The signature attaches to the submission data itself. Change the data, and the signature breaks.
Your team captures data in one system, exports it into a document flow, waits for a separate signature event, then has to reconcile the signed artifact back to the original submission. The signature may be complete, but the workflow now depends on two records staying aligned.
That gap gets worse when signed values feed downstream approvals, eligibility checks, underwriting, case management, or customer service workflows. Teams are left asking whether the document, the submission, the form revision, and the visible audit trail still describe the same transaction.
The risk surfaces the day a signed record has to survive an audit, a dispute, or a regulator's question. If the proof lives in a vendor's account, a PDF export, or a custom integrity layer, someone on your team has to explain where the signed data sits and what would invalidate it, under pressure, on the record.
You can build around it. It is rarely small. Cryptographic signing, key management, revision-aware validation, signature stamps, and API access all become infrastructure you own, patch, and defend the moment signed data has to stay trustworthy.
The stronger path is to bind signature proof to the form submission itself.



E-Sign+ is built for self-hosted Form.io environments, so signature records and protected submission data remain inside the customer's deployment. Teams do not have to move sensitive forms into an external signature service just to complete a regulated approval, consent, disclosure, or attestation step.
Signed data can be accessed through the native Form.io submission ID and APIs. That keeps the signature attached to the record your application already uses, instead of forcing developers to reconcile a detached document artifact with the form workflow that created the data.
Teams can configure signatures to protect selected fields, all form data, or chosen submission properties. When protected values or context change, the digital signature becomes invalid and the data is expected to be signed again, making integrity failure visible instead of hidden.
No. E-Sign+ is licensed as part of your self-hosted Form.io environment. There is no per-envelope or per-document meter, so signature volume is a capacity question inside your own deployment rather than a per-transaction line item.
Secondarily. E-Sign+ is decoupled from PDFs. It supports workflows that export to PDF when needed, but the core value is an immutable snapshot of form data inside the application. That matters when the submission record, not the document file, is the system of truth.
The customer supplies the private key strategy. E-Sign+ can use a private key configured in the enterprise server deployment or project-level integration with AWS KMS. The useful promise is not outsourced trust. It is cryptographic proof inside the environment your team governs.
E-Sign+ is an enterprise module for eligible self-hosted environments licensed for both the Security Compliance Module and E-Sign+. Configuration also depends on submission revisions and form revisions using the original form revision when viewing submissions, because signature validity depends on revision-aware context.
You will leave with a clearer view of what data needs to be signed, which fields or submission properties should be protected, how signature invalidation should work, and whether your current self-hosted license path supports E-Sign+. No production migration decision is required on the first call.
Bring one workflow. You will leave knowing what has to be signed for the record to hold up.
When signatures drift away from the submission layer, every review has to reconstruct what was signed and whether it still matches. E-Sign+ makes integrity part of the form workflow itself.
Per Form.io documentation, E-Sign+ verifies that the signed data and its context have not changed since signing.