ParaSign · secure document workflow
Get an important document signed.
Sign it yourself, sign together or send it to others. Every signature comes with proof anyone can check.
- Free forever · 2 signatures a month, no card
Why your document stays safe
- Your signing key stays here · it is made on your device and never reaches our servers
- EU jurisdiction · servers in Germany, under EU law
You are not signed in. You can already prepare a document. To sign or send it, you need a free Community account.
- Document
- Place
- Co-signers
- Identity
- Sign
What you can do without an account
Why an account?
Your document goes nowhere. The file and your private key stay in this browser. Our server only sees a fingerprint of the file. You sign with a key that belongs to the passkey on your device, and that key first has to be tied to an account.
Open a signing request someone sent you. You then see which file it is and who has signed. The document itself only opens once you sign in with the address the invitation went to. No account yet? Create a free one on that address. Then the document opens and you sign. Checking a signed document works without an account too.
A Community account gives you 2 signatures a month. Initials on every page do not count separately. See what Firm adds.
How should it be signed?
You can still change this before sending.
Pick the document you want to sign
ParaSign signs PDF files. Pick a PDF and place your signature stamp on any page. The file stays in this browser.
Drop a file here, or click to choose
Stays in your browser. Nothing is uploaded yet.
Place your signature
Click anywhere on a page to drop the stamp. Click another spot to move it.
Click a page to drop the signature stamp.
This file is an image, so you can place your signature stamp only. The full editor (+ Text, + Date, highlights, notes and page management) works on PDF files: pick a PDF to use it.
Signature without a stamp
This kind of file cannot take a visible stamp. You sign a fingerprint of the file (SHA3-256). Recipients check the signature with the same file.
- File
- -
- Size
- -
- SHA3-256
- -
For this kind of file you sign only the fingerprint. There is no preview and no visual editing. The full PDF editor (+ Text, + Date, highlights, notes and page management) appears when you pick a PDF file.
Add co-signers (optional)
Add each person who needs to sign. Each invitation works only for the email address you enter here. The document travels along encrypted, so nobody needs a separate copy.
Who is signing?
Your name goes into the stamp (for PDFs) and into the proof file (.psign).
Your name will appear as text inside the stamp. Choose 'Draw' if you want a handwritten signature.
Draw with your mouse or finger. A steady line works best. Your line goes into the PDF as an image.
Your line appears here while you draw.
Upload a PNG or JPG of your signature. A transparent PNG works best.
Checking your signing key...
Your signature style is what people see. What really binds the signature is your signing key (ML-DSA-65). You unlock it when you sign: with your passkey (Face ID, Touch ID or a security key), or without a passkey with the code from your authenticator app. The key is never exported. Recipients you add sign at /co-sign with their own signing key.
Review and sign
This is what you are about to sign. Check the document, your signature and the details. When you click Sign this document, you confirm with your passkey (Face ID, Touch ID or a security key) or, if you have no passkey, with the code from your authenticator app. That unlocks your signing key for this one document, and the signature is created on your device.
Document preview: visual seal
This is how readers see the document, with the Paramant stamp on it. You can drag the stamp while placing it.
Your signature mark
Typed name, drawn line or uploaded image: this is what sits inside the seal.
Cryptographic proof (.psign envelope)
The stamp is what people see. This file is the real proof: anyone can check it offline with only your public key. The signature itself is produced when you click Sign this document.
- Algorithm
- ML-DSA-65 (FIPS 204, post-quantum)
- Hash algorithm
- SHA3-256
- Document SHA3-256
- -
- Signer key fingerprint
- -
- Envelope version
- -
Show envelope structure
- Document
- -
- Mode
- -
- Signer
- -
- Signature style
- -
- Signing key
- -
- Recipients
- -
A qualified trust service provider signs a hash of this document and returns a PAdES signature carrying its own certificate. The document itself never leaves this page. Sandbox only: this is a prototype against a test environment, not a production service.
Your document has not been uploaded and stays in this browser. After you sign in, the document and the spot are ready again.
Signed.
Your signature is on the document.
Signer not verified. This document was signed without an email invitation, so nothing ties a person to a slot. The proof shows that one specific key signed this exact document. It does not show who holds that key. For a signature bound to an invited email address, use Request signatures instead.
Their personal links
Each link opens the document after sign-in, and is for that one person only.
See where everyone stands on the status page for this request.
What made this safe
Your browser encrypted the document before any of it left this device. Each personal link carries that one person's key after the #. A browser never sends that part of a link to a server. What we hold is data we cannot read. The key stayed here too: the invitation email carries only a notice. So the mail provider cannot get into the document, and neither can we.
A link is bound to the address you gave it, so it opens for that signer and not for whoever else it is forwarded to. When they sign, the signature is made on their own device with a key of their own (ML-DSA-65) and recorded on our relay and in the public CT log, so you can show later that it happened and when.
Nobody has signed anything yet. This screen is the moment the requests went out.
What made this safe
The signature was made here, on this device, by a key that never left the browser and was unlocked by your face, your fingerprint or your security key at the moment you signed (ML-DSA-65, the signature scheme in FIPS 204). We hold the public half and the record of it. We never held the half that signs.
The proof file travels with the document and stands on its own. Anyone can check the pair without an account and without us: at paramant.app/verify, which recomputes the document's own digest (SHA3-256), checks the signature against the public key inside the envelope and, for a proof with several signers, checks our counter-signature against a fixed Paramant key built into the page. That arithmetic happens in your browser; the document goes nowhere. The paramant-sign script cannot check this proof: it only knows the old envelopes (v1 and v2) and asks the relay for those.
A green result there means three things at once: the bytes have not changed since you signed, the signature came from the holder of that key, and
- Document
- -
- Mode
- -
- Key fingerprint
- -
- Relay record
- -