Standards, stated precisely
The value of an e-signature is entirely in what can be proven about it afterwards, so this page says exactly what the product does and does not give you.
What is applied
| Signature profile | PAdES — PDF Advanced Electronic Signatures, ETSI EN 319 142 |
| Container | PKCS#7 / CMS (RFC 5652), detached over the document byte range |
| Key & digest | RSA-3072 with SHA-256 |
| Coverage | The whole file, including the visible signature image |
| Key usage | digitalSignature + contentCommitment (non-repudiation) |
| Verifiable in | Adobe Acrobat/Reader, Apple Preview, any PAdES-aware validator |
What the demo does not give you
This demo signs with a self-signed certificate authority generated on the server. The signature is real and the tamper-evidence is real — but no public trust store knows that root, so a reader will show "signature validity unknown" rather than a green tick until the root is imported.
In eIDAS terms that is an advanced electronic signature, not a qualified one. A qualified signature requires a certificate from a qualified trust service provider on the EU Trusted List. Under South Africa's ECT Act 25 of 2002 it satisfies s13(1)–(2) as an ordinary electronic signature; it is not an "advanced electronic signature" as defined in s37, which requires accreditation by SAAA.
Where the law or a counterparty requires a qualified or s37-accredited signature, this demo is not sufficient, and we will say so rather than let you assume otherwise. Production plans include signing with an accredited credential.
How tamper-evidence is checked
The build refuses to ship unless an automated test signs a document, verifies it, then edits one line of the signed file and confirms verification fails. A claim that is never tested in its failing direction is not a claim.
Verify a file yourself
Open the signed PDF in Adobe Reader and look at the signature panel, or check the certificate of completion in your dashboard, which re-reads the signature out of the file rather than trusting our own log.