Sign Officially

Security

Exactly what we can see, and what we cannot.

Security claims are easy to make. This page explains how Sign Officially actually works, where your data goes, and how you can check it yourself.

On-device PDF tools

Merge, split, compress, rotate, organize, convert images, watermark, number, crop, edit, sign, fill forms, flatten, protect, unlock, redact, compare and repair all run inside your browser.

What happens

  • The page loads our code from signofficially.com, then your browser opens the file from your disk.
  • All processing uses pdf-lib, PDF.js and qpdf compiled to WebAssembly, running in this tab.
  • The result is saved straight to your device. The page makes no network request with your file.
  • Tool pages have no analytics, ads or third-party scripts. Our Content Security Policy only allows code from our own domain.

Check it yourself

  1. Open a tool, for example Merge PDF.
  2. Open your browser's developer tools and choose the Network tab.
  3. Add files and run the tool.
  4. You will see no upload. You can even turn off Wi-Fi after the page loads and the tool still works.

Server tools (Office conversions, OCR, PDF/A and the AI tools) are the exception, and are clearly marked. Those files are processed in an isolated folder and deleted within an hour.

Signature requests

Sending a document to other people needs a server, to email them and keep track. Here is what that server holds.

Standard mode

  • Your browser encrypts the PDF with a random AES-256-GCM key before upload.
  • We store that key encrypted with our server key (XSalsa20-Poly1305), separate from the files.
  • Signers unlock it only after opening their email link and entering a one-time code.
  • Signatures and filled fields are encrypted in the signer's browser too.

Private mode (end-to-end)

  • The document key is locked with a password only you and your signers know (PBKDF2-SHA256, 600,000 rounds).
  • That password never reaches our servers. We cannot open the document, and neither could anyone who broke into our servers.
  • Use a long password and share it by phone or message, not in the same email.
  • If everyone forgets the password, the document cannot be recovered. That is the price of real privacy.

What our servers can always see

To send emails and run the workflow we need: the document title and file name, the names and emails of people involved, where fields sit on the page, page count, file size, IP addresses and times of each step, and SHA-256 fingerprints. We never see the contents of a document in Private mode.

Proof that cannot be faked quietly.

Fingerprints

The SHA-256 fingerprint of the original is recorded when you send. Every signer's browser checks the document matches before they can sign.

Chained audit trail

Each event stores the fingerprint of the event before it. Changing or deleting any record breaks every record after it.

Digital signature (PAdES)

The final PDF is digitally signed with our certificate, inside the file, the way Adobe Reader and other PDF tools can check. Our server only ever signs a fingerprint, so it never sees your document.

Ed25519 seal

We also sign a public record of the final document. Our public key is published, and the verify page checks both the seal and the PDF signature in your browser.

Public keys: /.well-known/signofficially-seal.json. Signing certificate: Sign Officially Document Seal, SHA-256 4b0c452504d77546...

Accounts and infrastructure

  • Passwords are hashed with Argon2id and a secret pepper. We never store them in readable form.
  • Two-step verification with any authenticator app, plus recovery codes.
  • Sign in with WorkOfficially ID uses OpenID Connect with PKCE.
  • TLS everywhere with HSTS, a strict Content Security Policy, no third-party scripts, and session cookies that JavaScript cannot read.
  • Rate limits on sign-in, codes and sending, and account lockout after repeated failures.
  • Hosted in AWS us-east-1. Deleting a document removes its encrypted files and keys.

What we have not done yet

Honesty matters more than badges. Sign Officially is new. We have not completed a SOC 2 or ISO 27001 audit yet, and our signing certificate is currently our own rather than one issued by an Adobe-trusted authority, so PDF readers show the signature as valid but from an unknown issuer. Both are on the roadmap, along with an external penetration test and a public bug bounty.

Report a vulnerability

Email security@signofficially.com. We reply within two working days and will not take action against good-faith research. See security.txt.