The Notary Is a Security Boundary, Not a Rubber Stamp
· Christine Ali
People outside the notary industry sometimes have a wonderfully simple idea of what a notary does. Look at an ID. Watch somebody sign. Stamp paper. Done. That description is roughly equivalent to describing a firewall as a box with Ethernet cables plugged into it. Technically, yes. You’ve also missed the point. A notary occupies a very interesting place in a transaction because the notary is one of the places where a digital or administrative process collides with a physical human being.
A lender can have beautiful software. An escrow company can have excellent controls. Documents can be generated automatically. Status updates can move through APIs. Signatures can be routed electronically. Records can be stored in secure systems. Eventually, however, somebody has to answer a much more primitive question: Is the person standing here actually the person who is supposed to be doing this? That is a security boundary.

And I think we should treat it like one. This matters especially in real estate because the transaction has several characteristics that make fraud attractive: high dollar values, documents with enormous legal consequences, multiple organizations participating in the same transaction, and consumers who may only go through the process a handful of times in their lives. Complexity creates opportunity. The notary is not responsible for determining whether the transaction itself is wise, whether the contract is fair, or whether somebody should refinance their house.
That isn’t the job. But identity, willingness, presence, required formalities, and the integrity of the notarization absolutely matter. There is also something wonderfully unfashionable about this. Technology has spent decades trying to eliminate humans from processes. Sometimes we should. I have automated enough things in my career that I am certainly not going to argue against automation. But good system design isn’t about removing humans.
It’s about understanding where humans add information that the system cannot safely infer on its own. A notary can notice that something is wrong. An identification document can be examined in context. A signer can be physically present. Behavior that doesn’t match the expected situation can become visible. Records can be created showing what happened, when it happened, and who participated. That isn’t bureaucracy accidentally surviving digitization.
That’s defense in depth. The journal is another part of that security model. It creates an independent contemporaneous record of the act. In California, certain documents affecting real property, as well as powers of attorney, have specific thumbprint requirements. That is not something to casually expand into collecting biometric information everywhere, either. Good security controls have scope. More data is not automatically better security. The same principle applies to the entire transaction.
I don’t want software blindly trusting the notary. I don’t want the notary blindly trusting software. I want multiple independent controls that would have to fail before somebody can successfully impersonate a signer or corrupt a transaction. That’s how we design every other serious security system. Why would a house be different? This is also why I think the future of notarization is more interesting than “paper versus electronic.”

That’s the wrong argument. The real question is: Where does trust come from? If the answer is physical presence, we need to understand how that trust is established. If the answer is remote identity proofing, we need to understand that. If credentials are checked electronically, we need to understand the failure modes of those systems. If AI becomes capable of convincingly reproducing faces and voices, we need controls designed for a world in which seeing somebody on a screen is no longer particularly impressive evidence that they’re real.
The technology will change. The security problem doesn’t. At the end of the process, somebody is asserting that a particular human being appeared, was identified according to the applicable requirements, and performed a particular act. That assertion has value. So does the person making it. The notary isn’t the person who shows up at the end to stamp the paperwork. The notary is part of the security architecture.
We should design the rest of the system accordingly. For California’s specific journal requirements, see the California Secretary of State’s Notary Public Handbook. Requirements differ by jurisdiction.
For more information on secure notarization, and how technology can improve security and workflows, visit coverity.io
Discover more from Christine Alifrangis
Subscribe to get the latest posts sent to your email.
Leave a Reply