Let's Seal - Free open standard for document signing and verification
Show HN: Let's Seal – Let's Encrypt for document signing, free and self-hosted

Let's Seal is the open standard for proving any file is real and unaltered, acting as the 'Let's Encrypt' for document proof. This free, self-hosted solution uses the SEAL protocol to cryptographically verify file integrity, timestamp existence via Bitcoin, and confirm issuer identity. Supporting formats like PDF, images, and software artifacts, it offers a hosted web app, CLI tools, and APIs. Unlike paid notarization, it provides permanent, tamper-evident verification without vendor lock-in, ensuring authenticity is public infrastructure rather than a rental service.
Authenticity is infrastructure. It shouldn't be for rent.
- JCBird1012
In my opinion, all of these open source/free/open document signing tools are neat on paper (and technically fulfill the goal of being able to verify a document's chain-of-custody/signature provenance) - but won't take off in any meaningful way legally because there's no entity behind them taking the responsibility for accuracy and culpability.
DocuSign/Adobe/whomever is trust anchor, it's an entity you can sue or subpoena if something goes wrong. Someone who's actually on the hook for making sure whatever's signed is accurate and truthful (outside of the reputational risk of fraud completely obliterating any trust in your platform)...
No amount of cryptographic verification substitutes for having a legal person on the other end who can be held accountable for actually verifying the document was signed accurately/process was followed.
- vitally3643
You can't be the "Let's Encrypt of" anything if it's self-hosted. The entire point of Let's Encrypt is that there is a centralized reputable entity of note signing everyone's keys. Without that, it's entirely worthless. It's no better than a self-signed SSL cert or putting your own PGP key on a document manually. There's no point in a layer of abstraction atop that.
- qurren
Nice idea but with all related things the ultimate question remains whether courts will actually recognize it.
Currently courts will still consider paper-signed and scanned PDFs as legally binding, so any verification on top of that is superfluous to them.
More realistically, you take an oauth when you take the stand at the court, and if a signed document was altered by the counterparty you'd say so truthfully, if it weren't, you'd say so truthfully, and the penalty of that oauth purjury is high enough that most people wouldn't do it. Cryptography not needed.
- eps
Why not use RFC 3161?
Due to how the code signing works, timestamping servers are provided by all major CAs with full public access, e.g. timestamp.digicert.com, timestamp.comodoca.com, timestamp.sectigo.com, etc.
PS. OP, your comments are auto-killed for some reason. You may want to message mods to get this sorted.
- jkahrs595
Any benefits over DocuSeal?