Back
Disclaimer
Natty Hatty Signature — Audit Trail Policy
Last Updated: November 15, 2025
Version: v1.0
This Audit Trail Policy (“Policy”) explains how Natty Hatty, Inc. (“Natty Hatty,” “we,” “us,” or “our”) collects, records, preserves, and secures audit trail data for documents executed using Natty Hatty Signature (“Signature”). Audit trails are essential for validating electronic signatures and ensuring legal, regulatory, and evidentiary enforceability.
1. Purpose of the Audit Trail
The audit trail provides a verifiable, tamper-evident record of all significant actions taken on a document, including:
Signer identity
Signature events
Consent and intent
IP address and device data
Timestamps
Audit logs of access and activity
Cryptographic integrity checks
Audit trails support compliance with:
ESIGN Act (U.S.)
UETA (U.S.)
eIDAS SES (EU)
Best practices for digital evidence
2. What the Audit Trail Records
Natty Hatty Signature automatically records the following information for every document:
2.1 Signature Events
Signer’s name
Signer’s email address
Verification events (email delivery, open events, authentication)
Signature completion timestamp
Sequence of signing (if multiple signers)
Consent acceptance
2.2 IP Address & Device Information
For each event, the audit trail logs:
IP address
Device type (mobile, desktop, tablet)
Browser or OS fingerprint
Geolocation (approximate, if permitted)
This confirms attribution and intent.
2.3 Timestamps
Every event is timestamped with:
Date and time (UTC)
Event type (delivery, view, sign, decline, revoke)
Authentication attempts
Completion and locking of the document
Timestamps are immutable and essential for legal validity.
2.4 Document Hashing (Integrity Protection)
Natty Hatty generates a cryptographic hash of the final PDF and its signature data.
Hash includes:
Document content
Field placements
Signer inputs
Signature metadata
Audit trail snapshot
Integrity Guarantee:
If the final document is altered in any way, the hash will no longer match, proving tampering.
3. Log Integrity & Tamper Prevention
Natty Hatty uses multiple layers to ensure audit trails remain reliable.
3.1 Immutable Logging
All audit trail data is stored in an append-only, tamper-resistant format using:
Write-once log storage
Server-side hashing
Event-sequencing integrity checks
Natty Hatty employees cannot alter audit trails.
3.2 Secure Storage
Audit logs and documents are stored:
Encrypted at rest (AES-256)
Encrypted in transit (TLS 1.2+)
In AWS U.S. regions
With multi-zone redundancy
3.3 Tamper Detection
Every audit log entry is protected by:
Hash chains
Digital fingerprints
Server integrity validation
Signature locking once completed
If tampering is detected, the document is marked “Integrity Failed”.
4. Audit Trail Availability
4.1 Customers
Businesses (Controllers) may:
View audit trails
Download audit trails
Export them as part of the final signed PDF
4.2 Signers
Signers receive:
A downloadable copy of the signed document
Audit trail attached (where enabled)
Access via Customer App (if permitted by the organization)
5. Retention of Audit Trails
Audit trails are retained for the life of the Document and:
Retained up to 7 years after deletion when required for legal defense, fraud prevention, or compliance
Never deleted automatically unless the Customer account is terminated
(Full retention details: nattyhatty.com/legal/document-retention)
6. Legal Compliance
Audit trails are designed to support compliance with:
6.1 U.S. ESIGN Act Requirements
Intent to sign
Consent to electronic process
Attribution
Record retention
Accessibility
6.2 UETA Requirements
Electronic signatures legally equivalent to handwritten
Evidence of attribution
Reliable record retention
6.3 eIDAS (Simple Electronic Signatures – SES)
Signer identification evidence
Integrity of signed data
Event recording
Natty Hatty is not a qualified trust service provider (QES).
7. Customer Responsibilities
Customers are responsible for:
Verifying signer identity beyond electronic indicators
Understanding local laws applicable to their documents
Retaining backups if required by internal policies
Ensuring usage aligns with compliance needs
Natty Hatty provides the tools, but legal enforceability depends on jurisdiction.
8. Policy Changes
We may update this Policy as laws, standards, or platform capabilities evolve.
Material changes will be communicated to Customers.
9. Contact
For audit trail inquiries or legal questions:
Email:
Subject: Audit Trail Policy Inquiry