Can E-Signatures Be Copied and Excised? A Plain-Language Guide
E signatures can be copied and excised, and if you're about to sign a contract, that phrase probably sounds like a reason to worry. Here's the honest answer: a pasted image of a signature can absolutely be copied onto another document, and it can be removed without leaving a trace. But a compliant e-signature can't be excised without detection. The difference comes down to whether the signature is just a picture or whether it's cryptographically bound to the document itself. That distinction is the entire game. Platforms like LoreSign are built to prevent exactly the problem the phrase describes, not by making signatures harder to copy, but by making any tampering impossible to hide. This guide covers where the phrase comes from, what "copied" and "excised" mean in practice, how the law treats each type of signature, and what you can and cannot do when signing electronically.
| At a glance | Details |
|---|---|
| Short answer | A pasted signature image can be copied; a compliant e-signature cannot be excised undetected |
| Where the phrase comes from | 21 CFR Part 11, the FDA rule for electronic records and signatures |
| What makes it tamper-evident | Cryptographic hash, audit trail, and a tamper-evident seal |
| Legal backing in the US | ESIGN Act and UETA give e-signatures the same force as ink |
| What you cannot e-sign | Wills, some family law documents, and certain notarizations |
| How to sign safely | Use a platform that tracks every signer and delivers the completed PDF automatically |
In This Guide
- What Does 'E Signatures Can Be Copied and Excised' Actually Mean?
- Pasted Signature Image vs Compliant E-Signature
- The Critical Difference: Signature Image vs. Compliant E-Signature
- E Signatures Can Be Copied And Excised: A Step-by-Step Guide by LoreSign
- Is It Legal to Copy and Paste a Signature?
- How Compliant E-Signature Platforms Prevent Copying and Excision
- Are E-Signatures Legally Binding? ESIGN, UETA, and 21 CFR Part 11
- What You Cannot Do with E-Signatures
- How to Verify an E-Signature's Integrity Before You Rely on It
- Common Myths About E-Signature Security
- Final Thoughts: What "Copied and Excised" Means for Your Next Contract
What Does 'E Signatures Can Be Copied and Excised' Actually Mean?
"Copied and excised" means someone can take a signature from one document and put it on another, or remove it from a document without leaving evidence. A compliant e-signature must not allow either without detection.
The phrase comes from 21 CFR Part 11, the FDA's rule for electronic records and signatures. It sets a standard: a valid e-signature has to be bound to the document it signs. If someone copies it or cuts it out, the tampering has to be detectable.
Where the phrase comes from (21 CFR Part 11)
21 CFR Part 11 is the regulation that governs electronic signatures in FDA-regulated industries. It says e-signatures must be "unique to one individual" and "not be reused or reassigned to anyone else." The copying and excision language is the test for whether a signature actually meets that bar.
What 'copied' means in practice
Copied means taking a signature from one document and pasting it onto another. A scanned image of a wet signature is trivially easy to copy. You can do it in any image editor. The copy looks identical because it is identical.
What 'excised' means in practice
Excised means removing a signature from a document without leaving a trace. With a simple image pasted onto a PDF, someone can delete it and the document looks like it was never signed. A compliant e-signature ties the signature to the document's contents, so removal breaks that binding and leaves evidence.
The phrase 'copied and excised' comes from 21 CFR Part 11, the FDA rule that sets the standard for electronic records and electronic signatures in regulated industries. It describes the risk that a signature could be lifted from one record and pasted into another — which is exactly what a compliant e-signature is designed to prevent.
Pasted Signature Image vs Compliant E-Signature
| Factor | Pasted Signature Image | Compliant E-Signature |
|---|---|---|
| Can it be copied? | Yes — anyone can copy the image and paste it elsewhere | No — the signature is bound to the document and the signer's identity |
| Can it be excised? | Yes — you can cut it out and move it to another page or file | No — removing or altering it breaks the tamper-evident seal and is detected |
| Proof of who signed | None — the image carries no identity data | Yes — the platform records the signer, time, and IP address |
| Audit trail | None | Full audit trail plus a certificate of completion |
| Legal weight | Weak — easy to dispute as a forgery | Strong — backed by the ESIGN Act and UETA |
The Critical Difference: Signature Image vs. Compliant E-Signature
A pasted image of a signature is just pixels. It carries no proof of who applied it, when, or to what. Anyone can copy it from one PDF and drop it onto another in seconds.
What a simple e-signature (image) can and cannot do
A scanned signature can show intent. Courts have accepted pasted images as evidence that someone meant to sign. But it cannot prove the document wasn't altered after signing. It cannot prove the signer actually applied it. And it cannot stop anyone from lifting it and reusing it.
What a compliant e-signature adds: cryptographic binding
A compliant e-signature doesn't just sit on top of the document. The platform runs the document through a hash function, which produces a unique fingerprint of its exact contents. That fingerprint gets bound to the signature. Change one character in the document and the fingerprint no longer matches. The tampering is detectable.
Why a pasted signature image is not legally meaningless but is easily forged
Here's the honest answer: a pasted image isn't worthless. Under ESIGN and UETA, intent matters more than format. But it's weak evidence. The other side can claim they never pasted it, or that the document changed after they did. You'll have no audit trail to fall back on. A compliant e-signature gives you the hash, the timestamp, and the signer's identity tied together. That's the difference between a signature and a signature you can defend.
If you regularly send contracts, set up reusable templates and a brand kit so every document goes out with the same fields and look — it saves time and makes the audit trail consistent across signers.
E Signatures Can Be Copied And Excised: A Step-by-Step Guide with Loresign
- Upload the PDF to a compliant e-signature platform instead of emailing a scanned image.

- Place the signing fields exactly where each signature, initial, and date belongs.

- Send one secure link to each signer, in the order you set if the document needs multi-signer routing.

- Let the platform record every signer's identity, timestamp, and IP address as they sign.

- Rely on automated reminders for anyone who has not signed yet.
- Receive the completed, signed PDF automatically once everyone has signed.
- Keep the certificate of completion and audit trail with the document as your proof.
Is It Legal to Copy and Paste a Signature?
No. Copying and pasting a signature without authorization is forgery or misrepresentation. Even with permission, a pasted image creates a weak evidentiary record.
What the law says about unauthorized signature copying
Forgery laws cover any false making or altering of a writing with intent to defraud. Pasting someone else's signature onto a contract fits that definition. You don't need a pen. You need intent.
Why even authorized copy-pasting weakens your legal position
If someone says "sure, paste my signature," you've got consent but no proof. No timestamp. No document fingerprint. No audit trail. The other side can later claim the document changed after they agreed. You'll have nothing to show otherwise.
The difference between a signature image and a legally binding e-signature
A legally binding e-signature ties the signer's identity to the exact document through a cryptographic hash and an audit trail. A pasted image ties nothing to anything. Both can show intent. Only one survives a dispute.
How Compliant E-Signature Platforms Prevent Copying and Excision
A compliant platform doesn't just store your signature. It binds it to the document so tightly that any change leaves evidence. Think of it as a wax seal: you can break it, but everyone will see the break.
Cryptographic hashing: the document's fingerprint
When you sign, the platform runs the document through a mathematical function that produces a unique string of characters. That string is the document's fingerprint. Change one comma, and the fingerprint changes completely.
The signature is tied to that fingerprint, not to the page. If someone copies the signature onto a different document, the fingerprint won't match. The copy fails verification.
Audit trails: who did what, when, and where
Every action gets logged: who opened the document, when they signed, what IP address they used, what device they were on. This record is stored alongside the signed document.
LoreSign records each signer and sends automated reminders for unsigned documents. When everyone has signed, the completed PDF is delivered automatically. The audit trail shows the full sequence, so a missing signature or a changed timestamp stands out.
Tamper-evident seals: why excision leaves a mark
If someone removes a signature from a signed document, the seal breaks. The document no longer matches its original fingerprint. Verification tools flag the mismatch immediately.
The honest answer is that no system stops a determined attacker from editing a file. What a compliant platform does is make the edit detectable. That's the difference between a pasted image and a signature that holds up in a dispute.
Are E-Signatures Legally Binding? ESIGN, UETA, and 21 CFR Part 11
Yes. In the U.S., e-signatures carry the same legal weight as wet ink. Two laws make that true: the ESIGN Act of 2000 and UETA, adopted by 49 states. New York has its own equivalent statute.
What ESIGN and UETA guarantee
ESIGN and UETA say a contract can't be thrown out just because it was signed electronically. The signature is valid, the record is valid, and courts must admit both. That's the floor, not the ceiling.
What 21 CFR Part 11 adds for regulated industries
21 CFR Part 11 applies to FDA-regulated companies: pharma, medical devices, biotech. It demands more than legal validity. Signatures must be unique to one person, the signer's identity must be verified, and the system must prevent copying or excision without detection. That's where the phrase comes from.
Legal binding vs. tamper-evident: two different things
A signature can be legally binding and still easy to forge. ESIGN doesn't require cryptographic sealing. A pasted image can satisfy the law in a low-stakes dispute and fail the moment someone contests it. Tamper-evidence is a platform choice, not a legal requirement.
What You Cannot Do with E-Signatures
E-signatures cover most contracts, but not all. Some documents still demand wet ink or a notary, and no platform can change that.
Documents that still require wet signatures
Wills and codicils generally need a physical signature. Many family law documents, including divorce decrees and adoption papers, do too. Some real estate deeds and mortgage documents still require wet ink depending on the county recorder. Check your local rules before assuming an e-signature works.
When notarization is required
Notarization is a separate step from signing. A notary verifies your identity in person and witnesses the signature. E-notarization exists in many states, but it's not universal. If a document says "must be notarized," a standard e-signature alone won't satisfy it.
What a simple e-signature cannot protect against
A scanned signature offers no protection. Anyone can paste it onto another document. It won't prove you signed that specific version, and it won't detect changes made after signing. If the document matters, use a platform with cryptographic sealing and an audit trail.
How to Verify an E-Signature's Integrity Before You Rely on It
You can't verify integrity by looking at the signature. You verify it by checking what the platform recorded when the document was signed.
Questions to ask before choosing an e-signature tool
Ask three things. Does the platform bind the signature to the document with a cryptographic hash? Does it keep an audit trail showing who signed, when, and from what IP address? Does it state compliance with ESIGN and UETA? If the vendor can't answer all three in plain language, walk away. Platforms like LoreSign publish these details because they're the baseline, not an upsell.
How to check a signed document's audit trail
Open the completed document in the platform that produced it. Look for a certificate of completion or audit log. It should list each signer, the exact timestamp, the email address used, and the IP address. If the document was altered after signing, the platform flags it. You don't need to read a hash yourself. You need the platform to show you the record.
Red flags that a signature may have been tampered with
A signature pasted as an image with no platform behind it is the biggest red flag. No audit trail, no certificate, no way to check the version history. If someone sends you a signed PDF and can't tell you which platform produced it, treat it as unverified. A real e-signature leaves a paper trail. A copied one leaves nothing.
Common Myths About E-Signature Security
Most fears about e-signatures come from confusing a pasted image with a compliant signature. The myths below keep circulating because they sound plausible. They don't hold up.
Myth: A scanned signature is just as secure as an e-signature
A scanned signature is a picture. Anyone can copy it, paste it onto another document, and send it along. There's no cryptographic binding, no audit trail, no timestamp. A compliant e-signature ties the signature to the document itself, so any change after signing breaks the seal. The two aren't in the same category.
Myth: E-signatures are not admissible in court
ESIGN and UETA have made e-signatures legally binding in the U.S. since 2000. Courts accept them as evidence when the platform provides an audit trail and a certificate of completion. What courts don't accept is a bare signature image with no record of who signed or when. The admissibility question is really a platform question.
Myth: All e-signature platforms offer the same protection
They don't. Some platforms let you upload an image and call it done. Others bind the signature to the document with a cryptographic hash, keep a full audit trail, and flag any post-signing change. The difference matters when a contract is challenged. Check what the platform records before you trust it.
Final Thoughts: What "Copied and Excised" Means for Your Next Contract
The phrase sounds technical. The practical meaning is simple: a compliant e-signature cannot be copied or excised without leaving evidence. A pasted image can.
That's the whole decision. If you're signing a contract that matters, don't paste a picture of your signature. Use a platform that binds the signature to the document with a cryptographic hash and keeps an audit trail. Then any attempt to copy or excise the signature breaks the seal, and the break is visible.
LoreSign does exactly this: upload the PDF, place the signing fields, send one secure link, and the completed document comes back with a certificate of completion and a public verification page. The audit trail records who signed, when, and from where. If someone tries to excise a signature later, the document won't verify.
The question "e signatures can be copied and excised" has one honest answer: only when they're not real e-signatures.
Frequently Asked Questions
Is it legal to copy and paste a signature?
Copying and pasting a signature image without the signer's permission is generally forgery and is not legal. Even with permission, a pasted image carries no proof of who signed or when, so it is weak evidence if the document is ever disputed. A compliant e-signature avoids this problem because it is tied to the signer's identity and recorded in an audit trail.
Can you copy and paste a digital signature?
You can copy the image of a signature, but you cannot copy a compliant digital signature in a way that still works. The signature is bound to the document through a cryptographic hash, so moving it to another document breaks the seal and the tampering is detected. This is the difference between a picture of a signature and a real e-signature.
Are e-signatures legally binding?
Yes, in most cases. In the United States, the ESIGN Act and the Uniform Electronic Transactions Act (UETA) give e-signatures the same legal force as handwritten ones, as long as the signer intended to sign and the record can be retained. Some documents, such as wills and certain family law papers, still require a wet signature or notarization.
Can a digital signature be duplicated?
A simple image of a signature can be duplicated easily, which is why pasted signatures are risky. A compliant e-signature cannot be usefully duplicated because it is tied to a specific document, a specific signer, and a specific time. Any attempt to reuse it on another document breaks the tamper-evident seal and shows up in the audit trail.
What does 'copied and excised' mean in 21 CFR Part 11?
It means a signature could be copied from one electronic record and cut out (excised) to be used on another. The FDA included this language to require that electronic signatures be linked to their records so they cannot be lifted and reused. A compliant platform meets this by binding the signature to the document with a cryptographic hash and a tamper-evident seal.
What can I not sign with an e-signature?
You generally cannot e-sign wills, codicils, and some family law documents such as divorce or adoption papers. Certain notarizations and some court filings also require a wet signature or an in-person notary. Always check your state's rules and the specific document's requirements before choosing an e-signature.
How do I know my e-signature was not tampered with?
Look for a certificate of completion and an audit trail that shows who signed, when, and from what IP address. A compliant platform also applies a tamper-evident seal, so any change to the document after signing is detectable. If the seal is broken, the document is no longer valid proof.
About LoreSign
LoreSign helps individuals and businesses create, send, sign, and track documents in one place. You can upload a PDF or create an agreement, add the required signing fields, send it to recipients, and automatically receive the completed document once everyone has signed.

