DuoKey

PDF Sign

Sign documents without the certificate ever leaving DuoKey

A server-side signing API hosted in Cockpit. No client to install, no certificate on workstations: your systems send a hash, DuoKey returns the signature.

Your system

Sends a document hash

DuoKey PDF Sign

Signs with tenant certificate

Signed document

Signature returned

Only the hash and the signature cross the network. The certificate never leaves Cockpit.

How it works

Only the hash and the signature cross the network

DuoKey signs the hash with the tenant's certificate and returns the signature. Each signing app is scoped and authenticated on its own, with its own bearer-token secret.

Your system

Sends a document hash

DuoKey PDF Sign

Signs with tenant certificate

Signed document

Signature returned

Only the hash and the signature cross the network. The certificate never leaves Cockpit.

  • No client application to install, no certificate distributed to workstations
  • Bearer-token authenticated, scoped per app: one connector secret per signing use
  • Full audit trail of every signature, tied to a named app, not a shared endpoint
  • Certificate lifecycle (issuance, renewal, rotation) managed centrally in Cockpit

Engagement

Stop shipping signing certificates to workstations

See PDF Sign deployed against your own document workflow, with the certificate held centrally and every signature traceable to a named app.

Request a demo

Parlons des décisions qui comptent pour votre programme de sécurité.

Dites-nous où le contrôle est difficile aujourd’hui. Nous vous aiderons à définir une prochaine étape concrète.