You sign a contract on DocuSign at 2:47 p.m. on a Tuesday. Your vendor in Kuala Lumpur countersigns. Two years later, the contract lands in front of a Malaysian judge—and the question isn't whether the agreement exists. It's whether the signature itself is admissible as proof. E-signature platforms claim court enforceability as a standard feature. But 'enforceability' in Malaysia and Singapore means three separate battles: stamp duty classification, audit trail robustness under cross-examination, and admissibility under evidence law. Most e-signature vendors optimize for speed and ease of use. None of them optimize for what a Southeast Asian courtroom actually requires. We tested DocuSign, PandaDoc, and Adobe Sign against Malaysia's Stamp Act 1949 and Singapore's Evidence Act. Here's what we found—and what you need to verify before your vendor locks you in. The three tests every contract must pass An e-signed contract in Malaysia or Singapore faces three distinct legal gates: Stamp duty classification: Is the contract classified correctly for duty purposes? A misclassified e-signature doesn't void the contract, but it exposes you to back-duty liability and penalty interest. Audit trail defensibility: Can the platform prove when the signature was placed, by whom, from where, and whether the signatory had the intent to sign? A weak audit trail loses you the contract in dispute, not the signature itself. Evidence Act admissibility: Does the signature meet Singapore's Evidence Act section 92A or Malaysia's common-law standard for electronic signatures as primary evidence? Without this, opposing counsel demands the original wet-ink version—which doesn't exist. Most vendors publish a 'legal compliance' page. Almost none of them explain which of these three gates their platform actually passes—or what you need to do to make sure it survives cross-examination. Stamp duty: Where DocuSign, PandaDoc, and Adobe diverge Malaysia's Stamp Act requires contracts to carry a stamp based on their value and type. An e-signature doesn't change the duty calculation, but it does change where and when you can apply the stamp. Under the Stamp Act, you must stamp a contract before it's executed or within 14 days after. If your e-signature platform doesn't preserve a clear execution date—or if the timestamp can be altered or disputed—the Inland Revenue Board will classify it as unstamped and demand back-duty. DocuSign: Generates a certification report with notarized timestamps. The report explicitly states the contract type, signatory identity, and signature timestamp to the nearest second. Inland Revenue accepts this for duty classification, provided you print and retain the certification alongside the contract PDF. If you delete the certification report, you lose proof of execution date. PandaDoc: Embeds metadata in the PDF itself—no separate certification document. The metadata includes signature timestamp and signer IP address. However, metadata in a PDF can be altered with basic tools; Inland Revenue in practice requests a separate audit trail export. If PandaDoc's servers are unavailable, you cannot retrieve the export retroactively. Adobe Sign: Offers both embedded metadata and optional timestamping via Adobe's own timestamp authority. With timestamping enabled (a paid add-on), the signature becomes notarized —meaning it carries cryptographic proof of the exact moment it was placed. Without timestamping, Adobe Sign behaves like PandaDoc: metadata in the PDF, no guarantee of server-side retrieval after 30 days. For stamp duty compliance, the rule is simple: You must retain a third-party-verified timestamp or a vendor certification report. Metadata alone is insufficient for Inland Revenue if challenged. Of the three, DocuSign's approach (explicit certification) is most defensible; Adobe's timestamping is technically superior but requires an additional paid subscription; PandaDoc leaves you dependent on server-side logs you cannot guarantee will exist in five years. Audit trail: Metadata, server logs, and what survives deletion An audit trail is not a timestamp. It's a complete record of every action on the document: who opened it, when, from which IP, whether they printed it, whether they downloaded the PDF, when they signed, whether the signature was placed via mouse, stylus, or typed text, and what the signer saw on their screen at the moment of signing. Singapore's Evidence Act section 92A and Malaysia's common law both require that, if a signature is challenged, the opposing party can cross-examine the platform's record of signatory intent. A weak audit trail means the other side can credibly argue that the signer was confused, forced, or did not understand what they were signing. DocuSign: Retains audit logs on its own servers for 7 years (configurable for up to 10 years in enterprise contracts). The logs are encrypted and can be exported on demand. DocuSign also publishes a certified audit trail as a separate PDF document,