Quickstart: Digitize Your Ceremonies

Pair signature pads, build templates, configure routing, capture biometric strokes, verify identity via ID scan, generate cryptographic audit trails — the full setup in 6 steps, in under 25 minutes.

1

Enable the Aeion Bridge (For Hardware)

BrandModelsFeatures
**Wacom**STU-430 / 530 / 540 / 541Pressure-sensitive, monochrome
**Wacom**STU-300 / 320Basic, USB-powered
**Topaz**T-LBK460 / 462 / 463 / 765 / 776Pressure + tilt, signature replay
**Topaz**T-L755 / 760Color LCD, full-color rendering
BrandModelsOutput
---------------------------------------------------------------------------
HoneywellVoyager 1450g / 1452gPDF417 + 1D / 2D barcodes
ZebraDS9908 / DS9300 seriesPDF417 + driver's licenses
DatalogicQuickScan / Magellan seriesUniversal scanner
Generic USB HIDAny PDF417-capable barcode scannerPlug-and-play
2

Upload Your Document

Navigate to Admin → Esign → Documents → New Document and upload your PDF (contract, offer letter, consent form — whatever you need signed). Give it a title and description; Aeion creates the document record and you're ready to add signers in Step 3.

For reusable documents, open Admin → Esign → Templates and use the visual drag-and-drop field-placement builder: upload a source PDF, then drag to place and resize fields (text, date, checkbox, dropdown, signature) with normalized per-page coordinates. Each field can carry a crmMapping merge-field path for CRM auto-fill and a conditionalRule for show/hide logic, and a live preview resolves both as authored. Signers can also sign a plain document exactly as uploaded, using the capture methods below (browser canvas, or Witness Photo / ID scan / signature pad when a signer's config requires them).

3

Configure the Signing Workflow

ModeBehaviorWhen to use
**any**All signers can sign in any order, simultaneouslyMulti-party agreements with no order
**sequential**Signers in defined order; each must complete before nextPatient → doctor; lessee → landlord
4

Execute the In-Person Ceremony

When the workflow requires hardware (signature pad, ID scan), the in-person signing flow activates:

ID scan step:

  1. The system prompts "Please scan the back of your ID"
  2. Plug in (or use already-connected) 2D barcode scanner
  3. Scan the PDF417 barcode on a driver's license
  4. System parses ANSI/AAMVA spec → extracts Name, DOB, Address, License Number, Expiration
  5. Matches against the signer's pre-entered name (if pre-filled from CRM)
  6. Stores encrypted scan + verification result in the audit trail

Identity match scenarios:

  • Exact match — proceed to signature step
  • Close match (typo, hyphen difference) — admin override option
  • No match — abort with audit trail of the attempted ID

Anti-fraud features:

  • ID expiration check
  • Liveness check (optional — webcam-based, prevents photo-of-photo)
  • Backside-match verification (PDF417 + OCR of front)
  • AAMVA validity check (some states have specific format requirements)
5

Capture the Biometric Stroke

After identity verification, the signature pad activates:

On the device:

  • Wacom STU-540: shows "Please sign below" with brand logo
  • Topaz T-L755: shows the document preview + signature field
  • Pressure-sensitive devices capture up to 1024 pressure levels per sample point
  • Tilt-sensitive devices (Topaz pro models) capture stylus angle

Real-time render in browser:

  • Stroke renders into the PDF as the user signs
  • Biometric data (pressure curve, timing, velocity) captured separately
  • Customer sees their signature appearing on screen as they draw
  • Submit button only activates after minimum stroke length

Cryptographic seal on completion:

  1. A Certificate of Completion PDF is rendered (source document + a page listing every signer, timestamp, IP, and auth/capture method)
  2. A SHA-256 content hash of the complete sealed PDF is computed and stored — re-verifying the stored bytes at any time detects any post-seal change
  3. The per-document tamper-evident SHA-256 audit chain is verified and its integrity proof embedded in the certificate
  4. All artifacts are stored in the tenant's object storage; GET /esign/documents/:id/verify re-checks both the content seal and the audit chain on demand

> Cert-based signing is available for organizations that need it beyond the default content-seal path: configure a per-tenant X.509 signing certificate and Aeion embeds a PAdES / PKCS#7-detached signature into the sealed PDF. The SHA-256 content seal stays the default; PAdES is opt-in per tenant.

Audit trail contents:

  • Every action (open, view, scroll, field-fill, sign, decline) with timestamp + IP
  • Identity verification result + ID scan
  • Hardware device info (Vendor ID, model, firmware)
  • Biometric data (separate encrypted blob)
  • Document hash + signature chain
  • Witness photo (if required)
  • All recipient communications (emails, SMS) with delivery receipts
6

Wire Remote Signing + CRM Integration

For remote signing (no hardware), send the workflow link via email or SMS:

Remote signer experience:

  1. Receives branded email with secure link
  2. Optional pre-sign authentication (SMS-OTP, email confirmation)
  3. Opens link → views document on any device
  4. Fills required fields + signs (mouse / touch / typed name)
  5. Submits → cryptographic seal applied
  6. Receives signed copy via email automatically

Anti-fraud for remote:

  • IP + device fingerprint logged on every action
  • Suspicious-IP alerts (signing from country different than known IP history)
  • Multi-factor required for high-value contracts (>$10K, etc.)
  • Webcam liveness check optional for sensitive contracts

CRM auto-sync:

  • Completed contracts auto-link to the CRM contact + deal record
  • Contract metadata (counterparty, amount, expiration date, renewal date) populates CRM fields
  • Renewal-window alerts auto-create CRM tasks ("Renew NDA with ACME — 30 days out")

Bulk send: for repetitive contracts (1099s, NDAs, T&Cs), bulk-send to a CSV list of recipients. Each gets their own unique signing link with personalized prefilled fields.

Integration Recipes

CRM → contract sent. When a deal reaches a specific stage (e.g., "Verbal Yes"), Blueprint auto-fires a workflow that pulls the contract template, fills CRM data, and sends to the contact for signature.

Commerce → terms acceptance. Embed an esign workflow into the checkout flow — high-value purchases require T&Cs acceptance before payment. Audit trail proves the customer signed.

Legal → contract repository. Every signed document auto-files into the Legal module's contract repository with full metadata, renewal-window alerts, and cross-references between related contracts (master agreement → addendum).

Notifications → reminder cadence. A daily reminder sweep emits esign.reminder.sent for still-pending signers whose last reminder is older than the configured interval (default 3 days, capped at 3 reminders); the platform notification fan-out delivers them as email / SMS. Sequential workflows only nudge the currently-active signer.

Healthcare integration. Patient intake forms route through esign with HIPAA-compliant audit trails. Physician countersignature workflow ensures the signed-by-patient + signed-by-physician chain.

Real estate transactions. Multi-party workflows (buyer + seller + agents + attorneys + notary) with sequential routing. Each party's identity verified via ID scan; notary's signature includes a digital notary seal.

Troubleshooting

Signature pad not detected. Verify the Bridge is running. Check Admin → Bridge → Devices. If the device shows but is offline, unplug + replug. For Linux: confirm USB permissions (udev rules) allow access.

ID barcode scan fails. The PDF417 barcode on driver's licenses is small and can scan poorly with low-quality scanners. Try with a brighter light or higher-quality scanner. Some older state IDs use different formats — manual entry fallback always available.

Signer says they didn't receive the link. Check the workflow's notification log (Admin → Esign → Workflows → [workflow] → Notifications). Common cause: email in spam. Resend with SMS as backup channel.

Witness photo capture fails. Browser permissions for camera access. Grant in the browser's site settings. If using mobile, ensure HTTPS (camera APIs require secure context).

Workflow stuck after signer A but signer B not notified. Sequential workflows advance automatically. Check the trigger queue under Admin → Esign → System Health → Queue. If backlogged, restart the worker pool.

Audit trail PDF won't generate. Common cause: the document hash mismatch (the PDF was modified outside the signing flow). Check Admin → Esign → Workflows → [workflow] → Integrity Status. If hash mismatch, the workflow is compromised + must be re-initiated.

Frequently Asked Questions

Yes. Browser-based signing for any device. Remote signers receive a secure link; they type their name or draw their signature using mouse / touchscreen / stylus. No physical hardware required.

Progressive enhancement — UI falls back to standard web-based signing canvas instantly. The workflow doesn't break. The audit trail records the device-disconnect event for transparency.

If "Witness Capture" is enabled, the system prompts the operator to use the connected webcam to snap a high-resolution photo of the witness. Image is base64-encoded and permanently attached to the cryptographic audit trail appendix.

Yes — compliant with ESIGN Act (US), UETA (US states), eIDAS (EU), UK Electronic Communications Act, Singapore ETA, and India IT Act. The tamper-evident cryptographic audit trail provides evidence equivalent to or stronger than physical paper signatures.

Yes. The SHA-256 content-integrity seal and audit chain satisfy ESIGN Act / UETA requirements without a certificate authority, so content-sealing is the default. When you need cert-based signatures, configure a per-tenant X.509 signing certificate and Aeion embeds a PAdES / PKCS#7-detached signature into the sealed PDF.

Comparable feature set. Aeion advantages: included with platform (no per-envelope billing), native CRM / Commerce / Legal integration, biometric pad support that DocuSign lacks, lower long-term TCO especially at scale.

Aeion E-Sign supports Remote Online Notarization (RON) through integrated notary partners — Proof, BlueNotary, DocVerify, NotaryCam, and Pavaso. Configure a provider under RON provider settings and Aeion brokers the notarization session and records it against the signing document. A notary can also simply be one of the signing parties in a multi-signer workflow using their own physical or digital seal — that's just Aeion capturing their signature like any other signer's.

Yes. Configure under Settings → Esign → Storage Backends. Auto-route signed documents to BYOB S3 (Cloudflare R2, AWS S3, Wasabi, Backblaze). Retention policies per document type.

Configurable per workflow. Default: 7 years for contracts, 21 years for healthcare records, indefinite for notarized documents. Retention rules respect industry compliance (HIPAA 6yr, SOX 7yr, etc.).

Yes. The sealed Certificate of Completion PDF embeds the signed document plus every signer's audit log, identity-verification artifacts, witness photos, hardware device info, and the tamper-evident SHA-256 audit chain; `/esign/documents/:id/verify` re-validates the content seal and the chain on demand.

Ready to secure your contracts?