22 ms·
Show HN: OpenSign – Open source alternative to DocuSign
- yodon 3y agoMy understanding (possibly incorrect) is that competing with DocuSign is hard because of the need to follow obscure state and National laws (many of which are defined by case law rather than published law) in order for the signatures to be legally binding. Is that the case? And if so, is there evidence OpenSign has done this kind of SME research to make sure the electronic signatures are legally binding, or is this more "we brought in some devs and UI designers and built something" without actual legal review and guidance?
- wrs 3y agoDocuSign itself just refers you to your own counsel for legal advice, but does publish and update a handy multi-country legal reference. For the US one, at least, they give examples of where electronic signatures are pretty common and straightforward, and where you need to be careful. Software-wise, they have features to help you show evidence of who signed, where, and when in multiple ways. Nothing magical, though. If there were secret sauce, you would think they’d mention it prominently, but they don’t. https://www.docusign.com/products/electronic-signature/legality/united-states https://www.docusign.com/products/electronic-signature/legal...
- alexopensource 3y agoWe also generate a completion certificate that has the time & ip addresses of everyone who accessed and modified a doc during the entire signing process, plus we are open source which means more transparent. We plan to publish a lot of content in that space but with limited resources currently we plan to build the product features first. Also, we are soon going to start our fund raise efforts which will ultimately speed up things.
- szundi 3y agoAnd soon after suddenly the Pricing page appears, after 3 months of disappointment convenient features turn paying ones. In some more years it is just as expensive as Docusign. Eh sorry, I’m just sad about Rocket Chat.
- alexopensource 3y agoThe self hosted version will always be free :)
- josephcsible 3y agoYour CONTRIBUTING.md file says "By contributing, you agree that your contributions will be licensed under its MIT License." Since OpenSign is AGPLv3, why don't you allow contributions under the same license, if the self hosted version will always be free? I'm worried that the purpose of that might be to let you make it proprietary later.
- deleted 3y ago[deleted]
- tormeh 3y agoAGPL for thee but not for me, for I require MIT. To be fair, this is an entirely reasonable way to do business, but it's also a bit funny.
- anonymous_sorry 3y agoI guess this allows them integrate with proprietary code on their back end if necessary, whilst making it hard for a competitor to take their code and undercut them, since most corps with proprietary software to protect won't touch AGPLv3 with a barge pole. Nothing prevents an AGPLv3 fork if OpenSign goes proprietary in future. I'd rather this approach than yet another non-standard Amazon-proof licence.
- 3y ago
- alexopensource 3y agoThanks for asking the right question. We are taking legal help to be compliant with various jurisdictions. Our solution is currently able to safely sign a document with a digital signature that will make it tamper-proof and show a geen tick in Adobe PDF while keeping track of incremental annotations added by multiple signers. We envision to add support for eIDAS and AADHAAR e-sign(widely accepted in India) very soon.
- petertodd 3y ago> Our solution is currently able to safely sign a document with a digital signature that will make it tamper-proof Who holds the secret key that actually signs the document? If this is in fact a self-hosted, open-source, project then clearly the user does, and they could sign a different, tampered, version of the document after the fact. I would hesitate to use the term "tamper-proof" in that situation. Right now your documentation doesn't make it clear how this actually works. I'll also point out, that even if you were using my OpenTimestamps scheme or some other secure timestamping system, I would still hesitate to call the solution "tamper-proof". The problem is that even with timestamps someone can in many situations pre-generate alternate versions of a document in advance. Calling this type of system "tamper-resistant" is better IMO.
- alexopensource 3y agoIn the hosted version, we sign the document on behalf of the user using our own private key. Our roadmap also has the feature to bring your own cert(not relevant here). As soon as a user signs a document, a copy of the signed document is instantly sent to all the parties involved. This ensures that the signer cannot revoke the documents already signed. If the receiving party tries to modify the document, the signature becomes invalid. This is how we make sure that the docs are "tamper-proof" after signing.
- petertodd 3y agoThat's a reasonable, and pragmatic, way to implement this. But I'd still call it "tamper-resistant". One reason why is in situations where senders or recipients have modified something, proving that the _keys_ used to sign the documents were the correct ones can itself be a difficult problem.
- jjeaff 3y agoAre there really any laws requiring special types of signatures? Because I've never had a legal doc sent to me that they weren't fine with just stamping my signature on the line or even printing it out, signing it, and scanning it back in.
- alexopensource 3y agoIt depends on jurisdiction you are located in and the level of legal safety and acceptance you need. Our solution is already able to digitally sign the document which kind of makes it tamper proof and electronically sign(draw annotations) which will have you covered in most regions. Some regions have specific laws for example India has IT Act 2000, UETA & ESIGN Act while Europe has eIDAS.
- baz00 3y agoDepends where you are but contracts and other legal documents are only ultimately enforceable in court usually. Electronic signatures tend to shorten that process somewhat as they provide signatory verification, contract integrity and ID verification so it's seen as a legal risk and cost mitigation rather than an actual hard contractual requirement.
- p_l 3y agoEuropean Union (and some states connecting with the same infrastructure, like Switzerland), have standardized formats as well as defined CAs that provide certificates for "qualified" signatures, which have the same legal weight as if you had a printed document with physical signature. DocuSign supports those mainly through some interop connections where, for example, a qualified signature vendor provides an API that DocuSign can use to sign the document.
- alexopensource 3y agoYou are right, that is precisely the route we will also have to take for certain regions. For example in India, there are only 3 entities that are authorized by the government to enable Aadhaar based e-signature. We will have to integrate with any of those in order to be compliant. We have already started working in this direction.
- deleted 3y ago[deleted]
- candiddevmike 3y agoAFAIK DocuSign acts as a trusted third party and protects/prove chain of custody. Think of them like a digital notary public.
- alexopensource 3y agoOur understanding is that DocuSign does not have any legal authority, they prove the chain of custody/modifications using digital traces which our solution can also do, arguably in a more open way.
- toomuchtodo 3y agoElectronic signatures legally recognized in the United States are provided for in the Electronic Signatures in Global and National Commerce Act (“ESIGN”) and state and territory versions of the Uniform Electronic Transactions Act (“UETA”). These are the regulations you’ll want to adhere to in order to provide parity with digital signature authority of traditional commercial providers (in the US at least). Great work btw! (Not an attorney, not your attorney, but happy to chip in fiat so you can consult with counsel and obtain an opinion letter from one in support of your project)
- alexopensource 3y agoSaved the info in my notes. Will discuss it with our counsel in the next meeting. Thanks :)
- ncallaway 3y agoUETA has been substantially adopted by 49 states. The state of New York has their own statute. So, if you look at e-sign, UETA, and NY’s Electronic Signatures and Records Act, then you have fairly comprehensive coverage across the US. Also not an attorney, and this is also definitely not definitive legal advice!
- benatkin 3y agoYes, making a mill for supposedly trusted third parties, over having an actual trusted third party, is a more open way. Edit: I suppose in all except the free self hosted one, OpenSign would be the trusted third party, which I guess is more plausible. Unless the paid customers are given something close to root to administrate them. Still, a trusted third party is generally based on recognition. Even if I really dislike a company I eventually acknowledge they're trusted if it lasts long enough, like with ID.me. I didn't use ID.me until it was required for logging into the IRS and now I grudgingly admit that I think it's an extra security check on logging in. So until you're big like DocuSign I wouldn't view you in quite the same way as a trusted third party. That does bring a question, are your paid customers prevented from going under the hood in such a way that they would also have to be trusted at such a level along with OpenSign? -- This to say I'm open to using OpenSign, because there are plenty of uses where I would be open to using something that doesn't have this "trusted third party at the level of DocuSign" feature. The "digital notary public" analogy is apt. I sometimes sign documents with a notary, and other times without.
- figassis 3y agoWouldn’t it be amazing, since e signatures have been around for ages, that governments just published the requirements for legally binding digital signatures rather than ask each maker to go talk to them and get some obscure license or blessing?
- amolshejole 3y agoYeh, its already happening in a lot of regions across the world. We see a future that will have more open standards, it is precisely the reason we are working on this solution now.
- jeron 3y agoHow else will DocuSign have a moat??
- eKIK 3y agoIn the EU this is actually the case since 2016. There's this regulation called eIDAS (electronic IDentification, Authentication and trust Services). Article 26 (linked below) describes the requirements for an electronic signature to be legally binding. https://www.eid.as/#article26 https://www.eid.as/#article26 https://en.m.wikipedia.org/wiki/EIDAS https://en.m.wikipedia.org/wiki/EIDAS
- saled 3y agoYou know that there's nothing stopping an open source project funded as a not for profit from doing the same thing right? If something is hard, that's an argument for making a standard not for profit version of it, so it becomes a common good instead of platform rent seekers keeping out competition by saying it's "too hard".
- nonethewiser 3y agoHow do you personally differentiate between “rent seeking” and running a business?
- paulryanrogers 3y agoWhen it's 'done' and you keep collecting money, without adding additional value? Like a slumlord who collects rent and does nothing to even maintain the property. Except perhaps vote down YIMBY reforms.
- deleted 3y ago[deleted]
- kurthr 3y agoNot the OP, and this isn't something I'm dramatically invested in, but... Rent seeking would be designing a product for collecting rent (not a one time payment) for a product (e.g. SaS) that doesn't wear out or has separate maintenance costs. Like a house that is rented the value comes from the income stream and it likely is adjusted by something like inflation. Not renting would be selling a product for a one time fee, perhaps even if there are many customers (you still get to play ticket pricing games like the airlines so different people pay different amounts at different times, but not as variable as rent). Making the product non-transferable blurs the rent line a bit. Also not rental is the maintenance or improvement on the product (or the house) since that is new work that is being done. It used to be that only physical objects were rented and services were inherently work and required new effort/ingenuity to be solved each time. However, with the introduction of art reproduction (visual, audio, physical) and copyright/patent, as well as, non-perpetual licensing of software this is no longer the case. It's possible to hold a piece of intellectual property and collect perpetual rent with little or no future investment. It does create a different incentive structure that can be quite customer hostile.
- tiahura 3y agoYou are incorrect. I'm not familiar with any law that requires Docusign in any jurisdiction in which I practice. The Federal Esign Act provides: 15 USC 7006(5): The term “electronic signature” means an electronic sound, symbol, or process, attached to or logically associated with a contract or other record and executed or adopted by a person with the intent to sign the record.
- Sebguer 3y agoYou're misreading OP, they're not saying anything about law requiring Docusign, they're saying that Docusign has invested in meeting the law.
- SoftTalker 3y agoAFAIK, anything that is intended to be a signature, is a signature. This can be a hand-drawn "X", a signed name, a typed name, a fingerprint, a rubber stamp, clicking "I Agree" checkboxes, etc.
- kemitchell 3y agoI haven't researched the law here in a while, but my general impression the last time I did was that there isn't much in the way of legal requirements for signing things digitally beyond the federal ESIGN Act, general principles of state contract law, and the smattering of very particular kinds of transactions that require processes like notarization or recording. For everyday deals between the vast majority of people and companies, it really comes down to whether what the e-sign collects and saves will be available and convincing down the line, when there's a dispute. When dealing with government entities, you may run into policies of those entities that require use of a pre-approved service. For example: https://www.sos.ca.gov/administration/regulations/current-regulations/technology/digital-signatures/frequently-asked-questions#provider https://www.sos.ca.gov/administration/regulations/current-re... All that said, I have both implemented electronic signature in my own software and reliably recommended clients running sales ops just buy DocuSign. Familiarity and credibility can matter way more than legal or technical details...or not at all.
- Projectiboga 3y agoSupreme Court said you can agree to things online awhile ago.
- jacurtis 3y agoNothing in the American legal system is that straightforward and simple, even less so among our Supreme Court. Things got even more confusing now that this year the Supreme Court has set a new precedent that they can now overturn their own rulings from decades earlier. While I think that’s generally true that online signatures are acceptable in most circumstances, I’d be careful to blindly believe it as a blanket statement.
- vitus 3y ago> this year the Supreme Court has set a new precedent that they can now overturn their own rulings from decades earlier What happened this year specifically? Dobbs was in June 2022, but that isn't even close to the first time that the Supreme Court overturned precedent from 50+ years prior -- Brown v Board largely overturned Plessy v Ferguson ("separate but equal") from nearly 60 years prior. And, we've had plenty of Supreme Court precedents overruled since the 19th century. According to Congress: https://constitution.congress.gov/resources/decisions-overruled/ https://constitution.congress.gov/resources/decisions-overru... (Most of those never rose to the level of landmark decisions, but Plessy certainly did.)
- calvinmorrison 3y agoClose, the whole point of docusign is to avoid all of that by, one, paying docusign to solve those problems, and two because docusign is a "neutral" 3rd party who has good housekeeping records compared to "Opensign" where a self hosted sleazy hacker may decide he wants to fudge the datestamps on the signatures etc.
- thathndude 3y agoLawyer here. Not legal advice. Really not that much by way of law to consider. If everyone agrees that an E-signature is good, then, generally speaking, an e-signature is good. I’d suggest it’s more on the people actually drafting the documents being signed than the software layer facilitating.
- alexopensource 3y agoTrue. Even if one party from the signers dont trust e-sign, it wont work. But the number of people thinking an E-signature is good is only increasing day by day.
- menzoic 3y agoI think by everyone they meant everyone involved in the contract being signed
- ildon 3y agoLawyer here as well, but from Europe. Here the same is true, unless the government is involved. Documents from/to any agency, including anything that has any tax relevance, - generally speaking (there are many caveats) - shall be signed with services compliant with the e-signature standards provided by Regulation 2014/910/EU (in short: PADES, CADES, XADES). Out of curiosity: is there a similar requirement in terms of e-signature in the US when documents need to be sent to some agency, such as the IRS?
- graemep 3y agoNot a lawyer, but I know the position in the UK is pretty simple and much the same. The purpose of someone like Docusign is to provide a trusted third party to provide evidence. For most purposes GPG signed email (or anything else with a similar signature) would work perfectly well provided you could prove who the keys belong to. In fact it would be better than DOcusign who can (from the few documents I have signed) ultimately only really show they sent an email with a signing link to your email address. The last one from them has a warning: "Do Not Share This Email This e-mail contains a secure link to DocuSign. Please do not share this e-mail, link or access code with others."
- rubberband 3y agoYour overall understanding is correct. People pay DocuSign to "think" of everything for them (which is not at all bad, it just comes at a cost). Depending on the space, you have to deal with crazy laws that no one in their right mind would know about (nor think to even consider). Essentially, "no one ever got fired for signing with DocuSign" (play on IBM). I'm late to the party here, but if the authors want real world examples, please reach out.
- alexopensource 3y agoYou are right. But there are many Individuals/companies who cannot benefit from DocuSign's trust because of the price tag. We want to provide them the free/ open source option and during the process build a brand that is equally trusted if not more than DocuSign.
- cucho 3y agoNot OP, but would love to see those real world examples.
- fulafel 3y agoDepends on the jurisdiction and your definition of "hard" - in the EU there's some kind of qualification process by the regulators but the system is supposedly design to encourage competition and be open to new providers, and it's enough to be approved by one country's regulators I think.
- NoboruWataya 3y agoYou're getting a lot of responses to the effect that there aren't really any laws that require particular formalities to sign contracts, and while this is true in the "normal case" in many jurisdiction, there certainly are some categories of document that have more specific signing requirements. In most common law jurisdictions, for example, certain agreements must be signed as deeds which require certain formalities to be observed, and without enabling legislation it's not always easy to square these formalities with electronic signatures. https://en.wikipedia.org/wiki/Deed https://en.wikipedia.org/wiki/Deed
- tiansu_yu 3y agoNote that DocuSign does not automatically provide this as well in Europe. For example, in Germany, digital signature is not legal at all. So for every occasion, DocuSign is mainly used as a binding in a nonlegal way (for example, employee and employer agreed on paper that there will be a contract). But until both of you signed a physical copy, this is not legally binding at all.
- latchkey 3y agoIt is interesting to me how they (tm) on OpenSign, but don't do it in all their references to their competitors...
- wizzwizz4 3y agoThat's because they're staking a claim to a trademark. They're not staking a claim to the trademarks of their competitors.
- baz00 3y agoThis is naïve. DocuSign's main sell from a commercial perspective is it separates the parties into the signer, the signee and the authority. If the authority is the signee or the signer then it could be considered unfair. And really no one wants to end up having to hire lawyers to unfuck that mess. Not only that DocuSign does ID verification if you pay them which is required for a bunch of contract types. This does definitely not!
- alexopensource 3y agoWe are working on all these features, even an optional webcam capture during signing. This is just the beginning. Even with current features we are arguably the most complete solution in this space in open-source world.
- baz00 3y agoI appreciate what you're doing but we buy DocuSign so the problem is far far away from us. This turns it into a problem we have to manage ourselves or a problem of finding a vendor stable enough to host your stuff that will make it not our problem long enough for the longest contract retention to expire. Which is difficult.
- yborg 3y agoI'm sure these problems were also difficult for DocuSign in the beginning.
- baz00 3y agoNot really. They actually ran mock trials with legal professionals as test cases. That was an instant win for anyone wanting assurance of admissibility. No open source startup is going to win there because it's about entities and process, supported by technology not technology on its own. The technology is absolutely worthless without the framework and legal entities surrounding it. It's a unique position no one really understands that well.
- petertodd 3y ago> For comprehensive guidelines on how to use OpenSign, please consult our User Manual. FYI, USAGE.md seems to be missing. Also, a suggestion: while I agree with other posters that this isn't a replacement for the third-party trust model DocuSign provides, you might as well use my OpenTimestamps project to timestamp the documents OpenSign produces. Being able to prove that a document was in fact created in the past, before a dispute existed about the document, is significantly better than not being able to prove that. OpenTimestamps is free and open source, using Bitcoin so that you don't have a trusted third party. Timestamps made with OpenTimestamps are free, as merkle trees are used to allow the whole world's documents to be timestamped with a single Bitcoin transaction. https://opentimestamps.org/ https://opentimestamps.org/ A good example of how it's been used recently is by the official election authority in Guatemala to timestamp polling documents in their recent presidential election: https://www.youtube.com/watch?v=g0nnM5_Z90E https://www.youtube.com/watch?v=g0nnM5_Z90E
- alexopensource 3y agoThanks for the suggestion. We will definitely consider this. We have just released v1 48hrs before. We are working hard to put together a usage guide with docusaurus. You will see huge updates to documentation soon.
- Animats 3y agoIf you get something to sign, can you modify it and send it back to the other party so they can sign the modified version? Or is this a "take it or leave it" system?
- alexopensource 3y agoIts really important to preserve the integrity of the document during the signing process because of which modifications other than annotations are currently not allowed. We are building this to support an open architecture(micro frontend based add-ons). The two add-ons currently under development are - - A document organizer for signed/in-progress documents as we believe organizing legal documents is very different from organizing regular files as the user should be able to visually identify the status of the document and just hover on a document to see the current status of signers, etc. - An AI based assistant that will allow you to get any clause of a contract re-worded, explained, analysed for risks, etc.(we dont intend to replace lawyers here) Once we have these plugins ready. You will be able to create/modify docs before signing.
- Animats 3y agoIn other words, no.
- 29athrowaway 3y agoThis is similar to creating an open source nuclear waste management solution. Why would you want to store nuclear waste? Think about it. Even if you can, is that really what you want? Forever? There are probably more incentives and less legal liability storing nuclear waste than sensitive documents. It's not that other companies cannot do it, it's that nobody wants to do it.
- dboreham 3y agoNeutron star of risk.
- sirsinsalot 3y agoUntil my signing a contract means signing it and a checksum with my private key ... this whole space is flawed.
- zeta0134 3y agoWhy not make that your signature? Could you like, sign the current date with a private key, and write the result into the signature box?
- remram 3y agoThat only works if the other party is capable of verifying it. Also how do you tie people to keys? Have the government issue them?
- RedShift1 3y agoIn Belgium you can digitally sign documents with your e-ID (mandatory ID card issued by the government) and it has the same value as "classic" hand signed documents. I use it myself for everything, whenever I get a PDF I just sign it with my e-ID and send it along its way.
- johnfonesca 3y agoAt bulksign.com we have this feature, it's called "Local Certificate" signature.
- icelancer 3y agoI went to the installation instructions: https://github.com/OpenSignLabs/OpenSign/blob/main/INSTALLATION.md https://github.com/OpenSignLabs/OpenSign/blob/main/INSTALLAT... And it says you can auto-deploy to DigitalOcean (neat) and to a local server, and instructions are included for both. There's the bit on AWS S3 which makes sense but then no build/install instructions for local deployment. are those somewhere else?
- hardwaresofton 3y agoThe future of open source continues to be AGPL. [EDIT]: referring to (my own) article: https://vadosware.io/post/the-future-of-free-and-open-source-is-agpl/ https://vadosware.io/post/the-future-of-free-and-open-source...
- webmobdev 3y agoShouldn't be surprising as it is the only OSS license that protects your right to repair by guaranteeing source code availability. FSF doesn't get enough credit for their foresight.
- hardwaresofton 3y agoYeah, and a while ago there seemed to be people who didn't think it was F/OSS, and wanted to avoid it because it might reduce the likelihood of someone contributing. One thing I do think that people misunderstand is that a company can absolutely take your project and run it as a service -- they just have to contribute code back if/when they modify it. The real canary is requiring signed CLAs.
- webmobdev 3y agoTrue. Someone here in another comment has already pointed out that this project's CLA demands that all submissions have to be under the MIT license! This seems shady and can be perceived as an attempt to "steal" code in the future (MIT licensed code can be incorporated into xGPL license code, but it doesn't prevent the original license holder of the xGPL product to close source the product in the future. If the contributed code was also AGPL, the project managers would have to get permission from all submitters to close source a project or would be forced to remove their code from the product).
- hardwaresofton 3y agoI don't see that they have a CLA -- I can only find their note about the license contributors must take[0]. I guess that's one way around the CLA -- they don't need one if they force all contributions to be MIT in a file most people wouldn't read. In the end people the actual likelihood of someone making a credible legal threat is low so it all seems somewhat spurious but great way to go around the overt beacon that requiring CLA signing is. [0]: https://github.com/OpenSignLabs/OpenSign/blob/bb846442ecbaa34b480b445ac1e76b95233f5e78/CONTRIBUTING.md#license https://github.com/OpenSignLabs/OpenSign/blob/bb846442ecbaa3...
- j45 3y agoThis looks great. If there’s anyone familiar with this or from the product team would sincerely appreciate any insights on this scenario. Looking at the AGPL license, where would the licensing prevent or impact building an independent source code plug-in to integrate n to a piece of software that calls the hosted service via API, or an unmodified self-hosted copy? For me it helps spread awareness and use of a well made open source signature tool.
- alexopensource 3y agoCan you please clarify or provide more context regarding your question?
- gnarlouse 3y agoHow does something like this avoid IP theft/infringement cases? By all accounts it’s functionally the same thing as DocuSign? I ask because I am genuinely curious and hoping to learn a bit about IP law.
- jcoder 3y agoWhat kind of issue do you have in mind? By all accounts, the functionality or OpenOffice, LibreOffice, and Google’s suite are the same as Microsoft Office. There’s no theft unless they _actually stole intellectual property_
- hatsix 3y agoThe commenter is confused, they mean infringing, not theft. Theft is theft, no reason to get IP law involved. Infringement can happen without intent. I don't know who would be liable, the open source company with little revenue, or the customers who are just using the software.
- gnarlouse 3y agoThank you, yes I mean infringement. Say big Hooli company builds product/platform “A” and charges arm and foot for usage. Having tried the platform I personally find it ridiculous anybody is paying for this because I successfully (lone developer) hack together a trimmed down working clone of the core system *in under a week*. Furthermore, core aspects of Product/Platform “A” are open-source technology, in non trivial ways (like I’m not saying “oh they use YML for config files”, I’m saying “core engine component they’re using is explicitly open source”). If I decide to open source my clone, am I asking for trouble? This is all hypothetical, I’m not soliciting actual legal advice.
- xyst 3y agoVery cool. Thanks for sharing.
- coldtrait 3y agoI heard of this a while ago too - https://github.com/documenso/documenso https://github.com/documenso/documenso
- Helmut10001 3y agoI wish there was a free alternative to the German/Europe QES ("Qualified Signature"). The cheapest currently is about 20 EUR/ Month and allows you to make 3 Signatures. Others ask for 50 EUR for each QES. I hate to pay for my own Signature! We need something like Let's Encrypt for signatures.
- high_5 3y ago> We need something like Let's Encrypt for signatures. It's not the technical infrastructure, it's about trust. LE only solved the problem of safe transport, but not verification of authenticity of the endpoints. That's what incurs such cost.
- Helmut10001 3y agoThe endpoint (my ID) is free - it can be used to verify myself digitally. And that is what all QES services do, initially (once). What other costs if not hardware/bandwidth apply?
- grst 3y agoOther EU countries offer this for free, e.g. https://www.a-trust.at/pdfsign https://www.a-trust.at/pdfsign What's even worse is that in Germany most companies and authorities refuse to accept those digitally signed PDFs.
- Helmut10001 3y agoI wanted to come back here and add a thank you. I registered at a-trust through their EU-Identity Login and now I am able to sign 5 Signatures (QES) for free each month. Great!
- johnchristopher 3y ago> You will need to create an AWS S3 bucket or digital ocean space in order to store your uploaded documents The org I work for would love to self-host on-premise a digital signing solution so they definitely won't use external dependencies like AWS. Theoretically they could swap with minio but last time we used it it was not a drop-in replacement yet.
- alexopensource 3y agoWe will be supporting more storage providers including self hosting soon.
- johnchristopher 3y agoGood to hear ! It's not a problem if Minio is bundled into the self hosted stack as long as it's officially supported (paying for support is also okay).
- Clustered1441 3y agoThank you so much for your great work
- KronisLV 3y ago> Theoretically they could swap with minio but last time we used it it was not a drop-in replacement yet. Depends on whether AGPLv3 works for you or not (or whether you decide to pay them), I guess: https://min.io/pricing https://min.io/pricing I've actually been looking for more open alternatives, but haven't found much. Zenko CloudServer seemed to be somewhat promising, but doesn't seem to be managed very actively: https://github.com/scality/cloudserver/issues/4986 https://github.com/scality/cloudserver/issues/4986 (their Docker images on DockerHub were last updated 10 months ago, which is what the homepage links to; blog doesn't seem active since 2019, forums don't have much going on, despite some action on GitHub still) There was also Garage, but that one is also AGPLv3: https://garagehq.deuxfleurs.fr/ https://garagehq.deuxfleurs.fr/ The closest I got was discovering that SeaweedFS has an S3 compatible mode: https://github.com/seaweedfs/seaweedfs https://github.com/seaweedfs/seaweedfs
- ChrisCinelli 3y agoI suppose there is a need of a trusted 3rd entity that runs the service. Otherwise anybody could run the service and pretend that anybody else signed any documents they want at any time they wanted. I am not familiar with DocuSign internal but it looks like people are identified by their email. So only if you can click the link received in their email, it can be them. I guess a problem with DocuSign is still that anybody can sign up for a new email and pretend to be anybody they want.
- wscourge 3y agoThis is absolutely brilliant, thank you for creating it.
- upofadown 3y agoDoesn't contemporary PDF (for example) have something like a built in interpreter? How do you stop someone from, say, making a document that changes the wording after a certain date and then signing it?
- remram 3y agoI don't think PDF can do that.
- exhil 3y agoHow is this different from docuseal.co?
- pandemicsoul 3y agoIt's not – it's just a "competing" product.
- lpellegr 3y agoIt has "open" in the name! and an ugly UI :)
- alexopensource 3y agoWhat UI looks ugly to you? The website or the app itself or the github readme linked above? We would appreciate any precise feedback.
- lokesh1729 3y agoAs others pointed out, update documentation for self-host setup without the need of AWS. Since the project is open-source, update the documentation with local setup, architecture, design decisions made
- tz18 3y agoIs this different from https://opensignapp.com/ https://opensignapp.com/ ?
- Clustered1441 3y agoi think so
- tz18 3y agoI think it needs a way to review the contacts (other than the request signatures form), and to edit them (in case I put the wrong e-mail originally), or at least delete and re-create them.
- Peer_Rich 3y agohow is this different to Documenso.com? that looks more advanced