How it works
Only the hash and the signature cross the network
DuoKey signs the hash with the tenant's certificate and returns the signature. Each signing app is scoped and authenticated on its own, with its own bearer-token secret.
Your system
Sends a document hash
DuoKey PDF Sign
Signs with tenant certificate
Signed document
Signature returned
Only the hash and the signature cross the network. The certificate never leaves Cockpit.
- No client application to install, no certificate distributed to workstations
- Bearer-token authenticated, scoped per app: one connector secret per signing use
- Full audit trail of every signature, tied to a named app, not a shared endpoint
- Certificate lifecycle (issuance, renewal, rotation) managed centrally in Cockpit
Engagement
Stop shipping signing certificates to workstations
See PDF Sign deployed against your own document workflow, with the certificate held centrally and every signature traceable to a named app.
Request a demoSprechen Sie über die Entscheidungen, die für Ihr Sicherheitsprogramm zählen.
Sagen Sie uns, wo Kontrolle heute schwierig ist. Wir helfen Ihnen, den nächsten praktischen Schritt zu finden.