Digital signing platform

Digital signing for every workflow.

Sign, seal, validate and timestamp with one platform: smart cards in the browser, remote certificates on iOS and Android, and your company seal in an HSM. E-invoicing included.

On-prem or hosted · Arabic and English · PAdES, CAdES, CMS

ETA-approved e-invoicing

ITIDA-licensed signing

ISO 27001 certified

On-prem, hosted or white-label

Works in Egypt, Saudi Arabia and the UAE

Every way people sign

Three signing channels. One engine.

Let people sign where they already are, and seal documents automatically when no person needs to be involved.

Browser + smart card

The Trpass desktop app connects approved websites to the user's USB token or smart card. The private key never leaves the token.

Phone + OTP

The iOS and Android SDKs sign PDFs with an ITIDA remote certificate, confirmed by a one-time password. No token needed.

Company seal (HSM)

Seal invoices and documents automatically with your organisation's key, held in a hardware security module.

Integration advisor

Describe your signing workflow. Get a recommendation.

Tell us who signs, what they sign and where. Our AI-powered advisor suggests the SignLayer channel and the documentation to start with.

Signing API

Everything a signing workflow needs.

The SignLayer Signing API is the engine behind every channel. One JSON API signs, validates and timestamps.

19
API operations
3
signing channels
3
signature formats: CMS, CAdES, PAdES
2
languages: Arabic and English

Sign

PDFs as PAdES, and any file or data as CAdES, CMS or a bare signature, with a token, a phone or a seal.

Validate

PDFs, Office files, CMS and CAdES signatures, and certificates, with revocation checks through OCSP and CRL.

Timestamp

Trusted RFC 3161 timestamps from your Timestamp Authority, for PDFs and any file.

Branded signature stamp

A visible signature on the PDF page with your logo, position and wording.

Per-customer trust

Separate trust lists, timestamp settings, HSM and branding for each customer, in one deployment.

Audit and usage

Every operation is logged per customer, with daily usage statistics for operators.

See all platform capabilities

ETA e-invoicing

From your ERP to the Tax Authority, sealed automatically.

SignLayer eInvoice turns your invoices into ETA's canonical format, seals them with your company key and submits them for you.

  • Canonical format tested against ETA's official test vector
  • Amounts are signed exactly as written, for example 10.50
  • Submit, fetch, cancel and reject documents from one API
  • Sign-only mode if you submit to ETA yourself
Book an e-invoicing demo
  1. Your ERP / accounting systemSends invoices as JSON
  2. SignLayer eInvoiceBuilds the ETA canonical form
  3. Company seal (HSM)Signs as CAdES; the key stays in hardware
  4. Egyptian Tax AuthorityReceives and validates the document

Architecture

Built as a small set of focused services.

Channels on the left, the SignLayer platform in the middle, trust services on the right. Private keys stay in tokens, in ITIDA's remote key store and in HSMs; the Signing API never holds them.

SignLayer platformSigning channelsSignLayer platformTrust servicesWeb app + Browser SDKDesktop app → smart cardMobile app + iOS/Android SDKITIDA remote key + OTPERP / accountingInvoices as JSONYour backendDirect API callsSigning APIIsolated PDF engineAudit log and sessionsPer-customer trust and configeInvoice ServiceHSM gatewayYour HSMPKCS#11Timestamp AuthorityRFC 3161Revocation servicesOCSP and CRLEgyptian Tax Authoritye-invoice APIsRuns on your servers or hosted by SignLayer

Explore the architecture

What is SignLayer?

One platform for every signature your organisation needs.

SignLayer lets people sign documents with a smart card in the browser or with a remote certificate on their phone, and seals documents automatically with your company key. One Signing API signs, validates and timestamps, on your own servers or hosted.

Benefits

Why teams choose SignLayer.

Legally recognised signatures

PAdES and CAdES signatures with ITIDA-licensed certificates, validated with OCSP and CRL checks.

Keys stay in hardware

Private keys never leave the user's token, the remote key store or your HSM.

Sign from anywhere

In the browser with a smart card, or on the phone with a one-time password.

Automatic sealing

Seal invoices, statements and letters with your organisation's key, with no one involved.

Your servers or hosted

Run SignLayer on-premises for full control, or use the hosted API.

Full audit trail

Every operation is logged per customer, with trusted timestamps.

Sample use cases

What you can sign.

  • Contracts
  • Consent forms
  • Invoices
  • Letters
  • Application forms
  • Statements
  • Tenders
  • Employment agreements

Sectors

Built for the way your industry signs.

Banks, fintech and telecom

Let customers sign contracts from their phone.

Add remote signing to your iOS and Android apps with ITIDA certificates and an OTP, and seal statements and letters automatically with your HSM.

  • iOS and Android SDKs
  • OTP by SMS or email
  • White-label under your brand
Book a demo

Government and public sector

Legally binding signatures for citizen services.

Run SignLayer on your own infrastructure. Citizens and staff sign with smart cards or remote certificates, and documents are sealed with the authority's key.

  • On-premises
  • ITIDA-licensed
  • Local CAs trusted by default, starting with Egypt
Talk to us about on-prem

Software vendors and integrators

Add signing to your product in days.

Use the public Signing API and SDKs for web, iOS and Android. Ship signing inside your ERP, portal or app, under your brand or ours.

  • Public API reference
  • Web, iOS and Android SDKs
  • White-label builds
Read the docs

E-invoicing companies

File ETA e-invoices without touching cryptography.

Connect your ERP or accounting system to SignLayer eInvoice. Invoices are converted to ETA's canonical format, sealed with your company key in an HSM and submitted for you.

  • ETA-approved
  • Sign-only or sign-and-submit
  • Up to 100 documents per call
Book an e-invoicing demo

Want to see SignLayer on your own documents?

Book a demo

How it works

Live in three steps.

  1. 1

    Connect

    Connect your web app, mobile app or ERP to the SignLayer API. Run it on your servers or use the hosted API.

  2. 2

    Choose a channel

    Smart card in the browser, remote certificate on the phone, or the company seal in your HSM.

  3. 3

    Sign, validate, archive

    Every operation is logged. Validate any signed document at any time.

For developers

A public API and SDKs for web, iOS and Android.

Sign and verify with plain HTTP calls. Use the browser SDK for smart-card signing and the iOS and Android SDKs for remote signing.

Read the docs
# Seal data with the company key (CAdES, detached)
curl -X POST https://signing.your-domain.com/sign/data \
  -H "Authorization: $SIGNLAYER_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{ "signer": { "type": "hsm" },
        "input":  { "data": "SGVsbG8gV29ybGQ=" },
        "output": { "format": "cades", "mode": "detached" } }'

# Verify it
curl -X POST https://signing.your-domain.com/verify \
  -H "Authorization: $SIGNLAYER_API_TOKEN" -d @verify.json

Security and compliance

Keys stay in hardware. You stay in control.

Keys never leave the device

User keys stay on the smart card or token. Seal keys stay inside the HSM.

Isolated PDF engine

PDF signing runs as a separate internal service behind an encrypted channel.

Runs on your servers

Single-file server builds that install on current and older enterprise Linux, inside your network.

Your trust list

Local root and intermediate CAs for each market, such as Egypt's, by default. Add or remove trusted CAs per customer.

Approvals and certifications

ETA

Approved for Egyptian Tax Authority e-invoicing

Licensed for electronic-signature services

Certified information-security management

Certificate names, numbers and scope to be confirmed before launch.

FAQ

Questions buyers ask us.

Which countries do you support?

SignLayer is used in Egypt, Saudi Arabia and the UAE. Tell us where you operate and we will confirm the certificates and trust services for your market in the demo.

Which certificates work with SignLayer?

Qualified certificates from licensed CAs on smart cards and USB tokens, remote certificates on the phone (for example ITIDA in Egypt), and your company seal certificate in an HSM.

Is e-invoicing supported?

Yes. SignLayer supports Egypt's ETA and Saudi Arabia's ZATCA. For ETA, SignLayer eInvoice builds the canonical document, seals it with your company key and submits it, and can fetch, cancel and reject documents.

Can we host it ourselves?

Yes. The services install on your own Ubuntu or RHEL-family Linux servers, x86-64 or arm64. A hosted API is also available.

Which documents can be signed?

PDFs (PAdES), any file or data (CAdES, CMS or a bare signature), and ETA e-invoices. You can also validate PDFs, Office files and signatures.

Does it work on iPhone and Android?

Yes. Remote-signing SDKs are available for both iOS and Android.

How is SignLayer sold?

As an on-premises licence per server, as a hosted API, or as a white-label build under your brand.

How much does it cost?

Pricing depends on channels, volumes and deployment. Book a demo and we will send a quote.

Book a demo

See SignLayer with your own documents.

Tell us what you need to sign. A solutions engineer replies within one working day.

  • 30-minute live demo
  • E-invoicing, browser, mobile or seal
  • On-prem and hosted options
What do you want to sign?

We reply within one business day.