Understand what the evidence establishes.
Signitri combines identity checks, an audit record and a digital signature. Each provides different evidence. Certificate trust and long-term validation need their own checks.
Signed PDFs, with a timestamp when available.
The application reports B-T when timestamping succeeds and B-B when it does not. The current signing flow does not build the revocation evidence and archive timestamps required for a B-LTA output. We do not promise long-term validation after certificate expiry.
The signing certificate’s issuer, trust chain and validity affect the assurance of a signature. A self-signed development certificate does not establish a trusted signer identity. Production certificate trust must be verified before launch.
What to inspect in a signed file
Test the file with your verification tools.
The PDF contains the signature and its signing certificate. That permits inspection outside Signitri, but a valid cryptographic signature alone does not establish certificate trust, revocation status or legal effect. Those checks may require network access and external trust information.
We have not completed an independent Acrobat, Foxit or DSS interoperability assessment of the launch configuration. We do not guarantee offline validation or identical results across viewers. Ask for a representative completed file before relying on a particular viewer or assurance level.
Documents are processed on our servers.
Uploaded PDFs are stored in cloud object storage. The authorized signing function reads the stored PDF, applies the signer’s fields, prepares the signature and saves the completed revision. A separate service holding the signing key receives the signed attributes to sign.
This separation limits what the key service needs for normal operation. It is not a claim that documents stay in the browser, or that a compromised service cannot affect document security.
Identity providers
An explicit consent step precedes camera activation and identity processing. The consent record identifies the notice version, session and verification attempt. Automated checks can fail or require review; a pass does not guarantee identity or authority to sign.
Assurance work still to complete.
There is no SOC 2 report, ISO 27001 certification or independent review of the cryptographic implementation claimed here. We do not claim qualified electronic signatures.
The privacy notice, retention schedule and provider register remain drafts pending operating decisions and review. The audit trail records application events; it is not independently certified as immutable against privileged administrators. Retention and deletion across provider systems need to be verified before launch.
Privacy draft · Provider inventory ·Contact Signitri
Implementation review: 7 September 2026. This page does not certify the deployed environment.