Fingerprints
The SHA-256 fingerprint of the original is recorded when you send. Every signer's browser checks the document matches before they can sign.
Security
Security claims are easy to make. This page explains how Sign Officially actually works, where your data goes, and how you can check it yourself.
Merge, split, compress, rotate, organize, convert images, watermark, number, crop, edit, sign, fill forms, flatten, protect, unlock, redact, compare and repair all run inside your browser.
Server tools (Office conversions, OCR, PDF/A and the AI tools) are the exception, and are clearly marked. Those files are processed in an isolated folder and deleted within an hour.
Sending a document to other people needs a server, to email them and keep track. Here is what that server holds.
To send emails and run the workflow we need: the document title and file name, the names and emails of people involved, where fields sit on the page, page count, file size, IP addresses and times of each step, and SHA-256 fingerprints. We never see the contents of a document in Private mode.
The SHA-256 fingerprint of the original is recorded when you send. Every signer's browser checks the document matches before they can sign.
Each event stores the fingerprint of the event before it. Changing or deleting any record breaks every record after it.
The final PDF is digitally signed with our certificate, inside the file, the way Adobe Reader and other PDF tools can check. Our server only ever signs a fingerprint, so it never sees your document.
We also sign a public record of the final document. Our public key is published, and the verify page checks both the seal and the PDF signature in your browser.
Public keys: /.well-known/signofficially-seal.json. Signing certificate: Sign Officially Document Seal, SHA-256 4b0c452504d77546...
Honesty matters more than badges. Sign Officially is new. We have not completed a SOC 2 or ISO 27001 audit yet, and our signing certificate is currently our own rather than one issued by an Adobe-trusted authority, so PDF readers show the signature as valid but from an unknown issuer. Both are on the roadmap, along with an external penetration test and a public bug bounty.
Email security@signofficially.com. We reply within two working days and will not take action against good-faith research. See security.txt.