Digital signatures and ETA e-invoicing

Digital signing, built for Egypt.

Sign, seal, validate and e-invoice with one platform: smart cards in the browser, remote certificates on iOS and Android, and your company seal in an HSM.

On-prem or hosted · Arabic and English · PAdES, CAdES, CMS

ETA-approved e-invoicing

ITIDA-licensed signing

ISO 27001 certified

On-prem, hosted or white-label

Trusted by organisations across Egypt

  • Customer logo
  • Customer logo
  • Customer logo
  • Customer logo
  • Customer logo

Partner apps built on SignLayer: NTRA FEDIS

Prototype: customer logos will be added once approved.

Every way people sign

Three signing channels. One engine.

Let people sign where they already are, and seal documents automatically when no person needs to be involved.

Browser + smart card

The Trpass / Tawqe3y desktop app connects approved websites to the user's USB token or smart card. The private key never leaves the token.

Phone + OTP

The iOS and Android SDKs sign PDFs with an ITIDA remote certificate, confirmed by a one-time password. No token needed.

Company seal (HSM)

Seal invoices and documents automatically with your organisation's key, held in a hardware security module.

Integration advisor

Describe your signing workflow. Get a recommendation.

Tell us who signs, what they sign and where. Our AI-powered advisor suggests the SignLayer channel and the documentation to start with.

ETA e-invoicing

From your ERP to the Tax Authority, sealed automatically.

SignLayer eInvoice turns your invoices into ETA's canonical format, seals them with your company key and submits them for you.

  • Canonical format tested against ETA's official test vector
  • Amounts are signed exactly as written, for example 10.50
  • Submit, fetch, cancel and reject documents from one API
  • Sign-only mode if you submit to ETA yourself
Book an e-invoicing demo
  1. Your ERP / accounting systemSends invoices as JSON
  2. SignLayer eInvoiceBuilds the ETA canonical form
  3. Company seal (HSM)Signs as CAdES; the key stays in hardware
  4. Egyptian Tax AuthorityReceives and validates the document

Signing API

Everything a signing workflow needs.

The SignLayer Signing API is the engine behind every channel. One JSON API signs, validates and timestamps.

19
API operations
3
signing channels
3
signature formats: CMS, CAdES, PAdES
2
languages: Arabic and English

Sign

PDFs as PAdES, and any file or data as CAdES, CMS or a bare signature, with a token, a phone or a seal.

Validate

PDFs, Office files, CMS and CAdES signatures, and certificates, with revocation checks through OCSP and CRL.

Timestamp

Trusted RFC 3161 timestamps from your Timestamp Authority, for PDFs and any file.

Branded signature stamp

A visible signature on the PDF page with your logo, position and wording.

Per-customer trust

Separate trust lists, timestamp settings, HSM and branding for each customer, in one deployment.

Audit and usage

Every operation is logged per customer, with daily usage statistics for operators.

See all platform capabilities

Architecture

Built as a small set of focused services.

Channels on the left, the SignLayer platform in the middle, trust services on the right. Private keys stay in tokens, in ITIDA's remote key store and in HSMs; the Signing API never holds them.

SignLayer platformSigning channelsSignLayer platformTrust servicesWeb app + Browser SDKDesktop app → smart cardMobile app + iOS/Android SDKITIDA remote key + OTPERP / accountingInvoices as JSONYour backendDirect API callsSigning APIIsolated PDF engineAudit log and sessionsPer-customer trust and configeInvoice ServiceHSM gatewayYour HSMPKCS#11Timestamp AuthorityRFC 3161Revocation servicesOCSP and CRLEgyptian Tax Authoritye-invoice APIsRuns on your servers or hosted by SignLayer

Explore the architecture

Solutions

Built for the way your industry signs.

File ETA e-invoices without touching cryptography.

Connect your ERP or accounting system to SignLayer eInvoice. Invoices are converted to ETA's canonical format, sealed with your company key in an HSM and submitted for you.

Book an e-invoicing demo
  • ETA-approved
  • Sign-only or sign-and-submit
  • Up to 100 documents per call

How it works

Live in three steps.

  1. 1

    Connect

    Connect your web app, mobile app or ERP to the SignLayer API. Run it on your servers or use the hosted API.

  2. 2

    Choose a channel

    Smart card in the browser, remote certificate on the phone, or the company seal in your HSM.

  3. 3

    Sign, validate, archive

    Every operation is logged. Validate any signed document at any time.

For developers

A public API and SDKs for web, iOS and Android.

Sign and verify with plain HTTP calls. Use the browser SDK for smart-card signing and the iOS and Android SDKs for remote signing.

Read the docs
# Seal data with the company key (CAdES, detached)
curl -X POST https://signing.your-domain.com/sign/data \
  -H "Authorization: $SIGNLAYER_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{ "signer": { "type": "hsm" },
        "input":  { "data": "SGVsbG8gV29ybGQ=" },
        "output": { "format": "cades", "mode": "detached" } }'

# Verify it
curl -X POST https://signing.your-domain.com/verify \
  -H "Authorization: $SIGNLAYER_API_TOKEN" -d @verify.json

Security and compliance

Keys stay in hardware. You stay in control.

Keys never leave the device

User keys stay on the smart card or token. Seal keys stay inside the HSM.

Isolated PDF engine

PDF signing runs as a separate internal service behind an encrypted channel.

Runs on your servers

Single-file server builds that install on current and older enterprise Linux, inside your network.

Your trust list

Egyptian root and intermediate CAs by default. Add or remove trusted CAs per customer.

Approvals and certifications

ETA

Approved for Egyptian Tax Authority e-invoicing

ITIDA

Licensed for electronic-signature services

ISO 27001

Certified information-security management

Certificate names, numbers and scope to be confirmed before launch.

FAQ

Questions buyers ask us.

Which certificates work with SignLayer?

Qualified certificates from licensed Egyptian CAs on smart cards and USB tokens, ITIDA remote certificates on the phone, and your company seal certificate in an HSM.

Is ETA e-invoicing supported?

Yes. SignLayer eInvoice builds the ETA canonical document, seals it with your company key and submits it. It can also fetch, cancel and reject documents.

Can we host it ourselves?

Yes. The services install on your own Ubuntu or RHEL-family Linux servers, x86-64 or arm64. A hosted API is also available.

Which documents can be signed?

PDFs (PAdES), any file or data (CAdES, CMS or a bare signature), and ETA e-invoices. You can also validate PDFs, Office files and signatures.

Does it work on iPhone and Android?

Yes. Remote-signing SDKs are available for both iOS and Android.

How is SignLayer sold?

As an on-premises licence per server, as a hosted API, or as a white-label build under your brand.

How much does it cost?

Pricing depends on channels, volumes and deployment. Book a demo and we will send a quote.

Book a demo

See SignLayer with your own documents.

Tell us what you need to sign. A solutions engineer replies within one working day.

  • 30-minute live demo
  • E-invoicing, browser, mobile or seal
  • On-prem and hosted options
What do you want to sign?

Prototype: submissions are not sent anywhere yet.