ParaSign · secure document workflow
Get an important document signed.
Sign it yourself, work together or send it to others. Your document stays private and every completed signature comes with independently verifiable proof.
- Free forever · 2 signatures a month, no card
- Your signing key stays here · it is made on your device and never reaches our servers
- EU jurisdiction · servers in Germany, under EU law
You are not signed in. You can prepare a document here; signing or sending it needs a free Community account.
- Document
- Place
- Co-signers
- Identity
- Sign
Signing a document needs an account
Not because the document goes anywhere. It does not: the file and your private key stay in this browser, and the relay only ever sees a hash. The account exists because a Paramant signature is made with a key that belongs to a passkey on your device, and that key has to be enrolled somewhere before it can sign.
What you can do without one: open a signing request someone sent you and sign it with the link from that email, and verify any signed document against the public log. Neither needs an account.
Community accounts sign 2 documents a month. See what the paid tiers add.
How should it be signed?
Choose a workflow. You can change it before sending.
Pick the document you want to sign
ParaSign signs PDF files. Pick a PDF and place your signature stamp on any page. The file stays in this browser.
Drop a file here, or click to choose
Stays in your browser. Nothing is uploaded yet.
Place your signature
Click anywhere on a page to drop the stamp. Click another spot to move it.
Click a page to drop the signature stamp.
This file is an image, so you can place your signature stamp only. The full editor (+ Text, + Date, highlights, notes and page management) works on PDF files: pick a PDF to use it.
Hash-only signature
This file type cannot be visually stamped. You will sign the SHA3-256 of the bytes; recipients verify by re-hashing the same file.
- File
- -
- Size
- -
- SHA3-256
- -
This file type is attested by hash: no preview, no visual editing. The full PDF editor (+ Text, + Date, highlights, notes and page management) appears when you pick a PDF file.
Add co-signers (optional)
Add each person who needs to sign. Their invitation is bound to the exact email address below. The encrypted document travels with the request, so nobody needs a separate copy of the file. The key that opens it is the one thing we do not email: you pass that on yourself, on the next screen.
Who is signing?
Your name is baked into the visible stamp (for PDFs) and into the .psign envelope.
Your name will appear as text inside the stamp. Choose 'Draw' if you want a handwritten signature.
Draw with mouse or finger. Use a steady stroke - the result is rendered as PNG and embedded in the PDF.
Your line appears here while you draw.
Upload a PNG or JPG of your signature. A transparent PNG works best.
Checking your signing key...
Your signature style is what people see. What cryptographically binds the signature is your signing key (ML-DSA-65) — unlocked with Face ID / Touch ID / a security key the moment you sign, and never exported. Recipients you add sign at /co-sign with their own signing key.
Review and sign
This is what you are about to sign. Check the document, your signature, and the metadata. When you click Sign this document, you confirm with Face ID / Touch ID / your security key — that unlocks your signing key for this one document and the signature is created locally.
Document preview - visual seal
The stamp on the document is the visible Paramant seal. Drag it during placement; this is what readers see.
Your signature mark
Typed name, drawn line, or uploaded image - this is what sits inside the seal.
Cryptographic proof (.psign envelope)
The visual seal is supporting evidence. This envelope is the mathematical proof anyone can verify offline using only your public key. The signature itself is produced when you click Sign this document.
- Algorithm
- ML-DSA-65 (FIPS 204, post-quantum)
- Hash algorithm
- SHA3-256
- Document SHA3-256
- -
- Signer key fingerprint
- -
- Envelope version
- -
Show envelope structure
- Document
- -
- Mode
- -
- Signer
- -
- Signature style
- -
- Signing key
- -
- Recipients
- -
A qualified trust service provider signs a hash of this document and returns a PAdES signature carrying its own certificate. The document itself never leaves this page. Sandbox only: this is a prototype against a test environment, not a production service.
Your document has not been uploaded and stays in this browser. Signing in reloads this page, so you pick the file again afterwards.
Signed.
Your signature is on the document.
Signer not verified. This document was signed in open mode, so no email invitation tied a person to a slot. The proof shows that a specific key signed this exact document, and that the key is the one recorded in the envelope. It does not show who holds that key. For a signature bound to an invited email address, use Request signatures instead.
Their personal links
One link per signer. The key is in the link.
See where everyone stands on the status page for this request.
What made this safe
The document was sealed in your browser before any of it left this device, and each personal link carries that one person's key after the #, which is the part of a link a browser never sends to a server. What sits on our side is bytes we have no way to read. The key stayed here too: the invitation email carries only a notice, so the mail provider that delivers it holds no way into the document and neither do we.
A link is bound to the address you gave it, so it opens for that signer and not for whoever else it is forwarded to. When they sign, the signature is made on their own device with a key of their own (ML-DSA-65) and recorded on our relay and in the public CT log, so you can show later that it happened and when.
Nobody has signed anything yet. This screen is the moment the requests went out.
What made this safe
The signature was made here, on this device, by a key that never left the browser and was unlocked by your face, your fingerprint or your security key at the moment you signed (ML-DSA-65, the signature scheme in FIPS 204). We hold the public half and the record of it. We never held the half that signs.
The proof file travels with the document and stands on its own. Anyone can check the pair without an account and without us: at paramant.app/verify, which recomputes the document's own digest (SHA3-256), checks the signature against the public key inside the envelope and, when the envelope was counter-signed, checks our signature against the public CT log. Or offline, with paramant-sign verify <file> <envelope.psign> from paramant-sign.
A green result there means three things at once: the bytes have not changed since you signed, the signature came from the holder of that key, and
- Document
- -
- Mode
- -
- Key fingerprint
- -
- Relay record
- -