Privacy-first e-signature
E-sign with no upload
“E-sign” should not be a synonym for “upload the PDF to a vendor.” FreeSign is built so the signature provider never receives the document — only a hash and the cryptographic ceremony. That is the privacy differentiator: no upload, no account, still a real Advanced Electronic Signature-style artefact.
What “no upload” actually means
Your browser computes SHA-256 of the PDF with WebCrypto. That hash — not the file — is what the Worker sees when it binds consent, issues a per-user certificate, fetches timestamps, and returns a CMS seal. The seal is merged locally as an incremental PDF update. If FreeSign’s servers were seized tomorrow, they would not contain your contracts.
No account is part of the same design
Accounts create document libraries. Document libraries contradict “we never held the PDF.” FreeSign authenticates each ceremony with an email OTP and binds that verified email into the certificate, then forgets the workflow the way a hash-only protocol should. There is no folder of past NDAs waiting on our side.
Proof that still stands up offline
- Verify in FreeSign’s verifier or with public tools (
openssl cms, pyHanko, Adobe Reader). - RFC 3161 + OpenTimestamps give time evidence independent of FreeSign’s uptime.
- Evidence JSON travels inside the signed PDF’s CMS.
Related reading: Sign a PDF without uploading, Verify with openssl, post-quantum co-signature.
Who this is for
Legal and security teams who need an e-sign path for sensitive PDFs; founders signing NDAs before a data room exists; anyone who has ever hesitated to drop a contract into a SaaS because the contents were the whole point of the confidentiality clause.
FAQ
Is there really no PDF upload?
Correct. Only a hash and ceremony metadata are sent. The document bytes stay in the browser.
How is this different from “encrypted upload” products?
Encrypted upload still means the vendor stores a copy (even if locked). FreeSign never receives the copy at all.
Do I need an account for no-upload signing?
No. Email OTP per ceremony replaces accounts and document vaults.
Can others verify without FreeSign?
Yes. The signed PDF is a standard PAdES-B-T file with embedded evidence; public verifiers work without calling our API.