PRIVACY
Privacy
Your files never leave your device
Signet does not upload, store, read, or transmit your documents. When you sign or verify a file, its SHA-256 fingerprint is computed locally inside your browser. Only that fingerprint — a one-way mathematical digest from which the document cannot be reconstructed — is sent to the ledger.
What the ledger records
For each signature: the signer's name and company email, the file name, the file fingerprint, the declaration level and text, the project (if any), and the timestamp. For companies: role assignments, ledger visibility settings, monthly baselines, and project names. All of it is append-only and visible according to your company's visibility setting.
Who can see what
Company ledgers are grouped by email domain and visible only to signed-in members of that domain, subject to the roles your company configures. Individual certificates are viewable by anyone holding their unguessable link — that is deliberate, so recipients can verify what they receive. The public integrity page exposes only chain mathematics: hashes and counts, never names, file names, or company data.
Authentication
Sign-in uses one-time codes to your company email, handled by our authentication provider. Personal email providers are not accepted. We store no passwords.
Summary: fingerprints, not files; append-only records; company data stays within the company; proof is public only where proof is the point.