26 Jul 20268 min readKathmandu
Are E-Signatures on Proposals Legally Binding?
Short answer: yes, for almost everything a freelancer or agency signs. The longer answer is about evidence — and it's the part that matters if anyone ever disputes it.
Not legal advice.We build proposal software, we're not your lawyers, and none of us are qualified to be. This is a plain-English orientation to well-established law. For anything high-value, cross-border, or unusual, pay a professional for an hour of their time.
The two US laws that settled this
Electronic signatures have been enforceable in the United States for over two decades, under two complementary pieces of law.
The ESIGN Act (2000) is federal, and its core provision is refreshingly blunt: a signature, contract, or record relating to a transaction in or affecting interstate commerce may not be denied legal effect, validity, or enforceability solely because it's in electronic form. A signature can't be rejected for being electronic. That's the whole idea.
UETA (1999) is the model state law that does the same work at state level, adopted in nearly every US state. Between the two, an electronically signed proposal is treated the same as one signed in ink, in essentially every state.
Both laws are deliberately technology-neutral. Neither requires a certificate, a specialist vendor, or a particular cryptographic method. What they require is intent and attribution — that the signer meant to sign, and that you can show it was them.
What actually makes an e-signature valid
Four elements do the work, and they come up in one form or another in most jurisdictions.
1. Intent to sign.The signer has to take a deliberate action that means “I agree” — typing their name in a signature field, drawing it, ticking an affirmative box. A pre-ticked checkbox is a problem precisely because it isn't an action.
2. Consent to do business electronically. Both parties need to be willing to transact this way. Between businesses this is generally implied by conduct — you sent a link, they signed it — but consumer transactions in the US carry extra disclosure requirements under ESIGN, which is one reason consumer-facing lending and insurance paperwork looks the way it does.
3. Attribution. You need to be able to connect the signature to a person. Not with certainty — with evidence: the email address it was sent to, the address that signed, the IP, the timestamp, the device. This is where most disputes actually live.
4. Record integrity. The signed document has to be retained in a form that accurately reflects what was agreed and can be reproduced. If you can silently edit the terms after signing, the record proves nothing.
What e-signatures don't cover
There are carve-outs, and they're worth knowing even though they rarely touch client services work. ESIGN excludes things like wills and testamentary trusts, certain family-law documents such as divorce decrees, some court orders and official notices, and specific notices around utility cancellation, eviction, foreclosure, and health or life insurance lapse. Various jurisdictions add their own: documents requiring notarisation or registration, some property deeds, and some negotiable instruments.
None of that describes a design retainer, a development statement of work, or a photography booking. If you're signing a will electronically, you have bigger problems than which proposal tool to use.
Outside the United States
EU:the eIDAS Regulation recognises three tiers — simple, advanced, and qualified electronic signatures. Simple electronic signatures are admissible and valid for most commercial contracts; qualified signatures, which require an accredited trust service provider, carry the same legal effect as a handwritten signature and reverse the burden of proof. Ordinary B2B service agreements typically don't need the qualified tier.
UK:the Electronic Communications Act 2000 and the UK's retained eIDAS framework make electronic signatures valid for most commercial contracts, and the Law Commission confirmed in 2019 that they can be used to execute documents including deeds where the usual formalities are met.
Australia: the Electronic Transactions Act 1999 and its state equivalents validate electronic signatures where identity, intent, and consent to electronic form can be shown.
India: the Information Technology Act, 2000 recognises electronic records and signatures, with particular standing given to Aadhaar-based eSign and Digital Signature Certificates. Certain instruments are excluded, including some deeds, negotiable instruments, and documents needing registration — so Indian users should read that list before assuming coverage.
Canada: PIPEDA at federal level plus provincial acts, with Quebec running its own civil-law framework.
The pattern across all of them: for ordinary commercial agreements between businesses, a well-evidenced electronic signature is fine. The differences appear at the edges — statutory instruments, property, consumer protection, and anything requiring a notary.
The part that decides disputes: your evidence
Almost nobody argues that electronic signatures are invalid as a category anymore. What gets argued is “I didn't sign that” or “that's not what it said when I signed it.” Both are evidence questions, and both are won or lost by what your tool recorded at the moment of signature.
A screenshot of an email saying “yep, approved!” is genuinely some evidence — courts have upheld far less. But it's weak: no timestamp you can prove, no connection to a specific version of the document, nothing tying it to a device. A signature record with an audit trail is the difference between arguing and pointing.
What ApeiroCraft captures
Since we're describing what good looks like, here's exactly what our own signature record contains — verifiable against the product rather than aspirational:
- The signer's typed full name
- The signer's email address
- The signature image itself — drawn on the page or rendered from the typed name
- The IP address the signature came from
- The browser and device user-agent string
- A UTC timestamp of the exact moment of signing
- An explicit affirmative checkbox — the signer ticks that they agree, it's never pre-ticked
- A dated event trail of when the proposal was sent, first opened, re-opened, and signed
And the property that matters most: the signature is immutable once captured. The system will not overwrite an existing signature, and only a proposal in a sent-and-unsigned state can be signed at all. There is no path through the product where a signed proposal quietly acquires different terms — which is precisely the integrity requirement the law asks about.
Two honest limits. First, ApeiroCraft's signatures are simple electronic signatures in eIDAS terms — well-evidenced and appropriate for commercial service agreements, but not qualified signatures backed by an accredited trust provider, and not Aadhaar-based DSC signing for Indian statutory use. If your contract specifically requires either, you need a specialist provider. Second, we don't hold SOC 2 or HIPAA certification, so regulated-industry procurement may rule us out on those grounds regardless of signature quality.
Practical habits worth adopting
Send the proposal to the signer's own email address rather than a shared inbox — attribution is much stronger when the link went to one named person. Make sure the terms live inside the signed document, not in a separate attachment nobody signed. Keep the signed record and its audit trail rather than exporting a PDF and deleting the original. And when the person signing isn't the person paying, ask early whether they have authority to bind the company, because no signature technology fixes a signer who never had the power to agree.
Then stop worrying about it. The law settled this in 1999 and 2000; the remaining question was only ever whether your tool keeps a record worth showing. If you want the practical side of getting proposals signed at all, the follow-up cadence piece is more useful than any legal analysis, and the proposal templates all end in a signature page for exactly this reason.