Document integrity

How we prove a document has not changed

Termsroom does not keep your agreements. It records a fingerprint of each version instead. This page explains what that is, what it is used for, what it does not prove, and why a reviewer in Canada, the United States or Europe can accept it.

The short version

A fingerprint is a short value calculated from a file. Change one character anywhere in a hundred page agreement and the value changes completely. Two files with the same fingerprint are the same file. Two files with different fingerprints are not.

That single property is enough to answer the question a contract dispute actually turns on, which is not usually whether an agreement was signed but whether the words in front of you now are the words that were agreed then. Termsroom records the fingerprint of every version at the moment it is tabled, in a log that cannot be edited or deleted afterwards. Both sides hold the document itself, in storage they each control.

Why we do it this way rather than keeping a copy

A supplier who stores your agreements can tell you that it holds a file and that the file is the right one. That is an assertion by an interested party, and it is worth exactly as much as your confidence in them.

A fingerprint recorded in a log neither side can rewrite, with both parties independently holding matching documents, proves the same thing to somebody who trusts neither party nor us. It also means that nothing which happens to Termsroom can affect your ability to prove what you agreed. You are not depending on us to still exist, still hold the file, or still be trusted.

So this is not a compromise forced on us by the decision not to hold your documents. It is a better position than holding them would be.

What it is used for

When a version is tabled

The party tabling the version records the fingerprint of the file alongside the pointer to where it sits in their own storage. From then on, that value is what defines the version. Not the filename, and not where the file happens to sit.

When we tell you what changed

Each clause carries its own fingerprint, which is what allows Termsroom to say that every clause which changed is marked and nothing is marked that did not change. A comparison you have to take on trust is worth considerably less than one you can check.

When a negotiation closes

The closing record names the fingerprint of the version both sides confirmed as final, and is written into each party’s own storage. Each side ends up holding its own copy of what it agreed, rather than depending on ours.

The fingerprint computed by us, on request

When a version is indexed, Termsroom reads the file from your own storage, computes the SHA-256 over those bytes, and compares it with the value that was entered. An index is only ever built from bytes whose digest matches, so a clause index describes the document that was put forward and nothing else. A disagreement is recorded as a finding, with both values kept, and never resolved by overwriting one with the other. Until a version is indexed the fingerprint is still an assertion by the party that tabled it, and the screen says which of the two it is showing.

Clause numbers Word generates rather than prints into the file

Where an author used Word’s automatic numbering, the characters “12.4” are not in the document at all: it carries a numbering definition and Word computes the label when it renders. Termsroom rebuilds those labels from the document’s own definitions, and refuses the document outright where any part of the numbering cannot be reproduced exactly, rather than indexing it with clauses whose numbers quietly went missing. A rebuilt label is our reading of a definition rather than a fact about the file, so it is recorded as such, both parties are told which of the two a version’s numbers are, and the party that tabled the document is asked to open it and confirm the numbering matches what Word prints. Their answer, either way, goes into the shared record.

Reading the copy back

A version tabled at the shared table is copied into the counterparty’s own storage, then read back from that storage as a separate request and fingerprinted again. It is marked verified only if that value matches the one recorded when the version was tabled. A successful transfer proves a request was accepted; reading the copy back proves the document arrived intact, and the two are shown as different things rather than both as a tick. Where a copy was written and could not be read back, the record says written rather than verified, and says why.

Built and scheduled, not running yet

These are designed and in the plan. None of them is in the product today, and we would rather you heard which is which from us than found out in a demonstration.

Refusing active content at the door

not yet built

A PDF can be built so that what it displays depends on the reader, the date, or what somebody clicks. A fingerprint cannot detect a difference that is not in the file, so the intention is to refuse such documents at the point they are put forward and to note softer dependencies, such as fonts a document relies on but does not carry. Nothing is inspected today, because no document reaches us.

Checking again before signature

not yet built

A fingerprint taken immediately before the document goes to your signing provider and compared with the version both sides confirmed as final, so that nothing is sent if the values do not match. Termsroom does not connect to a signing provider today.

Why this is accepted, by region

The approach is not novel and does not depend on any one country recognising something unusual. Each of these is settled law rather than an argument we are making.

Canada

primary market

Federal law leaves the form of proof open and asks instead whether the system that recorded a document can be shown to have integrity. A fingerprint recorded in an append only log is squarely the kind of thing that provision contemplates.

There is a second provision that helps here in a way that is specific to how Termsroom is built. Where a document was recorded or stored by the party on the other side of the dispute, its integrity is presumed unless there is evidence otherwise. Because each party keeps its own copy in its own storage, a counterparty’s own copy is presumptively sound when it is produced against them. Canadian regulations also describe, step by step, the operation of generating a digest and then confirming that two digests are identical, so the mechanism is one Canadian law has already written down.

United States

expected market

The federal rules of evidence were amended in 2017 to allow electronic records to authenticate themselves in two situations: where a copy is identified by a digital process, and where a system that produces accurate results is certified as such.

The committee that drafted the amendment said in terms that data copied from electronic files is ordinarily authenticated by hash value, and that identical values reliably attest that two files are exact duplicates. In other words, the method Termsroom uses is not an alternative the rules tolerate. It is the method the rules were written around.

European Union

expected market

European law asks, of a signature at the advanced level, that any later change to the signed data be detectable. Detecting change is precisely what a fingerprint does.

Worth being exact about the limit, because the terms are defined and we do not meet all of them. A fingerprint satisfies the detectability requirement. It does not, on its own, identify a signatory or sit under a signatory’s sole control, which are separate requirements. So Termsroom makes any change to a document detectable, and the signature itself is performed by your own signing provider, which is where those other requirements are met.

Elsewhere

not assessed

We have not assessed the law of every country a customer might be in, and we would rather say so than imply a coverage we have not checked.

The underlying approach is not jurisdictionally exotic. Comparing digests to establish that two files are identical is standard practice in digital evidence internationally. What we have not checked, country by country, is whether any particular document type carries a formality that an electronic process does not satisfy. If your agreement is governed by the law of a country other than the three above, that is a question worth putting to your own advisers.

This page describes how the product works and summarises the position in each region. It is not legal advice, and whether a particular agreement can be concluded electronically is a question for your own advisers.

What a fingerprint does not prove

Being precise about the limits is what makes the rest of the claim worth anything.

It is not a signature. A fingerprint makes change detectable. It does not identify who signed, and it is not a secure electronic signature in Canada or an advanced or qualified electronic signature in Europe, all of which are defined terms with additional requirements. Signature is performed by your own signing provider, not by Termsroom.

It proves the file is identical, not that a screen looked the same. A PDF can be built so that what it displays depends on the reader, the date, or what somebody clicks, without any of that being visible in the file itself. A fingerprint cannot detect a difference that is not in the file. Refusing such documents at the point they are put forward is designed and scheduled, and is not running today, because no document passes through Termsroom to be inspected. Until it does, this is a limit you should assume applies.

No cryptography is unconditionally secure. The method Termsroom uses is the one approved by the United States National Institute of Standards and Technology for this purpose, with no retirement date set for it, and no practical attack against it is known. We would rather state it that way than claim something stronger that nobody could stand behind.

Checking it yourself

You do not have to take our word for any of this, and the check does not involve us. Every fingerprint appears on the version list at the shared table and on the closing record. On your own machine, against your own copy of the file:

shasum -a 256 master-services-agreement-v7.pdf

If the value matches the one on the record, you hold the agreed document. If it does not, you hold something else, and that is worth knowing before you sign rather than afterwards.

The same principle covers the record itself. Either party can export the full log of who did what and when, and verify on its own machine that no entry has been altered or removed, with no connection to Termsroom and no need to trust us. The trust page has the queries and the tooling.

The method, briefly

Termsroom uses SHA-256. It is a published international standard, it is what document signing products, evidence tooling and government systems use for this purpose, and it is approved by the United States National Institute of Standards and Technology for all uses of this kind with no transition date set. Where standards bodies believe a method is ending they say so and name a year; no such year has been named for this one.

Because records outlive methods, every fingerprint is stored alongside the name of the method that produced it, rather than assuming it. If the standard ever moves, the record says what it was calculated with and can be extended rather than replaced. Applying a trusted timestamp to the record produced when a negotiation closes, which would establish when it existed independently of us, is on the plan and is not in the product yet.

Related