act that made it. Take away the record and you have only a picture.
RunwayDue
ESIGN removed one obstacle, and only that one
ESIGN is a validation statute, not a formation statute. Its operative sentence, 15 U.S.C. §7001(a), says a signature, contract or other record relating to a transaction in or affecting interstate or foreign commerce may not be denied legal effect, validity or enforceability solely because it is in electronic form.
The word "solely" is the whole statute. ESIGN takes one defense off the table: you cannot argue the contract fails because it was electronic. Every other defense survives untouched. Fraud, duress, mistake, lack of capacity, lack of consideration, unconscionability, no meeting of the minds and the statute of frauds all work as they did on paper.
ESIGN also says, at §7001(b)(2), that nothing in it requires any person to agree to use or accept electronic records or signatures, other than a governmental agency in respect of a record that is not a contract to which it is a party. A private counterparty may always ask for paper.
One provision is commonly misread. §7001(c) imposes a detailed consumer consent procedure, including a clear and conspicuous disclosure of the right to a paper copy and a demonstration that the consumer can actually access the electronic format. It applies where some other law requires information to be given to a consumer in writing. It is not a general rule for every electronic contract. Capturing consent anyway is cheap and good evidence, which is a different argument.
UETA is the state-law layer, and New York is the only state without it
UETA is a uniform act drafted by the Uniform Law Commission in 1999 and enacted state by state. It has been adopted in 49 states, the District of Columbia and the US Virgin Islands. New York is the only state that has not.
The picture moved recently. Washington adopted UETA in 2020, replacing its Electronic Authentication Act, and Illinois adopted it in 2021, replacing the Electronic Commerce Security Act it had used since 1998. Before those changes the standard line was that three states were holdouts: Illinois, New York and Washington. That line is now wrong, and where you see it, treat the rest of the article with care.
New York is not a gap in coverage. It has the Electronic Signatures and Records Act, in Article III of the State Technology Law, under which an electronic signature may be used in lieu of a signature affixed by hand and has the same validity and effect. ESRA carries its own exclusions, so a New York transaction deserves its own check.
The layers interlock through ESIGN §7002. A state may modify or supersede §7001 if it has enacted UETA as approved in 1999, or if it specifies alternative procedures consistent with ESIGN that give no preference to any technology. In practice, for a domestic commercial contract you are under your state's UETA, with ESIGN as the federal floor.
| Statute | Scope | Definition of electronic signature | Notable exclusions |
|---|---|---|---|
| ESIGN, 15 U.S.C. §7001 onward | Transactions in or affecting interstate or foreign commerce | Sound, symbol or process, adopted with intent to sign | Wills, codicils, testamentary trusts; family law; most of the UCC; the notices in §7003(b) |
| UETA (1999 uniform text) | Parties who have agreed to transact electronically | Same wording, but "a record" rather than "a contract or other record" | Wills, codicils, testamentary trusts; most of the UCC; whatever each state adds |
| New York ESRA, State Technology Law art. III | New York transactions | State definition, same practical effect | Dispositions on death, certain fiduciary appointments, instruments where possession confers title |
Four things turn an electronic signature into an enforceable one
The statutes print no checklist. The requirements that matter reduce to four, and each is something you either recorded at signing time or did not. What that record has to hold is a subject of its own: what an e-signature audit trail actually has to contain.
- Intent to sign. The signer performed a deliberate act meant to serve as their signature. A mark placed after an explicit prompt is strong. A pre-ticked box is weak, because a pre-ticked box records no act at all.
- Consent to transact electronically. UETA §5(b) applies only to parties who have agreed to conduct the transaction by electronic means, and that agreement may be inferred from conduct. Capturing it explicitly turns an inference into a fact.
- Association of the signature with the record. The mark, the document and the evidence have to be bound together. If the signature can be lifted off the document without trace, the association is an assertion rather than a property of the artifact.
- Retention of an accurate, accessible record. ESIGN §7001(d) says an electronic record satisfies a retention requirement if it accurately reflects the information and remains accessible in a form capable of being reproduced. A record you cannot open in five years is not a record.
Intent to sign is a factual question, and consent is how you evidence it
Intent is proved by the shape of the process, not by a clause asserting that intent existed. A court reconstructing what happened looks at what the signer was shown, in what order, and what they had to do. If a signer sees the document, is told plainly that they are about to sign electronically and what that means, is told they can ask for paper instead, and only then may place a mark, the intent story tells itself. If they were shown a form with a signature already in it and a button saying Continue, there is very little to reconstruct.
Consent, done properly, is a short script. RunwayDue captures it before any field can be filled: the signer is told that their name, email address, date and time, network address, browser and operating system will be recorded and attached to the finished document, that everyone who signs receives a copy, and that they may ask for paper or decline and say why. Only then does the document become fillable, and the consent timestamp is stored separately from the signing timestamp.
That ordering does real evidentiary work. Consent at 14:02:11 UTC and a signature at 14:04:36 UTC is a story. Consent and signature carrying the same timestamp, because both were stamped when the document was assembled, is not.
ESIGN excludes a short and specific list of documents
ESIGN §7003 lists what the statute does not reach, and those categories are where people get hurt. Every category, its real status, and what to do instead is worked through in what cannot be signed electronically.
Under §7003(a), ESIGN does not apply to laws governing the creation and execution of wills, codicils or testamentary trusts; to state laws on adoption, divorce or other family law matters; or to the Uniform Commercial Code as in effect in any state, other than Articles 2 and 2A and two sections of the pre-2001 Article 1. So sales of goods and equipment leases are inside ESIGN. Negotiable instruments under Article 3, letters of credit under Article 5, documents of title under Article 7 and secured transactions under Article 9 are outside it, governed instead by whatever electronic provisions those articles carry in your state. If your document is one of those, do not reason from ESIGN alone.
Under §7003(b), ESIGN also does not apply to court orders and official court documents; cancellation of utility services such as water, heat and power; notices of default, acceleration, repossession, foreclosure or eviction under a credit agreement secured by, or a rental agreement for, an individual's primary residence; cancellation of health or life insurance benefits; product recalls and notices of a material failure risking health or safety; and paperwork accompanying hazardous or toxic materials.
UETA's exclusion list in §3 is similar but not identical, and each adopting state was free to add its own. Check state law rather than stopping at the federal statute.
A scanned signature image pasted into a PDF is the weakest form there is
A scanned signature image can be a legally valid electronic signature. It is a symbol, it can be attached to a record, and it can be adopted with intent. Nothing in ESIGN or UETA rules it out.
It is still the worst option available, and the reason is evidentiary rather than legal. A signature image is a picture file. It proves that a picture of somebody's handwriting exists and that somebody put it into a document. It proves nothing about who did that, when, whether the person whose handwriting it is knew, or whether the document changed afterward.
Worse, it is reusable. Once the image is emailed as a PNG or lifted out of a signed PDF, anyone holding it can paste it onto anything, and the result is a pixel-perfect match to the genuine article, because it is the genuine article on the wrong document.
A scanned signature is a picture of a signature. It is not a record of a signing.
RunwayDue
The table below is about evidentiary weight, not legality. Every row can be a valid signature. They differ in what you can prove when the other side says they never signed.
| Form | Proves a mark exists | Proves who made it | Proves when | Detects later alteration |
|---|---|---|---|---|
| Scanned image pasted into a PDF | Yes | No | No | No |
| Typed name in an email body | Yes | Weakly, via mail headers | Yes, via mail headers | No |
| Signing platform with an audit trail | Yes | Yes, via link, email, IP and event log | Yes, to the second | Yes, where a hash of the document was recorded and you still hold the file it was taken from |
| Certificate-based digital signature | Yes | Yes, via a certificate authority | Yes, via a timestamp authority | Yes, cryptographically |
| Wet ink on paper, witnessed | Yes | Yes, via handwriting and the witness | Only as well as the witness recalls | Partly, by physical examination |
Two of those rows are worth separating, because the terms get used interchangeably. An electronic signature is a recorded act of assent. A digital signature is a cryptographic technique in which a private key held by an identified person produces a verifiable seal. Every digital signature is an electronic signature. Almost no electronic signature is a digital signature. RunwayDue produces the former, with a full audit trail and a SHA-256 hash of the original document printed on the certificate. It does not issue certificates.
A dispute is an authentication fight, not a validity fight
When a signature is challenged, the fight is over attribution: whose act was this. The question becomes authentication, and it is the party relying on the signature who has to authenticate it.
UETA §9(a) sets the test: an electronic record or signature is attributable to a person if it was the act of the person, and the act may be shown in any manner, including a showing of the efficacy of any security procedure used to determine attribution. That is an invitation to describe your process. If you cannot describe it, you cannot rely on it.
Two California cases make a clean pair. In Ruiz v. Moss Bros. Auto Group (2014), an employer tried to enforce an arbitration agreement bearing an electronic signature and offered only a declaration asserting the signature was the employee's. That was not enough: it had not explained how the signing process worked or how it linked the signature to that person. In Espejo v. Southern California Permanente Medical Group (2016), an employer facing the same challenge described the system in detail, including unique login credentials and the date, time and IP address recorded at signing, and the signature was authenticated. The difference was not the law and not the technology. It was the record.
Both arose on motions to compel arbitration in California, a posture with its own burden-shifting steps, so read them for what they show about evidence rather than as a national rule. A declaration saying "this is their signature" is an assertion. A description of the system that shows how the mark got there is evidence.
Federal evidence rules point the same way. Federal Rule of Evidence 901(b)(9) allows authentication by describing a process or system and showing it produces an accurate result. Rules 902(13) and 902(14), added effective December 1, 2017, let certified records generated by an electronic process, and data copies verified by digital identification such as a hash value, be self-authenticating. A stored SHA-256 hash is not decoration. It is the mechanism those rules were written around.
What RunwayDue puts into the record, and what it will not tell you
The signed copy carries a certificate of completion generated as part of the PDF, so the evidence travels with the file rather than sitting in a database only we can read. It records the title, the filename, an internal reference, the SHA-256 hash of the original file, the signing order, who sent it, and the creation and completion timestamps in ISO 8601 UTC. The feature it describes is e-signature.
For each recipient it records name, role, email address, the moment they agreed to sign electronically, the moment they signed, the network address, and the browser and operating system their device reported. Where a value was not captured, the certificate says so rather than dropping the line, because a missing line cannot be told apart from a field that does not exist.
Underneath sits an append-only event log, printed on the certificate as well as held in the app: created, sent, reminded, opened, consented, field completed, signed, declined, completed, voided and downloaded, each its own row stamped with a time, an actor, a detail and a network address. Nothing in it is ever edited or deleted, because evidence you can edit is not evidence. Access is per recipient: each signing link carries its own 32 byte token from the operating system's cryptographic random number generator, since that link is the lock on the document.
The hash works backwards from the way people expect, so it needs saying carefully. Exactly one hash is printed on the certificate, and it is the hash of the original document, before any signature was drawn onto it. The check that works is this: take the original file, compute its SHA-256, and compare it to the "Original SHA-256" line. If they match, the document that went into the signing process is the document you have. Hashing the signed PDF and comparing it to that line will never match, because stamping the signatures and appending the certificate changed the bytes on purpose. The signed copy is hashed as well, but only the first 16 characters of that hash appear in the event log, so treat that entry as a reference rather than as something you can verify against.
Two limits are worth saying out loud rather than leaving for you to find. The legal note printed at the foot of the certificate today is written for Indian law: it refers to the First Schedule to the Indian Information Technology Act, 2000, and to the instruments that Act excludes. It is not a statement about ESIGN, UETA or New York's ESRA, and you should not read it as one. It does not change the record itself, which is what carries the evidentiary weight, but it is not the part to rely on.
The second limit is broader. RunwayDue will not tell you whether your contract is enforceable. It is not a law firm and this is not legal advice. Where a document is unusual, or a state has added exclusions, ask a lawyer about it. Electronic signatures are binding; the statute settled that in 2000. What is still up to you is whether, two years from now, you can show a court who signed, when, from where, and that the document in your hand is the one they signed.
Frequently asked questions
Is an electronic signature legally binding in the United States?
Yes. Under the federal ESIGN Act at 15 U.S.C. §7001, and under UETA in 49 states plus the District of Columbia, a signature or contract cannot be denied legal effect solely because it is electronic. New York reaches the same result through its own Electronic Signatures and Records Act. The question in a dispute is attribution, not validity.
Which states have not adopted UETA?
New York is the only one. Illinois adopted UETA in 2021 and Washington in 2020, so articles still listing them as holdouts are out of date. New York applies its own Electronic Signatures and Records Act, which gives an electronic signature the same validity and effect as a handwritten one.
What documents cannot be signed electronically?
ESIGN §7003 excludes wills, codicils and testamentary trusts, family law matters such as adoption and divorce, and most of the Uniform Commercial Code other than Articles 2 and 2A. It also excludes court documents, utility shutoff notices, notices of default, foreclosure or eviction on a primary residence, cancellation of health or life insurance benefits, product recalls, and hazardous materials paperwork. States add more under UETA.
Does a typed name count as a signature?
Yes, if it was typed with the intent to sign. ESIGN §7006(5) and UETA §2(8) define an electronic signature as a sound, symbol or process adopted with intent to sign, and a typed name is a symbol. What decides a case is not whether the mark looks like handwriting but whether the record shows a deliberate act of assent.
Is a scanned signature image pasted into a PDF legally valid?
It can be valid, and it is still the weakest common form. The image proves only that a picture exists and somebody placed it in a document. It carries no evidence of who did that, when, or whether the file changed afterward, and it can be copied onto any other document.
What is the difference between an electronic signature and a digital signature?
An electronic signature is a recorded act of assent, evidenced by a mark plus surrounding facts. A digital signature is a cryptographic technique in which a private key tied to a verified identity produces a mathematically checkable seal. Every digital signature is an electronic signature; almost no electronic signature is a digital signature. Ordinary commercial agreements rarely need certificate-based signatures, and RunwayDue does not issue them.
Do I have to capture consent before someone signs?
Not always as a matter of law, but you should always do it. The consumer consent procedure in ESIGN §7001(c) applies where another law requires information to be given to a consumer in writing, which is not most commercial contracts. UETA §5(b) applies only to parties who have agreed to transact electronically, and capturing that agreement explicitly turns an inference into a recorded fact. RunwayDue requires consent before any field can be filled.
How do I check the hash on a RunwayDue certificate?
Hash the original document, not the signed one. The certificate prints a single value, "Original SHA-256", and it is the hash of the file as it was before signatures were stamped onto it. Compute the SHA-256 of that original file and compare the two strings; they should be identical. The signed PDF produces a different hash, because signing changed its bytes, so comparing the signed file against that line proves nothing.
What would a court actually look at if a signature were disputed?
The process, described in detail. UETA §9(a) allows attribution to be shown in any manner, including the efficacy of the security procedure used, and Federal Rule of Evidence 901(b)(9) permits authentication by describing a system and showing it produces accurate results. In practice: how the signer was reached and identified, what they were shown and in what order, what was timestamped, and whether a hash ties the document to the one that went into the process.
How long should I keep the signed document and its audit trail?
At least as long as a claim on the contract can still be brought, which varies by state, and longer where tax rules apply. ESIGN §7001(d) requires a retained electronic record to accurately reflect the information and remain accessible in a reproducible form. Keeping the evidence inside the PDF you hold is what makes that achievable, and keep the original file too, since that is what the printed hash is a hash of.
Does RunwayDue handle tax filing?
No. RunwayDue produces proposals, contracts, e-signatures with a full audit trail, invoices, recurring billing, client records, expenses and bills, and books. It does no tax filing of any kind, in any country, and no sales-tax nexus or rate determination: it applies the rate you type. It does no payroll, no inventory and no bank feeds. It is not an accountant and not a law firm.