Triangle Authentication™

When a signature is challenged,
yours holds.

Every RegSecure signature captures three proofs: the signer's identity check, their presence on live video, and exactly what they signed, sealed together in one moment. If anyone ever disputes it, you hand over the proof.

No registration · No downloads · Works in any browser

Court-Ready Evidence
Biometric Checks Stay On-Device
Tamper-Evident by Design
Nothing Stored on Any Server

One signature. Three proofs.

A disputed signature comes down to three questions: did this person sign, were they actually present, and is this the document they saw? Triangle Authentication answers all three at once, and that triangle is the one in our logo.

Who Signed

Identity

The other party watches the signer sign, live on video, the way a notary witnesses a signature, and the signer's face at that instant is preserved in the evidence, as an image and as a cryptographic fingerprint. Supporting that witness, the signer completes their device's own check (Face ID, Touch ID, Windows Hello, or a passkey where available, or manual confirmation as a clearly labeled fallback), bound to the same moment as the video frame and the document. No one is matched against an outside identity record; the preserved, tamper-evident witness is the identity evidence.

That They Were There

Presence

At the moment of signing, a frame from the signer's live video is captured and cryptographically fingerprinted. The evidence shows a person, on camera, at that instant, rather than a credential replayed by someone else.

What They Signed

Document

A SHA-256 fingerprint of the exact document bytes. Change a single character, one comma, and the seal visibly breaks. The signature cannot be moved onto a different document.

Triangle Binding
All three proofs are captured together as a single atomic act, one continuous moment, and sealed into one tamper-evident record.

Three excuses. None of them survive.

“Non-repudiable” is a legal word for a simple idea: the signer cannot plausibly walk the signature back later. Every route to denial is answered by evidence captured at the moment of signing.

“It wasn't me.”

Answered by identity. The evidence pairs the live video frame of who was sitting there with the check the signer completed on their own device at that instant (biometric, passkey, or manual confirmation) and exactly when. The method used is recorded as a fact in the evidence, whichever one it was.

“I wasn't there.”

Answered by presence. A frame of the signer, live on camera at the instant of signing, is fingerprinted and preserved in the evidence package, alongside the visual snapshot itself.

“That's not what I signed.”

Answered by the document fingerprint. The cryptographic hash matches only the exact file that was on screen. Any alteration, before or after signing, is immediately detectable by anyone who re-checks it.

What the evidence package contains

Every signature produces one record you can hand to a lawyer, a regulator or an opposing party: which check the signer completed on their device and when, the fingerprint of the live video frame, the SHA-256 hash of the exact document that was on screen, the timestamp of each element, and a hash-chained audit trail of the session around them. Each of those can be re-checked independently, years later, by anyone holding the file.

How the binding works

One atomic act

The identity confirmation, the video-frame hash, and the document hash are captured together in one continuous moment and combined into a single record. A SHA-256 binding hash covers the three proofs and their capture timestamps, so none of them can be swapped out later without visibly breaking the record. Each element carries its own timestamp, preserved in the package, so anyone examining the evidence can see for themselves how tightly the three were captured together.

Hash-chained audit trail

Every session event is appended to an audit trail: joins, document shares, signatures. Each entry is hashed over its own content, and those hashes are combined into a Merkle root sealed with the evidence. Altering, inserting or removing an entry changes that entry’s hash or the root, and anyone who recomputes them sees it. Each device chains its own entries against its own local view of the session, so across a merged multi-party export prevHash is a per-writer pointer rather than one linear chain. Integrity rests on the entry hashes and the Merkle root, and the bundle states that procedure in writing. The signature sits inside a tamper-evident record of the whole session, exported in full with the evidence.

The evidence package

Three artifacts, all generated entirely in the browser. The JSON evidence bundle is the authoritative one: the document fingerprint, each signature’s full binding and signer snapshot, and the complete audit trail. Once signing completes, the signed document is produced as a single file, with the original pages stamped where the signatures were placed and the certificate appended at the end. That file carries its own SHA-256, recorded in the bundle. The hash the signatures attest to remains the original document’s. A standalone certificate of signature can also be generated at any point for quick legal review. RegSecure’s servers never see, store, or transmit any of them.

Verifiable but deliberately ephemeral

From the exported package, anyone can verify with standard SHA-256 tooling that a document matches the recorded fingerprint by re-hashing the file and comparing it, and that every audit entry still hashes to its recorded value and those hashes still produce the sealed Merkle root. The PDF certificate carries the same record in human-readable form. One thing deliberately cannot be re-verified later: the cryptographic attestations the participants' browsers exchange during the live session. RegSecure destroys every session key the moment the session ends. That is crypto-shredding, and it means no one, including us, can ever decrypt or re-derive anything from a past session. That is the trade we chose: the durable evidence lives in the hashes and the audit chain; the keys protecting the live conversation are gone forever.

Continuity across engagements

A professional can enrol one signing credential on their own device. Enrolment is optional and happens once. Every signature they produce afterwards carries an assertion from that credential, checked in the browser against the public key recorded at enrolment. Anyone holding two evidence bundles from that professional can confirm that the same credential signed both, without an account and without contacting us. The claim this supports is narrower than identity: the signature came from the holder of the credential enrolled on a stated date. Clients are never enrolled, and their signing ceremonies stay unlinkable between sessions.

The precise capture parameters and binding construction are part of our patent-pending method. Full technical documentation is available to auditors, counsel, and enterprise customers under NDA.

Built for the rules of evidence

Enforceable electronic signatures rest on a few core requirements: intent to sign, consent, a signature attributable to the signer and associated with the record, and record integrity. Triangle Authentication is engineered to produce evidence for each.

ESIGN ActUnited States (federal). Designed to satisfy the requirements for legally enforceable electronic signatures
UETAUnited States (state). Designed to satisfy attribution and record-integrity requirements
eIDASEuropean Union. Designed to support eIDAS-aligned evidentiary standards

RegSecure produces the evidence; the legal effect of a signature is ultimately determined by the court or regulator applying the law of your jurisdiction. Consult your counsel for jurisdiction-specific requirements.

Your next signature can be undeniable.

Video, signing, and a court-ready evidence package in a single encrypted browser session.
No registration, no downloads, no data on our servers.