Per-envelope pricing is fine when you send ten contracts a year. A construction company that sends contracts to every contractor on every project sends hundreds, and each one was being printed, emailed as a PDF, signed with a pen and photographed back. We built signing into their operations portal instead.
This is not legal advice; it is an engineering account of what a signature flow needs so that a lawyer can be comfortable with it. The owner reviewed the design with counsel before launch, and you should too.
Four things the record has to prove
Electronic signature laws in the US (ESIGN and UETA) care less about how the mark looks and more about what you can show afterwards. In practice that comes down to four questions the system must answer for every signature.
- Who signed: an authenticated signer, invited by email, with the address and IP recorded.
- What they signed: the exact document version, hashed, so it cannot be swapped later.
- That they meant to: an explicit consent step and a visible act of signing, typed or drawn.
- When, and in what order: an append-only event log for every send, view, sign and counter-sign.
Seal the result
When the last party signs, the system renders a final PDF with every signature placed, appends a certificate page listing the signers, timestamps and IPs, and stores the hash. Nothing in that record can be edited through the portal; the contract events and signatures tables only ever grow.
Keep the humans in the right places
Managers draft from templates or free text, attach a PDF if needed, and add one or more contractor signers. Contractors see only contracts addressed to them. The company counter-signs last. Every role sees exactly what it needs and nothing else, enforced by permissions rather than by politeness.
The same portal then carries the project forward: budgets, categorised expenses with receipts, and reports. The contract is where the relationship starts, not a separate product.


