CRYPTOGRAPHY • PKI • PUBLIC VERIFICATION
Cryptography, not compliance theater.
Full 3-tier X.509 you control. SHA-256 hash chain. Public verifier (no login). Native Adobe. Biometrics + AES. Free self-host open source lacks this depth; commercial for audit-critical teams.
YOUR PKI. YOUR CHAIN. ROTATABLE.
3-tier X.509 hierarchy (Root → Intermediate → Signer)
Tap/hover/keyboard (Tab + Space/Enter) on tiers. You generate + rotate. Adobe Reader trusts your root when installed or via AATL-equivalent for internal use.
NATIVE ADOBE READER VERIFICATION
Step through exactly what an auditor or counterparty sees
Open signed PDF in Adobe Reader
Uses ByteRange stabilization + pkijs CMS + embedded RFC3161 TSA. LTV enabled. Matches the documented signature creation and validation paths in the platform.
Hash-chained audit trail
Every event (CREATE, SENT, VIEWED, SIGNATURE_APPLIED, APPROVED...) appends a SHA-256(prevHash + payload). Constant-time verification. Full reconstruction on demand for disputes or regulators.
See live tamper demo on homepage. Real impl in the platform's hash-chained audit implementation.
Try the chain simulator →Biometric signatures + at-rest encryption
Pressure + velocity arrays captured during draw. Cryptographic hash of stroke stored. Saved signatures AES-256-GCM encrypted per-user. Stronger intent proof than static images or typed names.
Biometric capture and per-user encrypted signature storage (documented in security specs).
PUBLIC VERIFICATION — NO LOGIN, ANYONE
Regulators and counterparties verify independently via QR or /verify/[id]
The same page and API can inspect certificate IDs produced by the deployed FlySign instance. Availability and assurance depend on that deployment.
Self-hosting can keep keys, database, and objects in operator-selected infrastructure when configured as documented. Contractual terms such as a BAA require separate written confirmation and are not implied by this page.