Advanced Electronic Signatures

A signature is only as good as the proof behind it.

Kenal Sign turns a signature into evidence: a verified signer, a one-time code only they could use, and a cryptographic seal over the whole document that anyone can check, offline.

Built to the eIDAS Article 26 AES bar : jurisdiction-portable across Southeast Asia.

See it live: autentik.io is a complete consumer deployment of Kenal Sign, running this platform under one brand.

Perjanjian Sewa : Lease Agreement 3 pp / A4
Verified offline : no network to Kenal required
Seal
Ed25519 / SHA-256
Verification code
KS-BD74-DF7C-FF3C
Timestamp
RFC 3161 / 2026-08-04
Custody (this seal)
Zero : hash only

The difference

Most e-signatures are just a checkbox.

A tick and a typed name prove almost nothing when a document is challenged. Kenal Sign is built the other way around: the signature is the last step, and everything before it is evidence.

Ordinary e-signature

A record that you clicked.

An IP address, a timestamp, a checkbox. Nothing ties the click to a real, verified person, and nothing stops the document from being altered afterward. When it matters, the burden of proof falls back on you.

A Kenal Sign signature

Evidence that stands on its own.

Who signed is a verified identity. That they signed is a one-time code only they could receive. What they signed is a cryptographic seal over the entire document. Any relying party can check all three, without calling us.

How it works

Three proofs, bound into one seal.

Every Kenal Sign signature is built from the three things the eIDAS Article 26 standard asks an advanced signature to demonstrate, and records the proof of each.

01 / Identity

A verified signer, not an email address.

Signing opens on an identity confirmed through eKYC, so the signature is anchored to a real, checked person, not to whoever happened to hold a link.

who signed

02 / Sole control

A one-time code only they can use.

A single-use, time-limited code goes only to the channel bound to the verified identity, never one typed in at signing time. That linkage is what makes the signature genuinely theirs.

that they signed

03 / Seal

A cryptographic seal over the whole document.

An Ed25519 signature covers the entire manifest : document, signer, intent, the sole-control proof, and a trusted RFC 3161 timestamp. Change any bound field and the seal breaks.

what they signed

Why it holds up

Designed to be checked, not trusted.

The strength of a signature should not depend on the vendor still being around. Kenal Sign is built so the proof travels with the document.

Offline verification

Verifiable even if Kenal is gone.

Anyone can validate a sealed document against published cryptographic material alone. No login, no API call, no network path back to us. A verifier works fully offline, so acceptance never depends on our uptime.

✓ verified against Ed25519 public key

Zero-custody option

For sensitive documents, we hold only the fingerprint.

Attaching the document is the sender default. Choose zero custody on an envelope and Kenal Sign stores the document's SHA-256 and minimal metadata, never the file. Signers check that fingerprint against the copy you deliver yourself.

Tamper-evident trail

A hash-chained audit record.

Every event in a signing ceremony commits to the one before it. Insert, delete, or reorder anything and the chain no longer verifies : detectable by any relying party.

Jurisdiction-portable

One engine, many markets.

Signing profiles carry the rules of each market, Indonesia and Malaysia today, more on the same core, so the evidence package fits local law without a separate product.

For platforms and resellers

This is the product we sell, under your name.

Kenal Sign is white label to the core. Partners run the whole signing experience under their own brand and domain, provision their own customers, and never put us in a customer's line of sight.

  • Your brand, end to end. Logo, colour, language, and domain across the sender surface, the signing room, the console, and every notification.
  • Provision customers yourself. Create and configure downstream organisations from one console, each tenant isolated from the others, with no ticket to us.
  • Templates, bulk send, and an API. Reuse templates, send one document to many signers, and drive it all over REST with webhooks on the envelope, signer, and seal lifecycle.
J
Jaya eSign
sign.jaya.co.id
illustrative
M
Meterai Digital
sign.meterai.my
illustrative
one signing engine ↑

Autentik is a complete consumer deployment of Kenal Sign : everything on it is this platform wearing one brand. Jaya eSign and Meterai Digital are illustrative of what a partner deployment looks like, not live services.

The acceptance surface

One high bar that carries across borders.

Meeting the eIDAS Article 26 criteria also satisfies the UNCITRAL functional-equivalence model adopted across ASEAN and the Commonwealth, and the US ESIGN / UETA model. The same signature is accepted on the same evidence, market to market.

eIDAS Art. 26 (AES) UNCITRAL functional equivalence UU ITE : Indonesia US ESIGN / UETA Certified tier : optional

Request a briefing

Bring provable signatures to your platform.

Kenal Sign is onboarding partners and design customers across Southeast Asia. Tell us what your customers sign, and we will set you up.