ESIGN & UETA Compliant
eIDAS-Aligned
Hash-Chained Audits

Enterprise-Grade Signatures. Startup-Friendly Pricing.

Start Free(No card required)
Assess Risk2-min Security Audit

See Your Savings

Stop paying for paper, printing, and manual delays. Calculate your savings.

Annual Savings
$28,200

projected annual savings by digitizing

Trees Saved
16.8trees / yr
Water Conserved
1.68Mliters / yr
500+
Integrated Teams
10M+
Hardened Documents
60%
Average Efficiency Gain
4.9/5
Peer Review Average
Forensic Resilience Protocol

Architected for
the "Worst Case".

We don't ask you to trust our policy. We ask you to verify our architecture. 18 critical failure vectors, neutralized by design.

Cryptographic Integrity

What if someone downloads a signed PDF, edits it, and claims the agreement was different?

The IUSign Protocol

SHA-256 PAdES Seal. Even a 1-bit alteration invalidates the embedded cryptographic signature, providing instant forensic proof of tampering.

Identity Governance

What if someone creates a fake iusign document and sends it to my client?

The IUSign Protocol

Organization Root CA. Every verified document is cryptographically bound to your tenant's specific identity, making unauthenticated clones impossible.

Security Engineering

What if someone intercepts our webhook and replays it with modified data?

The IUSign Protocol

HMAC-SHA256 Signed Idempotency. Every payload is signed with a rolling secret; replayed or modified packets are rejected by the gateway.

Fraud Prevention

What if an admin tries to alter or delete audit logs to hide fraud?

The IUSign Protocol

DB-Level Immutable Triggers. We use hardened Postgres triggers that physically prevent 'UPDATE' or 'DELETE' actions on audit records.

Legal Compliance

What if we’re under litigation and need to preserve a document indefinitely?

The IUSign Protocol

Indefinite Legal Hold. Suspends all auto-deletion policies and mandates permanent archival until the hold is manually revoked.

Data Sovereignty

What if we want to keep documents stored but destroy the encryption key?

The IUSign Protocol

KMS DEK Invalidation. We physically purge the unique Data Encryption Key (DEK) from the KMS, rendering the storage-at-rest mathematically void.

Recovery Protocol

What if we accidentally delete a document—can we recover it?

The IUSign Protocol

30-Day Forensic Soft-Lock. Deletion triggers a 'Tombstone' state, allowing recovery via 2FA verification before final cryptographic erasure.

Forensic Audit

What if a regulator asks us to prove deletion?

The IUSign Protocol

Verified Deletion Certificate. We issue a cryptographic tombstone signed by the KMS proving the key destruction event.

Access Control

What if someone signs from a shared device—can it be misused later?

The IUSign Protocol

Ephemeral Signing Tokens. Sessions are tied to a one-time cryptographic nonce that expires immediately upon document submission.

Temporal Accuracy

What if somebody changes document’s timestamp—how do we prove real time?

The IUSign Protocol

RFC 3161 Trusted Timestamping. Timestamps are sourced from an external TSA, independent of the server's local clock.

Compliance Logic

What if a user invokes GDPR deletion but it's legally required?

The IUSign Protocol

Regulatory Hold Reconciliation. Automatically prioritizes legal retention mandates over deletion requests to ensure compliance.

Tenant Isolation

What if two competing clients use iusign—how do you ensure zero leakage?

The IUSign Protocol

Row-Level Security (RLS). Hardened database policies ensure that Client A can never physically access Client B's data at the kernel level.

Key Management

What if our team uses the wrong API key—can data be accessed across tenants?

The IUSign Protocol

Strict UUID Key Binding. API keys are cryptographically locked to a single Tenant ID; cross-tenant calls trigger an immediate security alert.

Anti-Phishing

What if someone creates a lookalike domain (sign.c0mpany.com) to phish users?

The IUSign Protocol

Verified Sender Profiles. We enforce SPF/DKIM and DMARC hardening, ensuring invitations only originate from your verified corporate domain.

Infrastructure

What if your system goes down during a critical signing period?

The IUSign Protocol

Multi-Region Hot-Failover. Real-time data replication across three geographic zones ensures zero data loss and sub-second recovery.

Portability

What if we want to leave iusign—can we export everything?

The IUSign Protocol

Open-Standard Export. Export full forensic packages in machine-readable JSON with PAdES-LTV signatures. No vendor lock-in.

Leak Containment

What if an API key is leaked—can someone misuse it silently?

The IUSign Protocol

IP-Bound Whitelisting. API tokens can be restricted to specific IP ranges, rendering leaked keys useless outside your corporate network.

Bulk Ops

What if we send to 1000s and some fail—can we retry only failed ones?

The IUSign Protocol

Atomic Bulk Retries. Our task queue tracks every individual recipient state; 'Retry' only targets failed nodes, never duplicates successful ones.

Engineered to outperform.

Swipe to compare
Capability FrameworkIUSignEnterprise Market LeaderSuite-Based Provider
Bulk Send Pipeline
Built-in / Unlimited
NoLimited
Domain White-labeling
Standard / Native
Enterprise OnlyNo
API Ecosystem
Developer-First / Full
Restricted / TieredRestricted
Envelope Surcharge
Non-existent
Usage-based FeesUsage-based Fees
GCP KMS Key Control
Included / Native
UnavailableUnavailable
Cryptographic Provenance
SHA-256 Chaining
NoneNone
Audit Integrity
DB-Level Triggers
Policy-BasedLog-Only
Data Sovereignty
Crypto-Shredding
Storage-BasedManual Deletion
Memory Security
Zero-Persistence
Persistent TempDisk-Based
Hybrid Execution
Native Print & Sign
Manual / ComplexUnsupported
Signature Standards
PAdES-LTV Native
Optional / Add-onProprietary
Webhook Reliability
HMAC / Idempotent
Simple POSTNone
Forensic Audit Export
Self-Verifying JSON
Dashboard OnlyPDF-Only
Account Governance
Identity-Bound Roles
Shared PermissionsLimited
Multi-Party Routing
Sequential / Native
Limited / Add-onStandard

Current Feature Matrix Verification: April 2026

Core Ecosystem

Full Stack. Zero Bloat.

Visual Document Preparation

Drag-and-drop signature, text, date, and checkbox fields directly onto your PDF. Upload PDF or DOCX — automatic conversion via LibreOffice.

Sequential Multi-Party Signing

Define signing order: Person 1 → Person 2 → Person 3. Each signer receives the document only when it's their turn.

Immutable Audit Trail

Database-level triggers physically prevent deletion or modification of audit logs. SHA-256 hash chain per event.

Change Request & Revision Workflow

Signers click anywhere on the PDF to place comment pins. You resolve, upload a revised document, and re-send — all version-tracked.

Full White-Label Capability

Custom logo, brand colors, organization name, custom email from address, custom domain with DNS verification. Per-tenant usage limits enforced.

Smart Email Delivery

Redis-backed queue with exponential backoff retry. 4 Jinja2 email templates with custom composer and variable substitution.

Stuck Document Detection

Automatically detects documents inactive for 7+ days. Status filters, manual reminders, and blocker identification.

Security-First API

Cryptographically verifiable actions, SHA-256 event chaining, and PAdES-LTV validation. Idempotent webhooks with HMAC signatures for high-trust integrations.

Secure by Architecture

Infrastructure-Level Trust

AES-256-GCM GCP KMS Envelopes

Your document is encrypted with a unique data encryption key (DEK) before it ever touches disk. The DEK itself is wrapped with a master key controlled in your GCP KMS instance.

Deploy Control Key
IUSIGN_KERNEL_X64
// GCP KMS ENVELOPE HANDSHAKE
STATUS: ENCRYPTED
MASTER: kms:global:ias:key/01
DEK_HASH: sha256:5e8...3a2
// ACCESS LOGGED VIA CLOUD AUDIT ✓

SHA-256 Hash Chain Integrity

Every signature event — envelope created, document viewed, signature applied — is cryptographically chained. If a single record is altered, the entire chain triggers a violation.

Validate Integrity
IUSIGN_KERNEL_X64
// CRYPTO-CHAIN VERIFICATION
EVENT: SIG_LOG_09
SIGNED_BY: MICHAEL ROBERTS
HASH: 0x82f0be...a12b
PREV: VIEW_LOG_08
DOCUMENT_RENDERED
HASH: 0x41e9d4...d94c
INTEGRITY: MATHEMATICALLY VERIFIED ✓

Ephemeral Zero-Persistence Flow

Raw document content exists only in temporary memory buffers during processing. We physically collect garbage (GC) and overwrite memory sectors after encryption.

Simulate Breach
IUSIGN_KERNEL_X64
// ZERO-PERSISTENCE STREAM
... allocating ephemeral_buffer [0x00FF23]
input_stream = io.BytesIO(encrypted_blob)
transformer.flatten(input_stream)
! EMERGENCY WIPEOUT INITIATED !
overwrite_sectors(0x00FF23, pattern=0x00, passes=3)
SOVEREIGNTY PRESERVED ✓

Immutable PDF Flattening

Signatures aren't just invisible overlays; they are physically burned into the document's structure at 300 DPI, creating a permanent, flattened forensic record.

Verify Provenance
IUSIGN_KERNEL_X64
IUSIGN ARCHITECTURE VERIFICATION
PROCESS_ID: 97588
status = service.verify("pdf-render")
Result: SUCCESS -- ENFORCED

Universal Evidence Package

Export a self-contained, court-ready JSON bundle containing all metadata, signer IP logs, intent capture, and the full hash chain provenance.

Download Bundle
IUSIGN_KERNEL_X64
IUSIGN ARCHITECTURE VERIFICATION
PROCESS_ID: 72217
status = service.verify("evidence-json")
Result: SUCCESS -- ENFORCED

HMAC-Signed Idempotent Pipelines

Webhooks aren't just POST requests. They are HMAC-signed for security and support idempotent retry logic to ensure your backend stays in perfect sync.

Test Endpoint
IUSIGN_KERNEL_X64
IUSIGN ARCHITECTURE VERIFICATION
PROCESS_ID: 82605
status = service.verify("webhook-flow")
Result: SUCCESS -- ENFORCED

Scale bulk sends without jobs failing.

Distributed task queue + surgical retry. Failed recipients auto-retry without resending completed ones. Idempotent webhooks guarantee no duplicates.

Verify System Integrity

Common Queries

Everything you need to know.

Is IUSign legally binding?

Yes. IUSign is fully compliant with the ESIGN Act and UETA in the US, and aligns with eIDAS standards in the EU. We capture intent to sign, mandatory consent, and provide an immutable SHA-256 audit trail for every transaction.

How does the 'Zero-Persistence' security work?

Unlike traditional platforms, IUSign processes sensitive document data in ephemeral memory. Once the PDF is flattened and encrypted, the raw data is physically overwritten in memory, ensuring your document content is never stored in an unencrypted state.

Can I use my own domain for signing?

Absolutely. Our Growth plan includes full white-labeling, allowing you to use your own domain (e.g., sign.yourcompany.com) with automated SSL, custom email branding, and localized signing experiences.

What is an Immutable Audit Trail?

Every event in the signing process is cryptographically hashed and chained to the previous event. This creates a forensic record that cannot be altered without detection, ensuring absolute cryptographic certainty in a court of law.

Does IUSign have a developer API?

Yes. We pride ourselves on being developer-first. We offer 39 documented REST endpoints, Python and Node.js SDKs, HMAC-signed webhooks, and a sub-15 minute integration time for most applications.

Take control of your document logistics.

Self-hosted ephemeral security, immutable audit trails, and 100% data sovereignty starts here.

Start Free(No credit card required)