Public validator
The validator is a public Ravisign page where anyone can check whether a document was signed through the platform and whether it has not been altered. No sign-in is needed. It is located at the /validar.php address of Ravisign and is the destination of the QR code printed on the manifest.
Look up by code or by link#
Type the envelope code (printed on the manifest, in the format 157b650a-75e0-4eaa-a32c-b92b5a432ee4) or paste the validation link, and click look up. Scanning the QR code on the manifest with a phone does the same.
The result shows:
| Information | Detail |
|---|---|
| Status | Completed, in progress, declined, expired or canceled, with the completion or cancellation date |
| Envelope code | The identifier looked up, with a button to copy it |
| Signature type | The envelope level (simple or advanced) |
| Signatures | For each party: partially masked name and contact, role, status and date on which they signed or declined |
| Hash of the original | SHA-256 of the PDF sent for signature |
| Hash of the final copy | SHA-256 of the final PDF, after completion |
| Last trail event | Hash that closes the envelope's audit trail |
| Protection | The protection seal of the final copy (see below) |
To protect the parties, the validator shows personal data only partially masked and never shows CPF, IP or the content of the document.
Protection seal#
| Seal | Meaning |
|---|---|
| Digital signature with timestamp and long-term validation data | Platform signature with timestamp and embedded validation information (PAdES-B-LTA). This is the intended level |
| Digital signature with timestamp | Platform signature with an ICP-Brasil timestamp |
| Platform digital signature | Platform signature without a timestamp |
| The final copy has not been generated yet | The envelope has not been completed or the final copy is being assembled |
Check a file#
In addition to looking up the code, you can upload the PDF you have at hand. The validator calculates the SHA-256 of the file and compares it with the recorded hashes:
| Result | Meaning |
|---|---|
| Matches the final copy | The file is exactly the signed copy |
| Matches the original | The file is exactly the document sent for signature, still without the manifest |
| Matches the manifest | The file corresponds to the envelope manifest |
| No match | The file was altered or does not belong to this envelope |
The uploaded file is used only for the calculation and is not stored.
Tip "No match" is the expected result for a PDF that was printed and scanned, or saved again by another program: any change to the file changes the hash. To check, use the original file received by email or downloaded from the panel.
Check outside Ravisign#
The final copy is signed with an ICP-Brasil certificate, so it can also be checked in the ITI Conformity Verifier, at verificador.iti.gov.br, without depending on Ravisign. The audit trail can be verified independently with the formula described in Audit trail.
Contact Ravi Systems support at the e-mail below.