A blockchain is only as trustworthy as the people allowed to write to it. On a public, permissionless chain, no single party can rewrite history, and that is a genuinely strong claim. On a private chain, the operator chooses the validators.
VeriDoc Global states that its VeriDoc Ledger operates under a Proof of Authority framework. Proof of Authority means the validating nodes are known and permissioned rather than open. Their published material does not name a public chain.
So what does the seal actually assert?
That the vendor recorded this hash, on the vendor's ledger, at this time. That is a real record. It is also the same kind of assurance any e-signature provider gives with an audit trail: the supplier vouching for the supplier's own data. The word blockchain does not, by itself, move the trust anywhere else.
| Capability | SignAndGo | VeriDoc Sign |
|---|---|---|
| Public verification, no login or upload | ||
| Scannable QR on the certificate | ||
| Tamper-evident audit trail | ||
| Evidence signed by an independent third party | RFC 3161 timestamping available | Vendor-operated Proof of Authority ledger |
| Verifiable with standard tools, without the vendor | OpenSSL and any RFC 3161 verifier | Verification through their platform |
| Reusable templates | ||
| Australian data residency (Sydney) | Not stated in published material | |
| Signing order, approvals and countersigning | ||
| Witnessed signatures | Not stated in published material | |
| Xero and Procore integrations |
VeriDoc Sign capabilities taken from VeriDoc Global and VeriDoc Sign published material, reviewed 16 August 2026. Where a capability is marked "not stated", we found no claim either way rather than evidence of absence.
Every audit certificate carries a QR code and a verification ID. Point a camera at it and the public verify page opens. No account, no app, no upload.
With RFC 3161 timestamping, an independent authority signs your document hash and the time using a key we never hold. We cannot backdate it, and neither can anyone else.
Because RFC 3161 is a published standard, a timestamp token can be verified with ordinary tools like OpenSSL. Your evidence does not depend on our platform still existing.
Under the Electronic Transactions Act 1999 (Cth) and its state equivalents, an electronic signature must identify the signatory, indicate their intention to sign, be as reliable as appropriate for the purpose, and the recipient must consent to the method used.
There is no blockchain requirement. There is no ledger requirement. What matters in a dispute is whether you can show who signed, that they meant to, and that the document has not changed since. That is an evidence question, and it is answered by an audit trail, a document hash, and ideally a timestamp from someone with no stake in the outcome.
No. Under the Electronic Transactions Act 1999 (Cth), a signature must identify the signatory, indicate their intention, be as reliable as appropriate for the purpose, and the recipient must consent to the method. Blockchain appears nowhere in the Act. A signature is not more enforceable because a hash was written to a ledger.
It depends entirely on who controls the ledger. A public, permissionless chain is genuinely outside any one party’s control. A permissioned Proof-of-Authority ledger is validated by nodes the operator chooses, so the assurance reduces to the vendor attesting to its own record. VeriDoc Global describes its ledger as operating under a Proof of Authority framework.
Every completed document is hashed and given an unguessable verification ID, printed on the audit certificate with a scannable QR code. Anyone can check it at signandgo.com.au/verify with no account and no upload. For evidence outside our own control, SignAndGo can also obtain an RFC 3161 trusted timestamp from an independent Timestamping Authority.
RFC 3161 is the internet standard for trusted timestamping. An independent authority signs your document hash together with the time, using a key the software vendor never holds. Because it is a published standard, the resulting token can be verified with ordinary tools such as OpenSSL, by anyone, without trusting us or asking our permission.
In Australia. Documents are held in Google Cloud Storage in Sydney (australia-southeast1), and SignAndGo is an Australian company billing in Australian dollars.