DocuSeal – Open-source Document Signing
docuseal.co
docuseal.co
Some people are confused about what signing means. To me, there are three different types:
1. The ability to put a visual signature on a document. If you want this, just use MS Paint or similar tools.
2. Cryptographic signature, using Public Key Infrastructure (PKI), etc. This isn't really practical until we have widespread client certificates, or something like EIP-712 in mainstream usage.
3. Digital verification via audit data. This is where eSign platforms really provide their value. It's possible to view when a user opened a document and when they signed it, by logging sufficient audit data about their user client/browser. Think about the unique fingerprint provided by websites like https://coveryourtracks.eff.org/, etc.
Now, DocuSeal seems to only log opening and signature events, along with the user-agent and IP address. For many users, this may be sufficient data, but DocuSign includes a more unique fingerprint. With this data, it's possible to be more confident that a system was used to sign the document than with a wet ink document.
That said, some people also feel that the credibility of having this hosted by a third party adds value, as they are impartial.
Still, for my purposes, it's a great free project, so thank you.
It's very practical and used in certain jurisdictions, with very high rollout rate of personal certificates. Within EU regulatory framework it's also a thing and has legal meaning, then there is US government with their weird fixation on contact-only smartcards.
That being said, it's globally deployed with an "advanced", rather then "qualified" profile, where provider applies a signature with their own certificate (or ethemeral certificate issued to user on the spot) and embeds it into pdf as a field.
European Commission even has a library [0] in addition to the law for that.
It's kind of a mess, but nobody really cares until somebody tries to challenge validity of their own signature, which is very very rare. As a former industry insider I would say it's all a security theater and you can as well exchange emails to confirm existence of a contract. It's just more convenient to have a document with a signature as a single artifact, even if it's produced in ms pain as you rightly suggest.
[0] https://ec.europa.eu/digital-building-blocks/sites/display/D...
In Ukraine PKI finally found the problem it was solving, due to VAT return fraud and repudiation through courts.
In Lithuania and Estonia it's also widely used, but I'm not familiar with their landscape that much.
Except then you need to have people install those tools and know how to use them correctly. I think eSign platforms can still provide some value here in terms of usability even if that's not the core value proposition.
Anyway, if you just want to draw a signature on docs standalone with only local software and none of that other nice stuff, the good solution on a desktop OS isn’t mspaint, but Preview. Works directly on pdfs, can generate a fancy sig or let you draw your own, signatures re-usable and available in a drop down menu next time you need to sign something.
As a quick summary about us: we offer the basics of document signing for free like what DocuSign and the like would give you in their paid product (unlimited document sending, mobile signing, stripe integration) via open source/self-hosted or free tier cloud hosting.
We cover our business costs by having Enterprise focused features as paid offerings (API/Embedding, custom logo branding/domain, SSO/SAML etc).
Please feel free to ask any questions and we'll do our best to answer them today.
I don't mean to sound entitled, I always want to express gratitude to developers for contributing to open source. But I will say that I would never pay for proprietary features- not because I don't want to pay, but because I want open source features, and I am willing to pay for open source features.
Notable instances of this strategy include Slack with Mattermost, Tableau with Metabase, and Calendly with Cal.com.
Excellent work, team. I'm optimistic about the success of this approach
I currently use DocuSign, for my plan, it would be more expensive to use this
I really want a self hosted, self branded, embedded solution with API access. You have this, but it is only available in the most expensive Enterprise plan. I'm not an enterprise and there is no discount for self hosting
My plan, given the open core alternatives are missing the mark for me, is to use the Google Workspace solution included in what we already pay (https://workspaceupdates.googleblog.com/2023/08/esignature-g...)
I'm open to reconsidering if you offer the right features at an acceptable price. I'd prefer a fixed price for self hosted, rather than something based on users and docs sent counts
...thoughts from a potential customer...
It’s like naming your drink CocaKaka
https://www.uspto.gov/trademarks/search/likelihood-confusion
I'll add that i did do a double take here, so you have a point
Some lawyer friends I have (here in Australia) have told me that electronic signatures (of the kind like DocuSign and Adobe Sign that have you “adopt” a digital signature and click a “Sign” button) should only be used in situations where the other party’s actions soon after signing will confirm their intention to be bound by the document.
For example, if there is a sales contract and the buyer proceeds to pay the money, then that payment shows intent to follow the purchase agreement.
Or, if someone sends an email after signing saying “All done. I look forward to working with you.” — that has the same effect.
To use it for something where the other party will be doing nothing for a long time (like a guarantor on a loan or lease) or acting unpredictably (like a house tenant) would be very risky. The other party could easily use the defence of “I didn’t click the button… I didn’t even know about the contract.” even if they did know and did click the button.
So why use a digital signing system? Efficiency!
It’s quicker and easier. You can get dozens done with the same time & effort it takes to arrange a single wet signature. It’s multilingual. It’s automated. It’s fancy!
Having any signature, whether wet or digital, shows that your side is following proper process. The signing of a document is an important moment, and the specific date & time often has real commercial, accounting or legal ramifications. Even if you could easily show to a court that the other party has “agreed” without signing (e.g. via email, text, phone, etc) and is acting in accordance, it’s better to just avoid the court in the first place.
To summarise:
Wet signatures are best. The other party would be crazy to challenge them.
Digital signatures are better than just an email saying “I agree.” The other party would have to be brave to challenge one.
An email saying “I agree” is better than a handshake.
(Again, I’m not a lawyer! I would love to hear a lawyer’s opinion. Though, please do so anonymously — I don’t want anyone getting in trouble!)
There's some truth to what they're saying, but is it any different than a handwritten signature? "I didn't sign that. That's not my signature."
In both cases, from a legal perspective, the issue is the same: I've got to prove to a judge or jury, by a preponderance of the evidence, you did sign or click. I can either bring in paid whore handwritting analyst to testify that in their professional opinion, it is your signature (and hope he doesn't get excluded for being a quack), or I can subpoena docusign to produce whatever evidence they have that the person actually clicked. In the end, the judge or jury will either believe them or not.
If this is a billion dollar life or death deal, my free legal advice is, in either situation, get as much verification as you can at the time of the signing. Both will be easier to prove if you have things like a copy of their driver's license, or even better, video of the person clicking/signing.
People can always claim they didn't sign something, ink or digital. The reason that DocuSign is a multi billion $$ company is that they have a bunch of audit trail features which make it pretty darn clear the person did in fact sign it.
In the EU, often a personal key on a tamperproof personal device is used. In many EU countries these are readily available to citizens and the resulting signatures carry the signer's name, a unique personal ID code, and have the same legal effect as a handwritten signature. This is called a "qualified electronic signature". Qualified trust service providers verify the identities of people and provision the hardware to them.
The EU system is great in that when creating or verifying signatures, you don't necessarily need a service provider at all — the software is free. Of course a good system can help managing signature invitations, the documents, archival, reminders, etc. But it's not needed for security; in fact the most secure way would be to not give your documents to a third party at all.
Alternatively, the e-signing providers private key can be used to create a seal on behalf of the person signing. It's then up to the security of the e-signing provider, how they validate the signer's identity, etc, to decide how trustworthy such a signature is.
One subtle problem in this setup is the trust list. Abode effectively has their own trust bit sovereign rights, while EU has it's own trust list (which doesn't always match with a list of qualified providers as per EU-conforming states). Then US federal government has it's own trust list.
So it's the usual PKI problem.
In the end you can't modify (actually you can, because PDF, but it's a different problem) the data without breaking crypto signature, but identity that is proven by this operation is not government-endorsed. Everybody is mostly fine with a status quo.
For us, the biggest question that comes up for our customers is the variety of signature specimen we intend to work with and how it will be applied to the final documents (the ones the bank would take to court):
1. No signature captured at all.
2. Signature captured using adoption of a machine-generated specimen.
3. Signature captured using touch, mouse or stylus.
4. Signature captured using a paper specimen & CCD.
5. Actual wet signature on paper with in-person presence required.
Option 1 seems to be the most popular with the latest wave of online banking products. Option 3 is the happy path for our in-branch product, but we have some cases fall into the Option 5 bucket as well - typically only when all signers cannot be present simultaneously for non-consumer accounts.Depending on the liability associated with the customer/account combo, the required quality of the signature specimen could vary. Some of our customers will allow for basic consumer accounts to be opened with minimal backing documentation because the limits on those products are relatively low (and relative volume is VERY high). For business customers & accounts, we are in a completely different universe. You take that stuff a lot slower. Businesses are typically much more understanding when you say you can't give them an active account right now.
The most important foundation to all of this is Know Your Customer (KYC). That entire process is designed to ensure that whoever you are pulling into the core system is exactly who they say they are, so that all subsequent business with that individual can be correctly attributed to the appropriate natural person. Once you have a 'hardened' customer information file, you can start to do scary business because you are now reasonably-confident you could win in court.
I get that e-signatures were a compromise around 1990s but it's a bit absurd we are doing this today.
A handwritten signature has some decent built-in security. A copy-pasted picture of a signature is a bit silly.
Docuseal: Open-source DocuSign alternative - https://news.ycombinator.com/item?id=36798593 - July 2023 (196 comments)
You’re already paying them $15/m and Acrobat sign is pretty straightforward. What does docusign give you?
[1] https://helpx.adobe.com/acrobat/using/digital-ids.html
[2] https://helpx.adobe.com/acrobat/using/certificate-based-sign...