SignWell

signwell.comcontributed by Samuele Ongaro

ALMOST

A weekend of work, and real gaps remain.

Electronic signatures: send a document, the other party signs in a browser, and both sides get a completed copy with an audit trail.

Promptfree, for everyone, and the only version there is
Build me document signing that replaces SignWell — and know what makes this ALMOST.

The signing flow is a fortnight. What matters is **an audit trail that holds up**: a record of who saw what, when, from where, sealed so that any later change to the document is detectable. That is what is actually being bought, and whether it satisfies a particular law in a particular country is a question for a lawyer, not for this prompt.

STACK
- Node 20+ with Fastify, server-rendered HTML
- SQLite through better-sqlite3, WAL mode
- pdf-lib for filling and flattening, and a signing library for the cryptographic seal
- Caddy in front

THE DATA MODEL
- documents: id, uid, title, owner_id, original_path, original_sha256, final_path, final_sha256, status, expires_at, created_at, completed_at
- recipients: id, document_id, name, email, role, order_index, token, auth_kind, viewed_at, signed_at, declined_at, decline_reason
- fields: id, document_id, recipient_id, kind, page, x, y, width, height, required, value — signature, initials, name, date, text, checkbox, dropdown
- audit_events: id, document_id, recipient_id, kind, actor, ip_hash, user_agent_bucket, meta_json, at — append-only, enforced by a trigger, and the most important table here
- templates: id, name, base_path, fields_json, roles_json
- The original file is never modified. Every signature produces a new file, and both hashes are recorded

THE AUDIT TRAIL
- Every event: created, sent, delivered, opened, each page viewed, each field completed, signed, declined, downloaded, reminded, expired
- Each with a UTC timestamp, the actor, a salted address hash and a coarse user agent
- Nothing in this table is ever updated or deleted
- At completion the trail is rendered as a page appended to the finished document: who signed, when, from where, and the hash of what they saw. A signature without that page is a picture of a name

SIGNING ORDER AND ACCESS
- Recipients in parallel or in a set order, with the next notified only when the previous finishes
- Roles: signer, approver, viewer, and a carbon copy who receives the finished document
- Each gets a long random token in their link, compared in constant time. No account, ever — requiring one is how a signing request goes unanswered for a week
- Optional extra authentication before signing: a code by email, or a passphrase shared by another channel. Record which was used

PLACING FIELDS AND SIGNING
- Pages rendered to images for placement; fields stored in PDF coordinates, not screen pixels
- Required and optional fields per recipient, validated before submission
- Draw with a pointer or finger, type in a signature face, or upload an image
- The drawn signature captured as a path and rasterised at print resolution, never screenshotted from the canvas at screen resolution
- Works properly on a phone, because most signatures are collected on one
- A clear review step showing every field before confirmation, and a decline path with a reason

SEALING
- On completion, flatten the fields and apply a document-level digital signature with a certificate held on the server. Any later change breaks it, which is the point
- A timestamp from an RFC 3161 authority if one is configured, so the signature stays verifiable after the certificate expires
- A verification page where anybody can upload the document and be told whether it is intact

DELIVERY AND CHASING
- Emails for each stage, plain and short, with the link and nothing else
- Reminders on a schedule, at most one per recipient per day
- Expiry, after which the link stops working and the document is marked expired
- The finished document sent to everybody with the audit page attached

OPERATIONS
- .env: DATABASE_PATH, STORAGE_PATH, BASE_URL, SMTP_URL, SESSION_SECRET, HASH_SALT, SIGNING_CERT_PATH, TSA_URL
- Migrations on boot, each once; files encrypted at rest
- Nightly backup covering the database and the file store, with a tested restore. Losing a signed contract is not an outage, it is a loss
- Health endpoint that seals a one-page document

WHAT MATTERS MOST
The append-only trail and the seal. Complete a document, change one byte, and confirm verification fails. And write the sentence about legal advice into the README and leave it there.

What you lose

  • An audit trail with timestamps, addresses and a certificate that a court or a counterparty will accept
  • Compliance with electronic signature law in several jurisdictions
  • Reminders and sequencing when several people must sign in order

If you would rather not build

  • DocuSign or Dropbox Sign, for the hosted version
  • A signed PDF with a certificate, for simple cases

What it costs

read from their page 15 Aug 2026

PlanBilled monthlyBilled yearlyLast read
—$10/mo—15 Aug 2026

Their pricing page is where these came from. Seeing a different price? Tell us.

The escape hatch

open source · no votes, no paid placement

Docuseal

$0

Self-hosted document signing with an audit trail and templates.

docusealco/docusealfree · open source

Documenso

$0

Open-source signing with cryptographic sealing of the completed document.

documenso/documensofree · open source

Why this verdict

our own opinion · changed only by a person

56/100

Verdict kinda at 56. The mechanics are a weekend; producing evidence that survives a dispute is what the fee actually covers.

History

tracked since 10 Aug 2026 · nothing is ever overwritten

Interest · last 30 dayspeak 2/day
views01230 Aug4 Sept9 Sept14 Sept19 Sept24 Sept28 Sept
— views— prompt copies none yet— votes none yet

Questions about SignWell

answered from the record above

Is SignWell free?

No — the plan we track is $10 a month. Personal at around $10/month billed monthly, cheaper annually.

Can you replace SignWell by building your own?

ALMOST. A weekend of work, and real gaps remain. Replacement score 56 out of 100, build time a weekend. Read what you lose before you decide.

How much does SignWell cost?

$10 a month on Personal — $120 a year. Recorded 10 Aug 2026.

What do you lose by replacing SignWell?

An audit trail with timestamps, addresses and a certificate that a court or a counterparty will accept; Compliance with electronic signature law in several jurisdictions; Reminders and sequencing when several people must sign in order. If any of those carry weight for you, keep paying.

Is there an open-source alternative to SignWell?

Yes: Docuseal, Documenso. The prompt on this page is for when you want it your way instead.

Related entries

same category first, most replaced first

All 27 in Commerce & contracts

Not sending yet

Every week, something stops being worth paying for.

New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.

free forever · no tracking pixel · stored here, never passed to anyone

Esc