Start free

Blog

AATL and non-AATL signing: what the difference actually is

AATL is a trust list inside Adobe Reader, not a legal standard. Here is what it does, what it does not do, and why most agreements never need it.

Two printed agreements side by side on a dark wooden desk, one with a small gold seal near its signature and one plain, a fountain pen lying between them, a curtained window behind.

People ask whether an e-signature is "AATL" as though it were a grade, and the question behind it is usually a different one: will this hold up? Those are not the same question, and conflating them costs people money in both directions — some buy a certificate they will never need, and some assume a certificate is what makes an agreement enforceable.

What AATL actually is

The Adobe Approved Trust List is a list of certificate authorities that Adobe ships inside Acrobat and Reader. If a PDF is signed with a certificate from one of those authorities, Adobe draws a blue bar at the top saying the signature is valid, and does it without the reader configuring anything.

That is the whole of it. It is a distribution mechanism for trust in one company's PDF reader. It is not a law, not a standard body, and not a statement by anybody about whether an agreement is enforceable.

There is a European analogue, the EU Trusted Lists, which underpins qualified electronic signatures under eIDAS. That one is attached to law: under eIDAS a qualified signature has a specific legal status in the EU. AATL does not have an American equivalent of that status, because American law took a different route entirely.

A close-up of a shield-shaped embossed seal pressed into thick cream paper on a dark wooden desk, a fountain pen and a brass magnifier beside it.

What American law asks for instead

The E-SIGN Act (federal, 2000) and the UETA (adopted in nearly every state) both take the same position: a signature is not denied legal effect merely because it is electronic. Neither of them specifies a technology. There is no list of approved algorithms, no accredited authority, and no certificate requirement anywhere in either statute.

What they ask for instead is about the circumstances of the signing:

  • the person intended to sign;
  • they consented to doing business electronically, and were told they could
  • ask for paper;
  • the signature is attributable to them, which is a question of evidence;
  • the signature is associated with the record it belongs to;
  • and the record is retained in a form that can be reproduced accurately.

Every one of those is a fact about what happened. A cryptographic seal proves the file was not altered afterwards, which matters, but it cannot by itself prove who signed or that they consented first. Which is why a signature taken on a phone with a full record of both, and then sealed, is more defensible than a sealed PDF with no record of who was at the keyboard.

So when does AATL matter?

It matters when a specific counterparty requires it, and that is the honest answer. The cases we see:

  • a government filing system that validates PDFs automatically and rejects
  • what it cannot chain to a trusted root;
  • a large enterprise procurement process whose policy names it;
  • cross-border work where a European counterparty wants a qualified signature
  • under eIDAS;
  • an internal audit function that has written "digitally signed certificate"
  • into a control and does not intend to reopen it.

Notice what those have in common: in each, a machine or a policy is doing the checking, not a court. AATL solves the machine-checking problem. It does not solve the "prove she signed it" problem, and the machine-checking problem is the rarer of the two for most businesses.

What it does not tell you

A certificate says a private key signed these bytes and that the key belongs to whoever the authority issued it to. It says nothing about:

  • who was holding the device. A certificate on a shared account signs
  • whatever anybody sends through it.
  • whether they read it. No certificate records that a document was
  • displayed, or for how long, or what it said at the moment it was signed.
  • whether they consented to sign electronically. That is a separate act
  • and E-SIGN wants it to precede the signature.
  • what the document said before. A certificate over a final PDF proves that
  • PDF is unaltered since signing. It cannot show what was on screen at the time
  • if the two were ever different.

That last one is the gap most people are surprised by, and it is where disputes actually live.

The practical answer

Ask the counterparty. If nobody is asking for AATL, you are choosing between "a document that validates in Adobe" and "a document you can defend", and the second is what a dispute turns on. If somebody is asking, get it — and understand you are satisfying their process, not improving your evidence.

You can also have both, and for high-value agreements that is the right answer. They are independent properties of the same document.

SignSealer is not a law firm and this is not legal advice. What is enforceable where you are is a question for your own counsel.


More writing · Who SignSealer is for

A hand holding a phone showing a document and a signature, outside a timber lakeside cabin, with two guests walking to the door with luggage.

Ready when the next guest is.

Free for the first 25 agreements a month. No card to start.