eSign · Digital Signatures

Sign the whole deal, once.

Bundle contracts, annexes, and declarations into a single PAdES-compliant signing request. Per-signer targeting, sequential or parallel routing, RFC 3161 timestamps, and a legally-defensible audit trail — signers complete everything in one session.

PAdES-B/T · RFC 3161 timestamps · Court-admissible

Employment pack · 3 docs SIGNATURE Date Name Initials SIGN HERE DATE FULL NAME Signers 3 AC Alex Chen[email protected] SIGNED DL Dana Lee[email protected] SIGNING… LG Legal Dept[email protected] QUEUED ROUTINGSEQUENTIAL TIMESTAMPRFC 3161 · TSA Send for signature
PAdES-B / PAdES-T VNPT SmartCA Viettel MySign NEAC / AATL anchors Client-side certs
Capabilities

Everything an enterprise signing workflow needs

Multi-document bundles, flexible routing, deep certificate support, and compliance semantics that hold up in court.

Multi-document signing

Bundle multiple PDFs, composed documents, or code-rendered templates into one request. Each document keeps independent pagination and field layouts under a shared audit trail.

PAdES-B / PAdES-T

Produce baseline PAdES-B or RFC 3161-timestamped PAdES-T signatures. Server-side signing with optional TSA and automatic fallback so a TSA outage never strands a request.

Sequential & parallel routing

Route one signer at a time, or fan out to everyone at once. Parallel mode uses PostgreSQL advisory locks to serialize concurrent submissions — race-condition-free, no leader election.

Four signing-key sources

Org-imported PKCS#12, an auto-provisioned internal CA, client-side USB tokens where the key never leaves the device, or remote HSM via VNPT SmartCA and Viettel MySign.

Three template sources

Upload PDFs, compose visually in the built-in editor, or import from DOCX. Spin up one-off quick-send bundles without a reusable template.

API, webhooks & verification

Org-scoped API keys, encrypted webhook events with retry, HMAC-secured public tokens, and a verification endpoint for chain-of-custody validation against trusted anchors.

Signer experience

One link. One session. Done.

Signers navigate every document in a single magic-link or embedded session, fill the fields meant for them, and submit once — no per-document ping-pong.

  • Document-level targeting — a signer is required on a document only where a field is placed; others see it reference-only.
  • Embed anywhere — drop the signing iframe into your onboarding flow with short-lived 15-minute session tokens.
  • Download everything — recipients get each signed PDF individually, or a single ZIP with every sealed document plus the audit trail.
  • Expiry & recovery — links expire after 14 days; an automated job retries failed finalizations so nothing gets stranded.
Contract Annex A Schedule
Sign here
tap to sign all 3
Cryptography & trust

Keys you control, trust you can prove

Signing is deterministic and auditable — there is no LLM anywhere on the signing path. Keys are protected at rest and, where you need it, never leave the signer's machine at all.

  • AES-256-GCM at rest — private keys are authenticated-encrypted with a 32-byte master key; plaintext never touches logs or backups.
  • Client-side signing — a cert-prepare / cert-complete handshake proves key possession without ever uploading it.
  • Bundled NEAC & AATL anchors — verify signed documents in-house without depending on external CRL/OCSP services.
  • HMAC-SHA256 tokens — magic-link, embed, and download tokens are hashed, never stored in plaintext; rotation invalidates every outstanding link.
PKCS#12 · org default
AES-256-GCM sealed
VNPT SmartCA · remote HSM
awaiting approval…
Verify · trust chain valid
NEAC anchor matched
Compliance by design

Legally defensible, all or nothing

All-or-nothing completion

If any document in a bundle can't be sealed, the whole request blocks. No partial packages, no leaked intermediate revisions.

Decline voids the request

When a signer declines, the entire request is voided — no signed document is released or downloadable, even if intermediate revisions existed.

Non-repudiation

PAdES signatures, RFC 3161 timestamps, and chain-of-custody validation give legal defensibility in Vietnam and internationally.

Sealed audit package

Every signing event — identity, timestamp, document version, fields modified — is logged and included in the downloadable package.

Use cases

Legally-binding signatures for every team

From HR to healthcare, collect defensible signatures wherever consent, approval, or agreement is required.

HR & People Ops

Offers & policy attestations

Offer letters and employment contracts, plus annual policy attestations where every employee signs the updated handbook — sent in bulk and tracked to completion.

Sales

Order forms & renewals

Order forms, quotes, and renewals signed by the customer and countersigned by finance — embed the signing step right inside your sales flow.

Banking & Lending

Loan agreements & KYC

Loan agreements, guarantees, and account-opening KYC — signed with VNPT SmartCA or Viettel MySign for full legal validity in Vietnam.

Insurance

Applications & settlements

Policy applications, beneficiary designations, and claims settlements routed to every party, each closed with a timestamped, non-repudiable audit package.

Healthcare

Patient & trial consent

Patient consent, telehealth consent, and clinical-trial informed consent — collected once per session with a sealed, non-repudiable record.

Real Estate & Field Ops

Leases & on-site sign-off

Leases, disclosures, and on-site work-order or quality sign-offs — routed sequentially or in parallel, downloadable as one signed package.

Close agreements without the paperwork drag.

Self-hosted, PAdES-compliant e-signatures with the certificate options your compliance team requires. See it on your documents.