Login
Security & Trust

Signed. Sealed. Provable.

Every contract carries legally-attributable signatures and a cryptographic seal that reveals any change after the fact — not a promise, a proof.

All protections active
SHA-256 sealed TLS in transit & at rest Signing certificate E-SIGN · UETA · eIDAS

Don’t take our word

Watch the seal break in real time

When all parties sign, we hash the final document. Edit one character below and the hash — and the verdict — changes instantly.

Try it: tamper-evidence, live
Sealed hash

Current hash

Verified — the document is intact and matches its seal.

This is the real algorithm — SHA-256, computed in your browser right now.

Security posture

Active

Standards-based e-signatures

Executed under E-SIGN, UETA and eIDAS SES. Every signer gives explicit consent before signing.

Active

Signature evidence captured

Name, unique ID, timestamp, IP, device, method and consent — the set that makes a signature attributable.

Active

Certificate of completion

A standalone audit page with every party’s evidence and the document’s cryptographic seal.

Active

Tamper-evidence seal

A SHA-256 hash over the final content and every signature. Any change breaks it — as you just saw.

Active

Append-only audit trail

Creation, edits, AI actions, reviews, access and signatures — with immutable version snapshots.

Active

Encrypted on Google Cloud

Stored on Google Cloud / Firebase, encrypted in transit (TLS) and at rest, behind role-based rules.

How a signature becomes provable

1

Consent

Each party explicitly agrees to sign electronically.

2

Sign

Name, timestamp, IP, device and method are captured.

3

Seal

A SHA-256 hash is computed over content + signatures.

4

Verify

Anyone can re-check the seal and read the certificate.

Recognized legal frameworks

E-signatures on Coventract are executed to be valid across the GCC, wider MENA, the EU and the US.

🇶🇦 Qatar🇦🇪 UAE🇸🇦 Saudi Arabia🇪🇬 Egypt🇪🇺 eIDAS🇺🇸 E-SIGN · UETA
Read the full e-signature legality

Data processing & sub-processors

Core sub-processors are Google Cloud / Firebase (hosting, database, auth, storage) and Resend (transactional email). A Data Processing Agreement is available for business customers on request.

This page describes current platform capabilities and is not legal advice.