A drawn signature and a digital signature are different things. Here is which one you need
"Sign this PDF" can mean two things, and the difference matters more than the vocabulary suggests. The first meaning is the one everyone pictures: your handwritten mark, placed on the page where the line is. The second is a cryptographic operation that binds the document's contents to a certificate issued to you, so that any later change is detectable. Both are called signatures; both are legal in most contexts; only one of them is what a bank, a notary or a public administration means when it says "digitally signed". Knowing which is which saves a rejected filing or, worse, a dispute.
What a drawn or typed signature is
Technically, a visual signature is an image. Whether you draw it with a finger, type your name in a script font or upload a photograph of your signature on paper, the result is a picture placed onto the page as an annotation or as part of the page content. Our sign tool works this way and says so on its page. The PDF that comes out has no new cryptographic properties; it is the original document with an extra image in it, in the same way a stamp or a logo would be.
This is what the law calls a simple electronic signature in most frameworks: data in electronic form attached to other electronic data and used by the signatory to sign. It is not a lesser category by default. A very large share of everyday agreements — engagement letters, rental inventories, consent forms, internal approvals, delivery notes — are signed this way and are perfectly binding, because what makes a contract binding is the parties' intent and their ability to prove it, not the technology.
What a visual signature cannot do is prove anything by itself. Anyone with a copy of the image can place it on any document. If the other party later claims they never signed, the evidence that they did comes from outside the file: the email thread the PDF travelled in, the timestamps on the server that stored it, the fact that they acted on the agreement afterwards. That evidence is usually more than enough for ordinary disputes. It is not enough when a rule specifically requires a stronger form.
What a certificate-based digital signature is
A digital signature in the PDF sense (the standard is PAdES, built on the PDF specification's signature dictionary) works in three steps. First, a hash — a fixed-length fingerprint — of the document's bytes is computed. Second, that hash is encrypted with the signer's private key, which lives on a smart card, a USB token, a phone's secure enclave or a cloud HSM. Third, the encrypted hash, the signer's public certificate and optionally a timestamp from a trusted authority are embedded in the file. A viewer that opens the file recomputes the hash, decrypts the embedded one with the public key, and compares: if they match, the document has not changed since signing and the certificate identifies who signed.
The certificate is the part that makes this legally weighty. It is issued by a certification authority that verified the signer's identity, and it can be revoked. When the authority is one accredited by a government scheme and the private key is held on certified hardware, the result is what EU law (eIDAS) calls a qualified electronic signature, which is treated as equivalent to a handwritten one across all member states. Other jurisdictions have their own tiers with similar logic; in the United States the ESIGN Act and UETA are technology-neutral but courts weigh the strength of the evidence, and in Colombia Law 527 of 1999 and Decree 2364 of 2012 distinguish a firma electrónica from a firma digital backed by a certification entity.
The visible part of a digital signature — the box with a name, a date and sometimes a drawn mark — is just a rendering of the underlying data. It can be blank. What matters is the signature dictionary in the file, which a viewer such as Acrobat Reader validates and shows in its signature panel, typically with a green tick when the certificate chain is trusted and the document is unchanged.
The comparison that actually matters
- Identity: a visual signature asserts it; a digital one proves it, to the extent the certification authority verified it.
- Integrity: a visual signature detects nothing. A digital one makes any later change to the signed bytes detectable — and if changes are made after signing without a new signature, viewers flag the document as modified.
- Time: a visual signature carries whatever date is typed next to it. A digital one can carry a timestamp from a trusted authority proving the signature existed at that instant, which matters when a certificate later expires or is revoked.
- Non-repudiation: with a visual signature the signer can plausibly deny it. With a qualified digital signature the burden of proof reverses in many legal systems.
- Cost and friction: a visual signature takes ten seconds and no setup. A digital one requires obtaining a certificate, keeping its private key safe and using software that supports PAdES.
When the picture is enough
Use a visual signature when the counterparty accepts it and no rule requires more: most commercial agreements between businesses that already know each other, employment paperwork inside a company, quotes and order confirmations, school and medical consent forms, minutes and approvals. The practical safeguards that make these robust are procedural, not technical: send the signed file from an email account clearly yours, keep the original exchange, and where possible have the other party countersign and return the same file so both versions match.
It is also enough for one very common case: the document that will be printed anyway. A visual signature placed on the page prints exactly like ink, avoids the print-sign-scan cycle and keeps the document at its original quality. Nobody looking at the printout will know or care which tool placed the mark.
When you need the real thing
Use a certificate-based signature when the recipient tells you to, and expect that instruction from tax authorities, courts, company and land registries, public procurement platforms, banks for certain account operations, and any regulated process that names the signature level it requires. Also use it when the document is high-value enough that you would want to prove, years later, exactly what was signed and when — share transfers, guarantees, settlements. In those cases a visual signature is not merely weaker; it may be rejected outright, and the time spent placing it is wasted.
Where do you get one? Governments often issue certificates to citizens (national ID cards with a chip, in many countries), certification authorities sell them to businesses and professionals, and cloud signing services (DocuSign, Adobe Sign and their local equivalents) provide signatures whose legal tier depends on the identity checks performed. The tools on this site do not produce certificate-based signatures, and we would rather say so plainly than blur the line: what you get from the sign tool is the image, placed cleanly, on a file that never left your device.
One more thing: signatures and passwords
People sometimes password-protect a document after signing it visually, hoping the password stands in for integrity. It does not. A password controls who can open the file; it says nothing about whether the content was changed by someone who could. If integrity is the concern, a digital signature is the tool. If confidentiality in transit is the concern, a password on the signed file is reasonable — just send the password through a different channel from the file.