> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vumasign.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Sealing

> What happens when the last recipient finishes.

When the last recipient finishes, the envelope is **sealed**, and that is one pipeline with no
options: the field values are flattened into the PDF, a Certificate of Completion is generated and
appended, and then the whole assembled document is signed.

* ⚠️ The signature covers the flattened fields **and** the certificate, because signing happens
  last. One applied before the certificate was appended would either be invalidated by appending
  it or — worse — stay technically valid while covering only part of what a reader sees.
* ⚠️ A live seal is a **PAdES signature with long-term validation and an RFC 3161 timestamp** —
  everything needed to verify it is inside the file, and verifying it never asks us anything. It
  is not yet **trusted**, though: our AATL certificate has not arrived, so we sign with one this
  organisation issued to itself, and Adobe Reader reports “signature validity unknown” on it. That
  is correct — no public trust store carries the issuer — and your recipients will see the yellow
  bar. The seal is intact and the audit trail proves who signed independently of the certificate,
  but we would rather you heard this from us than from a customer. Swapping in the AATL
  certificate is configuration on our side, not a release of this product; documents sealed
  before the swap keep the certificate they were sealed with. The swap moves the **live
  certificate only**: the sandbox seals under separate configuration of its own, so nothing you
  rehearse against the sandbox changes on the day the AATL certificate arrives.
* ⚠️ A sandbox seal is a **real seal by a certificate that is not our binding one**. Every page is
  watermarked, the seal covers the watermark, and your PDF reader will report the signature as
  intact and its issuer as untrusted — which is exactly the case your verification code needs to
  handle and the one you would otherwise never get to rehearse. The certificate itself names a
  sandbox authority, so a verifier reading nothing but the signature panel can tell a test
  document from a real one. Which of the two you get is decided by the credential that created
  the envelope, and is never inferred later.
* A sealed document is **not recallable**. Rehearse with a [test key](/concepts/test-and-live).
