Trust & Security
Signet keeps process evidence without becoming a long-term document custodian. During signing we hold encrypted packages (not the document code). After completion we seal, deliver a password-protected PDF, and purge content-bearing storage.
How a package is opened (accurate model)
A signing link alone does not decrypt the PDF. Opening needs both:
- Server-minted invitation link — authorises a short-lived signing session for one recipient (plus channel OTP as designed). Only our application can create a valid link; forged URLs fail hash checks.
- Document code — held by participants, used to unwrap the package key for that request and later as the open password on the completed PDF. We never store or email the code. Without it, stored ciphertext cannot be turned into a readable PDF.
Operators, admin tools, and account login cannot open your PDF. After purge, content is gone even if someone still has an old link or the code.
Ciphertext at rest
If an attacker downloads every unpurged blob from our data store, they get ciphertext and wrapped keys—not readable PDF content. Unwrapping requires the document code, which is not stored on the server. A stolen invitation from someone’s mailbox is a different threat: that link plus a leaked document code could open that one package while it is still active; it does not unlock other people’s packages.
Completed PDF: seal & public verify
When signing finishes, Signet seals the package with an ISO 32000 digital signature (CMS/PKCS#7) under Signet’s document seal certificate, then open-password protects the file with the document code. That is a real cryptographic seal on the file—not only visual ink stamps. It is not an eIDAS qualified signature (QES) or PAdES-LTV certification.
Public /verify opens your uploaded PDF in server memory with the document code and checks that the digital seal inside that file still matches the file bytes. It does not look up envelopes or package rows on our servers. We never store the PDF or the code. That proves package integrity and Signet’s seal—not government identity of each signer (party-owned identity: the document owner verifies who the people are).
Card payments (Airwallex)
Signet never collects, stores, or logs card numbers, expiry, or CVC. Card fields are rendered by Airwallex’s Card Element (provider-controlled iframes). Our servers create a PaymentIntent, verify payment status with Airwallex after the shopper pays, and record billing metadata (amount, currency, intent id, state)—not card data. Merchant API keys and PaymentIntent secrets are not exposed to the browser app UI.
Zero-Retention Model
Documents are stored only during the active signing window and purged after completion or expiry (zero-retention custody—not end-to-end zero-knowledge while signing is open). Admin tools expose metadata, hashes, health, and billing state—not document previews or signature drawings.
Invisible Security (email)
Email is treated as readable transport. While signing is in progress, invitations carry a signing link only—no unfinished PDF attachment, no document preview body, no document code. Share the document code through a channel you choose (call, chat, prior agreement).
When everyone has signed, Signet emails a normal password-protected PDF— not an unlocked file. Open it in tools people already know (Adobe Acrobat Reader, Apple Preview, or free PDF readers that support a password). When the reader asks for a password, use the document code. No special Signet app is required just to read the signed document.
Evidence Without Content
After purge, Signet may retain process metadata only—hashes, timestamps, consent actions, payment records, and purge status—not completed document content. Signed-in preparers may see title and signature progress on a dashboard; that is metadata, not recovery of the PDF. Public verification of a completed file relies on the file itself (see above), not on those retained rows.
Assurance tiers
| Tier | Current mechanism |
|---|---|
| Standard | Signing: email invitation link plus email OTP; document code for package unlock and completed PDF password. Account login may use optional email or SMS 2FA. |
| Enhanced | Stronger multi-channel signing factors planned (not default signing path today) |
| High assurance | Passkey/WebAuthn for accounts exists as an option; high-assurance signing path planned |
v1 Scope Limitations
Signet v1 does not claim QES certification, PAdES-LTV, SOC 2, ISO 27001, or trusted timestamp authority status. We do not prove legal personhood from an email or phone channel. Full legal text is on the Terms and Conditions page.
Need help?
Operators and EITS Support cannot open your PDF, recover a document code, or re-send a sealed package after delivery and purge. For account or product questions that do not require those recoveries, open a case with EITS Support.