When a signature is challenged,
yours holds.
Every RegSecure signature captures three proofs: the signer's identity check, their presence on live video, and exactly what they signed — sealed together in one moment. If anyone ever disputes it, you hand over the proof.
No registration · No downloads · Works in any browser
The Three Proofs
One signature. Three proofs.
A disputed signature comes down to three questions: did this person sign, were they actually present, and is this the document they saw? Triangle Authentication answers all three at once — that triangle is the one in our logo.
Identity
The signer confirms their identity at the moment of signing — with Face ID, Touch ID, Windows Hello, or a passkey where available, or manual confirmation as a clearly labeled fallback. Biometric and passkey checks happen entirely on the signer's own device: no biometric data is ever transmitted, and RegSecure never sees it.
Presence
At the moment of signing, a frame from the signer's live video is captured and cryptographically fingerprinted. The evidence shows a person, on camera, at that instant — not a credential replayed by someone else.
Document
A SHA-256 fingerprint of the exact document bytes. Change a single character — one comma — and the seal visibly breaks. The signature cannot be moved onto a different document.
Non-Repudiation
Three excuses. None of them survive.
“Non-repudiable” is a legal word for a simple idea: the signer cannot plausibly walk the signature back later. Every route to denial is answered by evidence captured at the moment of signing.
Answered by identity. The evidence records how the signer's identity was confirmed at the moment of signing — biometric or passkey verification completed on their own device, or manual confirmation — and exactly when. Biometric and passkey signings are marked forensic-grade; manual ones are labeled as such.
Answered by presence. A frame of the signer, live on camera at the instant of signing, is fingerprinted and preserved in the evidence package — alongside the visual snapshot itself.
Answered by the document fingerprint. The cryptographic hash matches only the exact file that was on screen. Any alteration — before or after signing — is immediately detectable by anyone who re-checks it.
Evidence graded honestly
Not every signing meets the highest bar — a signer on an older device may confirm manually instead of biometrically. When that happens, the evidence package says so: the signature is recorded, but it is not marked forensic-grade. Your strongest evidence stays credible in front of a judge precisely because the weaker cases are never inflated.
For Technical Readers
How the binding works
One atomic act
The identity confirmation, the video-frame hash, and the document hash are captured together in one continuous moment and combined into a single record. A SHA-256 binding hash covers the three proofs and their capture timestamps, so none of them can be swapped out later without visibly breaking the record. Captures completed quickly enough with biometric or passkey verification are marked forensic-grade; anything slower, or confirmed manually, is recorded and labeled honestly.
Hash-chained audit trail
Every session event — joins, document shares, signatures — is appended to a hash-chained audit trail: each entry cryptographically references the one before it. Removing, reordering, or editing any entry breaks the chain visibly. The signature doesn't stand alone; it sits inside a tamper-evident record of the entire session, exported in full with the evidence.
The evidence package
Two artifacts per session, both generated entirely in the browser: an authoritative JSON evidence bundle — document fingerprint, each signature's full binding and signer snapshot, and the complete audit chain — and a human-readable PDF certificate for quick legal review. RegSecure's servers never see, store, or transmit either one.
Verifiable — and deliberately ephemeral
From the exported package, anyone can verify with standard SHA-256 tooling that a document matches the recorded fingerprint — re-hash the file and compare — and that the audit chain is internally intact, end to end. The PDF certificate carries the same record in human-readable form. One thing deliberately cannot be re-verified later: the cryptographic attestations the participants' browsers exchange during the live session. RegSecure destroys every session key the moment the session ends — crypto-shredding — so no one, including us, can ever decrypt or re-derive anything from a past session. That is the trade we chose: the durable evidence lives in the hashes and the audit chain; the keys protecting the live conversation are gone forever.
The precise capture parameters and binding construction are part of our patent-pending method. Full technical documentation is available to auditors, counsel, and enterprise customers under NDA.
Standards
Built for the rules of evidence
Enforceable electronic signatures rest on a few core requirements: intent to sign, consent, a signature attributable to the signer and associated with the record, and record integrity. Triangle Authentication is engineered to produce evidence for each.
RegSecure produces the evidence; the legal effect of a signature is ultimately determined by the court or regulator applying the law of your jurisdiction. Consult your counsel for jurisdiction-specific requirements.
Your next signature can be undeniable.
Video, signing, and a court-ready evidence package — in a single encrypted browser session.
No registration, no downloads, no data on our servers.