Anyone can put a picture of a signature on a page
What decides a dispute two years later is whether you can still show what happened: who opened it, from where, what they accepted, in what order, and that not one byte has moved since. That record is the product.
· 4 min read

Drawing a signature onto a PDF is a weekend project. Every product in this market can do it, and the demo always looks the same: pick a document, drop a box, click sign, watch a nice animation.
Then two years pass and somebody disputes it. The question in that room is never whether the picture is pretty. It is whether you can show who was invited, when they opened it, how they proved who they were, what disclosure they accepted, in what order, and that the document has not changed since.
The ceremony, recorded as it happens
Rutba Sign records the ceremony while it occurs rather than assembling a report afterwards, and hash-chains it so events cannot be reordered or quietly thinned. Documents are pinned by hash on arrival and never rewritten.
That last point deserves unpacking, because it is where this differs from the obvious implementation. Marks and values are drawn on the pages of the uploaded PDF using the format’s own append-only mechanism. The original bytes never change. What makes the signature valid is the evidence record, not the picture — and the picture being an addition rather than an edit is what keeps the original checkable.
A certificate of completion that never claims more than was actually verified is worth more than one that claims everything.
Identity is a ladder you choose per signer
Not every agreement needs the same proof, and pretending otherwise produces either friction nobody needs or evidence nobody can rely on. The identity ladder is chosen per signer: email, a phone code, an access code, location.
The certificate then says what was actually done. If a signer proved nothing beyond clicking a link in an email, the certificate says that, in those terms. It is the least flattering design choice in the product and the one that makes the rest of it worth anything.
Your counterparty needs nothing from us
Signing is by link: the other party needs no Rutba account. And verification is public, permanent and free — a completed package can be checked without an account, without a subscription, and without trusting us, because the seal is checkable against a published key set.
Every act is countersigned by the platform the instant it happens, not only at completion. So a single party who signs and then waits three weeks for the others holds a receipt of their own act, countersigned, before the envelope seals.
And you still cannot buy it on its own
The three applications underneath carry their own labels. The composer and tracking are early access; the signing engine and the public Verify surface are available and running, with an RFC 3161 timestamp from a public authority and around 231 automated checks behind them, including both tamper directions.
Priced per envelope, not per seat
| Plan | Price | What it covers |
|---|---|---|
| Pay as you go | $0.90 per envelope | The complete workflow. No seat count, no monthly minimum. |
| Agreements | $59 / month | Signing plus the life of the agreement: 75 envelopes a month, 250 live agreements. |
| On your own licence | Part of your suite licence | Already running Rutba? It attaches like any other app. |
| Verification | Free, unlimited, forever | The public check. No account. |
Per envelope rather than per seat because the seat model charges you for the colleague who sends four contracts a year, and charges your client nothing for the one they sign. That is the wrong way round.
Check a document right now
The public verification surface needs no account and no key. It answers valid, tampered, or unknown.
Verify a document