Skip to content
CogniYukti

Quote to cash

A typed name in a text box is not a signature. It is a rumour.

Most products in this bracket either resell somebody else's signing service or store the signer's name and call it done. The first makes the evidence somebody else's to explain. The second produces nothing anybody would rely on.

The test is simple: can a third party verify the document without trusting you?

Signing

Your workspace has its own key, and what gets signed is what the signer saw.

The key belongs to your workspace alone — not one key for every customer of ours — and the private half is encrypted where it rests. A leak, or a subpoena, reaches one workspace rather than everyone.

When somebody signs, the document is re-rendered with the signature block filled in, those exact bytes are signed, and those exact bytes are stored. Downloading the signed contract afterwards returns the stored file rather than rendering it again — so the thing in the file cabinet is the thing that was agreed to, byte for byte.

The words the signer agreed to are captured with the signature, naming the law they rely on, rather than merely being displayed on a page.

Certificate of completionMSA · Smoke & Co Logistics
Sent
2 Sep 2026, 14:02 UTC
Opened
2 Sep 2026, 17:41 UTC
Signed
3 Sep 2026, 09:16 UTC
Signed by
Anneke Smit · Operations Director
From
84.22.xxx.xxx · Firefox on macOS
Document hash
3f9a…c218
Workspace key
AC:41:9E:…:7B:20
Plus the exact words the signer agreed to, captured at the time. Anyone can check the document against that hash without an account and without asking you.
Illustrative
  • Opening the link is recorded, separately from signing

    So the certificate carries a real timeline — sent, opened, signed — rather than one timestamp.

  • Signing revokes every sibling link

    No second copy of the same contract can be signed afterwards.

  • The signer is emailed the signed document

    With the fingerprint in the message, so both sides hold the same artefact.

  • Only the hash of the link is stored

    The link itself is never kept, so a database reader cannot mint themselves a session on a pending contract.

Verification

Anyone can check it, and the check reveals nothing.

A public page takes the signed document. The reader's own browser hashes the file and sends only the digest — the document never leaves their machine. The answer comes back as authentic, or not.

The page shows the contract number, who signed, when, and which organisation issued it. Never the body, never the amounts, never anybody's email address.

And a mismatch returns one message. There is no hint about what nearly matched, because a hint tells a guesser they are getting warmer.

  • Every dead link fails identically

    Expired, revoked, already used, never existed — one response. Somebody trying links learns nothing from the difference.

  • The certificate names your key's fingerprint

    In the short form used for exactly this purpose, so a counterparty's security team can check it against the one you publish.

  • The verification page shows almost nothing

    Deliberately. Contract number, who signed, when, and which organisation issued it — never the body, the amounts, or an email address. A verification surface that discloses the contract has defeated itself.

  • An unknown reference fails exactly like a known one

    So the page cannot be used to discover which contract numbers exist.

Is this legally binding?

The consent text names the electronic-signature law it relies on and is captured with each signature, alongside the signer's identity, address, browser and the document's hash. Whether that satisfies a particular contract in a particular jurisdiction is a question for your counsel, not for a website — what we can say is what evidence is produced.

Do you use a third-party signing vendor?

No. Which is why the evidence bundle is ours to make good rather than whatever a reseller chooses to expose.

What if the document is edited after it is sent?

Signing captures the document as it stands at that moment and signs those exact bytes, so a signature always corresponds to a real rendering. The certificate's hash is what a verifier checks against.

Can a signed document be deleted?

It is stored as an immutable copy alongside the record. Voiding applies to contracts that have not been signed.