NearSync Help

Documents

Identity-Grade Signing for High-Value Agreements — Technical & Legal Overview Verify signer identity beyond email-only authentication.

"Identity-grade verification by default. Not an upgrade. Not a premium tier. The standard Documents brings to every high-value agreement."


1. Executive Summary

Documents provides multiple layers of signer identity verification that surpass the basic email link model used by most digital signature platforms. While the email link model—sending a link to an email address and assuming the recipient is the verified signatory—is convenient, it is legally tenuous. It proves only that an individual had access to an email account at a particular moment; it fails to provide definitive proof of identity, deliberate intent, or exclusive control of the signing process.

For agreements where signatory identity is commercially or legally material—such as high-value commercial contracts, regulated financial instruments, healthcare authorisations, or government agreements—this level of verification is insufficient. Documents signed via email link alone are vulnerable to repudiation: the claimed signatory can assert they did not sign, their email was compromised, or the link was forwarded to a third party.

Documents addresses these vulnerabilities with a layered verification architecture combining SMS OTP verification, Knowledge-Based Authentication (KBA) leveraging CRM relationship context, and optional third-party biometric and government ID verification. Each layer contributes a distinct category of identity evidence. Together, they create a verification record that demonstrates deliberate intent, identity possession, and relationship context—meeting the “intent to sign” standards required by international legal frameworks and satisfying eIDAS Advanced Electronic Signature (AES) requirements.


When a platform relies solely on a signing link sent via email, the resulting verification record is narrow:

  • A message was delivered to a specific email address.
  • The link was clicked by someone with access to that account.
  • The document was accessed from a specific IP address at a recorded time.

This is a meaningful starting point but insufficient for high-stakes agreements. The gap between "access to an email account" and "the specific individual authorised to execute an agreement" constitutes the repudiation window.

2.2 The Repudiation Risk

Repudiation occurs when a signatory asserts they did not execute an agreement or lacked the intent to be bound by it. In an email-only model, several arguments remain available to a bad-faith signatory:

  • Account Compromise: A third party accessed the email account and clicked the link.
  • Link Forwarding: The link was forwarded to a colleague or assistant who lacked the authority to sign.
  • Phishing/Spoofing: The account holder was a victim of a cyberattack, and the link was activated without their knowledge.
  • Absence of Intent: The signatory argues they clicked the link without realising it constituted a legally binding execution.

Multi-factor authentication (MFA) mitigates these risks. Demonstrating that a signatory received an OTP on a registered mobile device, answered challenge questions derived from their specific relationship history, or passed a biometric check creates a record that is significantly harder to contest.

2.3 Regulatory Insufficiency

In regulated sectors—including financial services, healthcare, and government contracting—email-link verification often fails to meet statutory authentication standards. The eIDAS Advanced Electronic Signature (AES) tier, the ESIGN Act’s “intent to sign” requirement, and HIPAA’s authorisation standards all contemplate a higher degree of identity verification than simple email possession.


3. The Three Verification Layers

Documents’s architecture is structured into three complementary layers. Organisations can configure any combination of these layers to match the required assurance level for specific document types or deal values.

Layer Method Proof Category Description
Layer 1 SMS OTP Possession A time-sensitive passcode delivered to a registered mobile number.
Layer 2 KBA Relationship Challenge questions derived from NearSync CRM data specific to the signer.
Layer 3 Biometric/ID Inherence/Identity Real-time government ID and biometric liveness verification.

4. Layer 1: SMS OTP Verification

4.1 Technical Workflow

SMS One-Time Passcode (OTP) verification requires the signer to confirm possession of a registered mobile device before accessing the document:

  1. Access Request: The signer clicks the email link; however, the document remains locked.
  2. Phone Number Prompt: The signer is prompted for their registered mobile number (often pre-populated from CRM data).
  3. OTP Delivery: Documents generates a cryptographically random, 6-digit, time-limited OTP (valid for 5–10 minutes) delivered via SMS.
  4. Validation: The signer enters the code, which is validated against the generated token and time window.
  5. Audit Trail: Successful validation is recorded in the audit trail with timestamps and masked phone numbers.

4.2 Evidentiary Value

SMS OTP establishes a possession factor. In legal terms, it proves the signing event required access to both the email account and a physical device linked to the individual. This effectively neutralises "link forwarding" or "simple account compromise" arguments.


5. Layer 2: Knowledge-Based Authentication (KBA)

5.1 CRM-Contextual vs. Generic KBA

Generic KBA systems use public data (e.g., "What was your previous address?"), which is often discoverable via social engineering or public records. Documents’s CRM-Contextual KBA is categorically different. It generates challenges from the signer’s actual history within the NearSync CRM—details only the genuine relationship party would know.

5.2 Challenge Generation Examples

CRM Data Category Example Challenge Question Why It Works
Deal History "What was the value of your 2023 contract to the nearest £10,000?" Requires specific commercial knowledge.
Interactions "In which month did your account manager last visit your office?" Based on private meeting logs.
Agreement Terms "What are the standard payment terms in your current MSA?" Specific to negotiated legal terms.

5.3 Evidentiary Value

Successful KBA completion provides Relationship Context Evidence. A signatory claiming they have no relationship with the firm would struggle to explain how they correctly answered multiple questions regarding specific account history and prior deal values.


6. Layer 3: Third-Party ID and Biometric Verification

6.1 Maximum Assurance

For high-stakes agreements, Documents integrates with identity verification providers to perform real-time, document-based authentication. This links a real-world government identity to the digital signing event.

6.2 Supported Methods

  • Government ID Verification: Real-time analysis of passports, national IDs, or driving licences for authenticity and tampering.
  • Biometric Liveness Check: A "selfie" or video capture ensures the person is live and matches the ID document.
  • NFC Chip Verification: For e-passports, the internal chip is cryptographically verified against the issuing authority.
  • Sanctions Screening: Optional screening against PEP (Politically Exposed Persons) and global sanctions lists.

7. Verification Assurance Levels (VAL)

Documents allows organisations to automate the required verification level based on risk thresholds:

Assurance Level Methods Typical Use Cases
Standard Email + IP + Fingerprint Internal NDAs, low-value quotes.
Enhanced Standard + SMS OTP Standard B2B contracts, SOWs.
High Enhanced + Contextual KBA High-value MSAs, financial agreements.
Maximum High + Biometric ID Regulated finance, healthcare, gov-contracts.

8. The Verification Audit Record

Every signing event generates a structured, tamper-evident audit record embedded in both the CRM and the signed PDF's metadata.

Documents Signer Verification Audit Record — High Assurance Example
-----------------------------------------------------------------
Signer:         Arjun Mehta (CFO, Meridian Ventures)
Email:          arjun.mehta@meridian.in (Verified)

--- LAYER 1: SMS OTP ---
Result:         PASS (Phone: +91 98XXX XXXXX)
Timestamp:      2026-03-04T11:47:23Z

--- LAYER 2: CRM-CONTEXTUAL KBA ---
Result:         PASS (5/5 Correct)
Sources:        Deal_History, Interaction_Logs

--- LAYER 3: BIOMETRIC ID ---
ID Type:        Passport (IND) - NFC Verified
Liveness:       PASS
Match Score:    98.7%
-----------------------------------------------------------------
Assurance:      MAXIMUM
SHA-256 Hash:   a3f8c2d91b4e7f6a...c8d2e1f0

  • ESIGN Act (US): Documents's MFA architecture satisfies the "intent to sign" requirement by proving the signature was a deliberate, multi-step volitional act.
  • eIDAS (EU): Documents meets Advanced Electronic Signature (AES) requirements by ensuring the signature is uniquely linked to the signatory and under their sole control.
  • Sector Specific: Meets SCA (Strong Customer Authentication) for banking under PSD2 and HIPAA identity verification standards for healthcare disclosures.

10. Documents vs. Competing Platforms

Feature Documents Competitors (DocuSign/Adobe)
Default Standard Configurable identity-grade. Email-link only (Standard).
SMS OTP Native/Included. Paid/Premium add-on.
KBA Type CRM-Contextual (Dynamic). Generic/Public data (Static).
eIDAS AES Native capability. Often requires external certificates.
CRM Integration Deep/Bi-directional. Limited/Surface level.

11. Practical Applications

  • Financial Services: Secure loan facility agreements by preventing identity fraud.
  • Healthcare: Ensure HIPAA compliance for patient data authorisations.
  • Government: Meet NIST Identity Assurance Level 2 (IAL2) for public sector procurement.
  • Cross-Border Trade: Mitigate risk in high-risk jurisdictions via biometric and sanctions screening.

12. Summary

Documents’s multi-layer architecture delivers identity-grade execution for agreements where email-link verification is insufficient. By integrating possession, knowledge, and inherence factors, Documents creates a court-admissible evidence package that protects against repudiation and satisfies global regulatory frameworks.

Identity-grade signing. Configured for your risk. Native to your CRM.

5 minUpdated 28 July 2026

Did this answer your question?

No, ask a person