Electronic signatures: send a document, the other party signs in a browser, and both sides get a completed copy with an audit trail.
Build me document signing that replaces SignWell — and know what makes this ALMOST. The signing flow is a fortnight. What matters is **an audit trail that holds up**: a record of who saw what, when, from where, sealed so that any later change to the document is detectable. That is what is actually being bought, and whether it satisfies a particular law in a particular country is a question for a lawyer, not for this prompt. STACK - Node 20+ with Fastify, server-rendered HTML - SQLite through better-sqlite3, WAL mode - pdf-lib for filling and flattening, and a signing library for the cryptographic seal - Caddy in front THE DATA MODEL - documents: id, uid, title, owner_id, original_path, original_sha256, final_path, final_sha256, status, expires_at, created_at, completed_at - recipients: id, document_id, name, email, role, order_index, token, auth_kind, viewed_at, signed_at, declined_at, decline_reason - fields: id, document_id, recipient_id, kind, page, x, y, width, height, required, value — signature, initials, name, date, text, checkbox, dropdown - audit_events: id, document_id, recipient_id, kind, actor, ip_hash, user_agent_bucket, meta_json, at — append-only, enforced by a trigger, and the most important table here - templates: id, name, base_path, fields_json, roles_json - The original file is never modified. Every signature produces a new file, and both hashes are recorded THE AUDIT TRAIL - Every event: created, sent, delivered, opened, each page viewed, each field completed, signed, declined, downloaded, reminded, expired - Each with a UTC timestamp, the actor, a salted address hash and a coarse user agent - Nothing in this table is ever updated or deleted - At completion the trail is rendered as a page appended to the finished document: who signed, when, from where, and the hash of what they saw. A signature without that page is a picture of a name SIGNING ORDER AND ACCESS - Recipients in parallel or in a set order, with the next notified only when the previous finishes - Roles: signer, approver, viewer, and a carbon copy who receives the finished document - Each gets a long random token in their link, compared in constant time. No account, ever — requiring one is how a signing request goes unanswered for a week - Optional extra authentication before signing: a code by email, or a passphrase shared by another channel. Record which was used PLACING FIELDS AND SIGNING - Pages rendered to images for placement; fields stored in PDF coordinates, not screen pixels - Required and optional fields per recipient, validated before submission - Draw with a pointer or finger, type in a signature face, or upload an image - The drawn signature captured as a path and rasterised at print resolution, never screenshotted from the canvas at screen resolution - Works properly on a phone, because most signatures are collected on one - A clear review step showing every field before confirmation, and a decline path with a reason SEALING - On completion, flatten the fields and apply a document-level digital signature with a certificate held on the server. Any later change breaks it, which is the point - A timestamp from an RFC 3161 authority if one is configured, so the signature stays verifiable after the certificate expires - A verification page where anybody can upload the document and be told whether it is intact DELIVERY AND CHASING - Emails for each stage, plain and short, with the link and nothing else - Reminders on a schedule, at most one per recipient per day - Expiry, after which the link stops working and the document is marked expired - The finished document sent to everybody with the audit page attached OPERATIONS - .env: DATABASE_PATH, STORAGE_PATH, BASE_URL, SMTP_URL, SESSION_SECRET, HASH_SALT, SIGNING_CERT_PATH, TSA_URL - Migrations on boot, each once; files encrypted at rest - Nightly backup covering the database and the file store, with a tested restore. Losing a signed contract is not an outage, it is a loss - Health endpoint that seals a one-page document WHAT MATTERS MOST The append-only trail and the seal. Complete a document, change one byte, and confirm verification fails. And write the sentence about legal advice into the README and leave it there.
What you lose
- An audit trail with timestamps, addresses and a certificate that a court or a counterparty will accept
- Compliance with electronic signature law in several jurisdictions
- Reminders and sequencing when several people must sign in order
If you would rather not build
- DocuSign or Dropbox Sign, for the hosted version
- A signed PDF with a certificate, for simple cases
What it costs
read from their page 15 Aug 2026
| Plan | Billed monthly | Billed yearly | Last read |
|---|---|---|---|
| — | $10/mo | — | 15 Aug 2026 |
Their pricing page is where these came from. Seeing a different price? Tell us.
The escape hatch
open source · no votes, no paid placement
Docuseal
$0Self-hosted document signing with an audit trail and templates.
docusealco/docusealfree · open source
Documenso
$0Open-source signing with cryptographic sealing of the completed document.
documenso/documensofree · open source
Why this verdict
our own opinion · changed only by a person
56/100
Verdict kinda at 56. The mechanics are a weekend; producing evidence that survives a dispute is what the fee actually covers.
History
tracked since 10 Aug 2026 · nothing is ever overwritten
Questions about SignWell
answered from the record above
Is SignWell free?
No — the plan we track is $10 a month. Personal at around $10/month billed monthly, cheaper annually.
Can you replace SignWell by building your own?
ALMOST. A weekend of work, and real gaps remain. Replacement score 56 out of 100, build time a weekend. Read what you lose before you decide.
How much does SignWell cost?
$10 a month on Personal — $120 a year. Recorded 10 Aug 2026.
What do you lose by replacing SignWell?
An audit trail with timestamps, addresses and a certificate that a court or a counterparty will accept; Compliance with electronic signature law in several jurisdictions; Reminders and sequencing when several people must sign in order. If any of those carry weight for you, keep paying.
Is there an open-source alternative to SignWell?
Yes: Docuseal, Documenso. The prompt on this page is for when you want it your way instead.
Related entries
same category first, most replaced first
Every week, something stops being worth paying for.
New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.
free forever · no tracking pixel · stored here, never passed to anyone

