Send a client a signed proposal. They now have a file containing your signature as an image. Not a photograph of it, not an approximation, the actual asset.
Extracting it takes about thirty seconds with tools that ship on every operating system. Open the PDF, select the image, export. Or screenshot and crop, which is cruder and works fine.
What comes out can be placed on any other document. The result is visually identical to the original, because it is the original.
Why this is worse for service businesses
A software agency signs a lot of documents with a lot of people. Proposals, statements of work, change requests, NDAs, contractor agreements. Each one goes to a different party, and each one carries the same signature image.
After a year of trading, that image sits in the inbox of every client you’ve quoted, every contractor you’ve onboarded and every prospect who received a proposal and went elsewhere. That last group is worth thinking about, because they have no ongoing relationship with you and no reason to be careful with your files.
Nobody in that set has to be malicious for this to go wrong. A file gets forwarded. An inbox gets compromised. A laptop gets sold without being wiped properly.
What an image proves, and what it doesn’t
The mark communicates intention to a human reader. That’s genuinely useful and it’s why signatures exist at all.
What it doesn’t do is record anything about the act of signing. Look at a signature image on a document and ask three questions. Who applied it? When? To which version of the text?
The image answers none of them. The pixels are identical whether you placed them yesterday on the document you agreed, or someone else placed them today on a document you’ve never seen.
That’s the whole problem in one sentence, and it’s the sentence most people skip past because signatures on paper never had this property. A wet-ink signature is physically bound to the sheet it’s on. Lifting it and reapplying it required forgery skills. Lifting a PNG requires a mouse.
The evidence that actually holds
What makes a signed document defensible is a record, not a picture. Three things specifically: authentication of who signed, a timestamp of when, and proof the document hasn’t been altered since.
Put those together and a challenge becomes answerable. Someone claims they never agreed to clause 7? There’s a record of who authenticated, at what time, against a document whose content can be shown to be unchanged. Someone claims the amount was different? Same answer.
Without that record, the argument comes down to two parties asserting things about a picture, and the picture is the same in both stories.
Practical steps, in order of how much they cost
Stop sending high-resolution signature images where a lower-resolution one will do. This is weak mitigation and it’s free. A signature that’s legible but not print-quality is less useful to someone lifting it.
Keep the signature asset out of shared drives, project folders and template files. Agencies leak signature PNGs through their own template repositories more often than through anything an attacker does, usually because someone put a signed example contract in the folder new starters copy from.
For documents where the amount or the obligation is significant, use a signing process that produces a record rather than a decorated PDF. The distinction is not about the visual. It’s about whether anything exists, outside the file, tying a person to a moment and a document version.
And be specific with clients about which route a given document took. A proposal signed with an image is fine and everyone understands it. A statement of work worth six figures deserves better, and saying so during the sale is easier than explaining it during a dispute.
Where the image still belongs
None of this means signature images are useless. Plenty of paperwork has never needed more than a legible mark, and adding weight to all of it would slow everything down for no benefit.
Internal approvals, delivery confirmations, an email signature block, a document nobody will argue about. The picture does its job.
In Chaindoc, the tool that made the image can also apply it to a document properly, which is the useful combination: draw or type a signature once, keep it, and choose per document whether it’s decoration or part of a signed record. It needs a Chaindoc account, with signature creation and storage on the free tier.
The mistake isn’t using a signature image. It’s assuming the image is doing work it has never been capable of doing, and finding out at the point where somebody disagrees with you.
- How to Use Codex in VS Code - August 12, 2026
- Every Signed PDF You Send Contains a Reusable Copy of Your Signature - August 12, 2026
- What Software Agencies Actually Need From an SEO Partner - August 11, 2026



