> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.bluenotary.us/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Are My Notarized Documents Secure? Understanding Digital Certificates, Tamper-Proofing, and Validation

When you complete a Remote Online Notarization (RON) or eSign session on BlueNotary, the finished document isn't just a PDF with a signature image on it. It's cryptographically sealed so that anyone who receives it later can prove two things: **who** notarized it, and that **nothing has been changed** since it was sealed. This article explains how that works and how you (or anyone you send the document to) can verify it.

# 1. How a Digital Certificate Works

A **digital certificate** is an electronic credential that binds an identity (a notary, a signer, or an organization) to a cryptographic key pair. It's the digital equivalent of a tamper-evident ID card, issued and vouched for by a trusted authority.

When a document is signed:
1. BlueNotary platform creates a hash – a "fingerprint" of the document's **exact** contents. Change a single character and the hash changes **completely**.
2. BlueNotary locks that fingerprint using the notary's private key (a secret only they hold). This locked fingerprint is the notary's seal, saved inside the document along with their certificate.
3. Later, anyone can use the notary's public key (included in the document) to unlock the fingerprint, recalculate the document's fingerprint themselves, and check that the two match. If they match, the seal is real and nothing in the document has been changed.

Because only the notary possesses their private key, a valid seal could only have been produced by them – this is what gives the document **non-repudiation** (the notarization can't credibly be denied or forged).
---
# 2. How Notarized Documents Are Tamper-Proof

A completed notarization carries a digital certificate and tamper-evident seal applied at the moment the notary finalizes the session. This is what makes the document tamper-proof in practice.

### What "tamper-proof" actually means
The document is more accurately **tamper-evident**: it's sealed so that any modification is immediately detectable. If someone alters the text, moves a signature, changes a date, or edits anything at all after sealing, the cryptographic hash no longer matches the signature, and the document reports itself as **invalid**.

### The layers that protect the document
*Note: Some of the following features may not be available for all accounts.* 
* **Document hash + digital signature.** As described above, the notary's private key signs a hash of the finalized document. Any post-seal edit breaks the match.
* **Notary's digital certificate.** The seal identifies the specific commissioned notary who performed the act, backed by a CA in a recognized trust chain — so the signature isn't just valid, it's attributable to a verifiable, authorized person.
* **Trusted timestamp.** A timestamp from a trusted Timestamp Authority (TSA) proves the document existed in its sealed form at a specific date and time, and that the notary's certificate was valid at that moment, even if the certificate later expires.
* **Locked PDF (certification signature).** The finished PDF is certified so that permitted changes are restricted; standard PDF readers will flag any modification made after certification.
* **Tamper-evident audit trail.** Alongside the document, BlueNotary maintains a session record — identity verification results, the notarial certificate, timestamps, and an event log – providing independent evidence of how the notarization was performed.
Together, these mean a BlueNotary document is a self-verifying legal instrument.
---

# 3. How to Validate a Notarized Document

### Option A: Validate in Adobe Acrobat / Acrobat Reader (recommended)
1. Open the notarized PDF in **Adobe Acrobat** or the free **Acrobat Reader**.
2. Look at the top of the document for a **signature banner**. A blue ribbon or "Signed and all signatures are valid" means the document is both intact and from a trusted source. You may instead see a warning that the signature's validity is unknown or has problems — on its own, this does **not** mean the document was altered; it usually just means your software hasn't been set to trust the notary's certificate yet (see the note below). What matters most is the integrity line in step 4.
3. Open the **Signature Panel** (click the banner, or the pen/signature icon in the left toolbar).
4. Expand each signature to review the **Signature Details**:**Signer identity** – the notary's name and issuing authority.**Signing time** – the trusted timestamp.**"Document has not been modified since it was signed"** – the key line confirming integrity.
5. Optionally, check the **certificate details** to see the issuing authority and trust path. If your software reports the certificate as untrusted, that reflects whether the certificate (called 'root') is installed on your device — not whether the document is authentic (see the note below).

If the document had been altered, Acrobat would instead show a warning such as "the document has been altered or corrupted since it was signed."

**Don't see a green checkmark?** If Acrobat shows "At least one signature has problems" or a yellow/unknown-identity warning, this usually does **not** mean the document is invalid — it means your Adobe software hasn't yet been told to trust the issuing root. Certificates that chain to the BlueNotary CA or IdenTrust Global Common Root (via the Federal Bridge) require a **one-time root certificate install** per computer before Adobe displays the checkmark automatically. The tamper-seal and document integrity are valid whether or not the checkmark appears; the checkmark is just Adobe's visual confirmation of trust. Contact BlueNotary support if you need the root certificate file and install steps.

### Option B: Look up the session on BlueNotary
Every notarization is tied to a session record you can look up directly at [**bluenotary.us/session-verification**](https://bluenotary.us/session-verification). 
1. Enter the **Session ID** (from your notarization confirmation email or the completed document if included) to confirm the session's status and open its session report, then cross-check those details – the notary, the date and time, and the document – against the record you're holding. If they match, you have independent confirmation that the notarization genuinely took place on the BlueNotary platform.
The audio/video recording of each session is securely stored for **at least 10 years** and can be downloaded at any time by the notary, providing a further durable record if a document's authenticity is ever questioned.

---

## Related Information
**Is a digitally notarized document legally valid?**
Yes. Remote Online Notarization is authorized in the majority of U.S. states, and electronic signatures and records are broadly recognized under the federal **ESIGN Act** and the **Uniform Electronic Transactions Act (UETA)**. A properly executed RON document carries the same legal weight as a traditional in-person notarization. Because it also carries cryptographic proof of integrity, it is often *easier* to defend than a paper original, which has no built-in tamper detection.
> Acceptance can vary by jurisdiction, recipient, and document type (some county recording offices and institutions have their own requirements). If a document is for a specific recording office, lender, or court, confirm their acceptance criteria in advance.

**Why can't someone just edit the PDF afterward?**
They can open and attempt to edit it — but the moment they save a change, the hash no longer matches the notary's signature, and any validator (Acrobat included) will report the document as modified/invalid. The edit doesn't go unnoticed; it destroys the seal's validity, which is exactly the point.

**Which certificate authority issues the seal?**
Individual notaries commonly use **IdenTrust Basic** certificates, which trace back to the IdenTrust Global Common Root through the U.S. Federal Bridge — a legitimate, government-grade trust program. This is a different trust path from the Adobe Approved Trust List (AATL) you may see mentioned elsewhere. Both are valid; the only practical difference is that Federal Bridge certificates may require the one-time root install described above before Adobe shows a green checkmark automatically.

**What if the certificate has expired?**
An expired certificate does **not** invalidate a document that was signed while the certificate was valid. The **trusted timestamp** proves the signature was applied during the valid period, so the notarization remains verifiable indefinitely.

**Keep the original file**
Validation depends on the embedded cryptographic data. Printing the document, taking a screenshot, or re-saving/"flattening" it through another tool can strip out the signature and seal. Always retain and share the **original signed PDF** to preserve verifiability.


**Explain the building blocks**
1. **Key pair**: Every certificate is tied to two mathematically linked keys: a **private key**, kept secret by the holder, and a **public key**, shared freely, with a special property: What one key **locks**, **only** the other can **unlock**.
2. **Certificate Authority (CA)**: A trusted third party that verifies the holder's identity and issues the certificate. 
3. **The certificate itself.** A file containing the holder's identity details, their public key, the issuing CA, a validity period, and the CA's own digital signature over all of it.
---

**Need help?** If a document you received won't validate, or you're unsure whether a recipient will accept a digitally notarized record, contact BlueNotary support with the document and any verification link so we can help you confirm its status.