DuoKey

PDF Sign

Sign documents without the certificate ever leaving DuoKey

A server-side signing API hosted in Cockpit. No client to install, no certificate on workstations: your systems send a hash, DuoKey returns the signature.

Your system

Sends a document hash

DuoKey PDF Sign

Signs with tenant certificate

Signed document

Signature returned

Only the hash and the signature cross the network. The certificate never leaves Cockpit.

The problem

Document signing keys end up scattered across client machines

Local signing certificates are hard to govern and easy to lose track of.

When signing certificates live on individual workstations or file shares, there is no single answer to who can sign what, no clean audit trail, and no fast way to revoke a compromised endpoint without chasing down every machine that holds a copy.

  • Certificates on endpoints

    Every signing workstation is a place the key could leak from.

  • No central audit trail

    Local signing tools rarely log who signed what, or when.

  • Slow revocation

    Rotating a compromised signing key means touching every machine that has it.

  • Compliance evidence

    Auditors want proof of custody for the signing key, not just the signed PDF.

How it works

Only the hash and the signature cross the network

DuoKey signs the hash with the tenant's certificate and returns the signature. Each signing app is scoped and authenticated on its own, with its own bearer-token secret.

Your system

Sends a document hash

DuoKey PDF Sign

Signs with tenant certificate

Signed document

Signature returned

Only the hash and the signature cross the network. The certificate never leaves Cockpit.

  • No client application to install, no certificate distributed to workstations
  • Bearer-token authenticated, scoped per app: one connector secret per signing use
  • Full audit trail of every signature, tied to a named app, not a shared endpoint
  • Certificate lifecycle (issuance, renewal, rotation) managed centrally in Cockpit

Engagement

Stop shipping signing certificates to workstations

See PDF Sign deployed against your own document workflow, with the certificate held centrally and every signature traceable to a named app.

Request a demo

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.