A PAdES digital signature
The sealed PDF is signed to the European PAdES standard, the format PDF readers already know how to verify. Change one character and the seal breaks.
Electronic signatures, sealed
sigillumSign sends your documents for signature, confirms who is signing, and seals the finished PDF. Years from now, anyone can check who signed, when, and that nothing has changed since.
Who it is for
Leases, engagement letters, loan paperwork, offer letters, consent forms. When one of them is questioned, an email trail and a scribble are not much to stand on. sigillumSign gives every signed document a record you can hand over: what was signed, by whom, how they were identified, and when.
It works the same for a two-person firm and for a regulated one. Healthcare teams get a HIPAA-ready service on every plan; everyone gets the same evidence.
How it works
One pass from a PDF to a sealed record, started by your software or by your staff.
Your system sends a PDF, its fields and its recipients in one API call, or starts from a template your team already approved. You get an envelope back.
POST /api/v1/envelopes
Each signer gets a private, single-purpose link that expires on schedule, then confirms a one-time code sent by email or text. No account, no password, no app.
recipient.verified
The signer agrees to sign electronically before anything else happens, then reviews the document and signs in the browser on any phone or computer.
recipient.consent_given
The finished PDF is sealed with a digital signature, stamped with a trusted time, and returned with its certificate of completion. Your system hears about it through a signed webhook.
envelope.sealed
Evidence
Most signing tools treat the audit log as an appendix. sigillumSign is built the other way around. Every step, from the envelope being created to the identity check, the consent, each signature and the seal, is written once, in order, and never edited or deleted.
Every completed envelope comes back as two documents:
So when someone asks who signed this, when, and how do you know, you hand them a certificate instead of searching an inbox.
| Time | Event | Detail |
|---|---|---|
| 14:02:11Z | envelope.created | via API |
| 14:02:12Z | envelope.sent | 1 recipient |
| 14:29:31Z | recipient.otp_sent | |
| 14:29:47Z | recipient.verified | one-time code |
| 14:30:02Z | recipient.consent_given | disclosure v1 |
| 14:31:40Z | recipient.signed | page 4 |
| 14:32:08Z | envelope.sealed | Sealed |
The seal
A signature is only as good as your ability to prove it in five years. Each seal is made from open standards, so checking it never depends on us.
The sealed PDF is signed to the European PAdES standard, the format PDF readers already know how to verify. Change one character and the seal breaks.
An outside timestamp authority countersigns the moment of sealing under RFC 3161, so the time does not rest on our clock.
The certificate status and timestamp material needed to check the seal are embedded in the file and kept fresh, so it can still be verified years later, offline.
The sealing key was created inside a hardware security module in Azure Key Vault Premium and never leaves it. Our code only ever sends a fingerprint of the document to be signed.
Developers and staff
Everything sigillumSign does is an API call. Your system opens an envelope, your signer signs on their phone, and your system hears back through a webhook signed with a key you hold, so it can confirm the message came from us before acting on it.
When a person needs to take over, the portal puts envelopes, templates, delivery status and the audit trail in one place, with no engineer required. Use the API, the portal, or both.
# open an envelope from a template
POST /api/v1/envelopes
{ "template": "tmpl_engagement_letter",
"recipients": [{ "name": "…", "email": "…" }] }
201 { "id": "env_8kq2…", "status": "sent" }
# the signer verifies, consents, and signs
webhook envelope.sealed
sealed.pdf · certificate.pdf
signature verified
Security and compliance
Every plan gets the same protections. There is no premium tier for doing it properly.
Single-purpose links that expire, one-time codes by email or text, and signer sessions held in secure cookies, never in browser storage.
Agreement to sign electronically and the intent to sign are captured as steps in the signing, in line with the US ESIGN Act, rather than assumed.
Documents and signer details are encrypted in transit and at rest, access is controlled, and their contents are kept out of logs. Health information is handled as health information.
Audit events are append-only and sealed documents are kept in storage that cannot be overwritten. Evidence is added to, never edited.
Next step
A short walkthrough: prepare, verify, sign, seal, and the certificate at the end. Bring your most complicated packet, and your document volume, and we will walk you through pricing.