GhostSignStudio

Verify a signed PDF's integrity — free, in your browser.

Drop in any file to see its SHA-256 fingerprint. For a signed PDF it checks the digital seal — GhostX's own, or any standard PAdES signature — byte for byte. Everything runs on your device.

GhostVerify reads a file entirely in your browser and shows you its SHA-256 hash — the fingerprint that changes completely if even one byte of the file changes. For a PDF signed with GhostSign it also reads the signing record embedded in the document's metadata: the original document hash, the signing timestamp, and the signer.

It's worth being precise about what that establishes, because "verified" is a word that invites over-reading. A hash comparison can only tell you whether a file matches a value recorded SOMEWHERE ELSE. It cannot, on its own, tell you who produced the document: someone could alter a contract, sign the altered version through GhostSign, and end up with a perfectly consistent file. Integrity and provenance are different claims, and a fingerprint speaks only to the first.

So the check that actually means something is an external comparison. Keep the SHA-256 from when the document was signed — it's printed on the audit certificate page — and compare it to the hash shown here. A match ties the file in your hands to that specific moment rather than merely to itself. For multi-signer documents, the certificate also prints a chain hash linking each signature to the one before it, which fixes the signing order; comparing those printed values is how you check a chain today.

How it works

  1. 1

    Drop in the file

    Any file works — a signed PDF, a contract, a photo, an archive. It's read in your browser and never uploaded.

  2. 2

    Read the fingerprint

    GhostVerify computes the SHA-256 hash and, for a signed PDF, validates its digital seal and timestamp — or, for older GhostSign PDFs, shows the signing record stored in their metadata.

  3. 3

    Compare it to what you recorded

    Match the hash against the value on the audit certificate, or against a copy the sender kept. That external comparison is what makes the check meaningful.

Good to know

  • A fingerprint, compared against something you already have

    The strongest use of this page is comparison. Hash the file, then check that value against the SHA-256 printed on the audit certificate or held by whoever sent it. That ties the file to a moment in time. Without an external reference, a hash only tells you what the file is right now.

  • Integrity is not provenance

    Even a matching hash doesn't prove who created the document. Someone could alter a contract and sign the altered version, producing a file that is internally consistent and entirely misleading. Consistency and authorship are separate questions.

  • Signing order is printed, not recomputed here

    Multi-signer certificates carry a chain hash that links each signature to the previous one, so the order can't be rearranged without breaking it. This page doesn't recompute that chain from an uploaded file — the chain view lives in the signing flow itself. Here you compare the printed values.

  • A different hash usually means a re-save, not tampering

    Opening a PDF in some viewers and saving it rewrites the file structure without changing anything you'd see, and that alone changes the hash. Print-to-PDF and some email gateways do the same. A mismatch tells you the bytes differ — not who changed them, or why.

  • Nothing is uploaded

    The hash is computed in your browser. That matters more here than almost anywhere else in GhostX: the documents people verify are usually contracts, and handing one to a verification service to prove it's private would rather defeat the point.

Frequently asked questions

  • What does the hash actually prove?

    That the file you have now is byte-for-byte the file that produced that hash. To turn that into a statement about a moment in time, compare it against a SHA-256 you recorded earlier — from the audit certificate, or from the sender's copy.

  • Can I verify a document I didn't sign with GhostSign?

    You can hash any file and compare it against a checksum you were given — that works for installers, archives, anything. Yes, if it carries a standard PDF digital signature (PAdES), as most e-signature products produce: this page checks that the signed content is unchanged and shows the name on the signing certificate. Only GhostX seals are matched to a known key, so for anyone else's signature the name is what the certificate claims, not something we can vouch for.

  • Can I check the order multiple people signed in?

    Not from an uploaded file on this page. The chain hash that fixes signing order is printed on the audit certificate, and the live chain view is part of the signing flow. Compare the printed chain values if you need to confirm an order after the fact.

  • The hash doesn't match what I expected — has the document been tampered with?

    Possibly, but re-saving is the more common explanation. Some PDF viewers rewrite the file on save without changing anything visible, which changes the hash. Ask the sender for their copy and compare before drawing any conclusion.

  • Is the hash the same as sha256sum would produce?

    Yes. It's a standard SHA-256 over the file's raw bytes, so sha256sum on Linux, shasum -a 256 on macOS, or CertUtil on Windows all produce the identical value — which means you can check our answer independently.

  • Is my document uploaded to verify it?

    No. The file is read and hashed in your browser; there is no upload endpoint for it to go to.

Everything runs in your browser. Your files are never uploaded — for the single-file tools there's no upload endpoint to send them to.

More from the GhostX family