Skip to content
E-Signature & Document Verification

SignSign collects Law 5070 e-signatures on contracts, using a Turkish ID card or a qualified certificate.

Law 5070 e-signing with a Turkish ID card or qualified certificate. RFC 3161 timestamps, PAdES-B-LTA archiving and shareable verification links.

Sign
organisations signing with Sign
89+
ready-made signing flows
5
PAdES long-term archive level
B-LTA
free contracts in the first month
20

Overview

Sign collects Law 5070 e-signatures on contracts, using a Turkish ID card or a qualified certificate.

Sign handles contracts and forms that used to need a wet signature electronically, under Turkish Electronic Signature Law No. 5070. Customers sign with their chip-enabled Turkish ID card (TCKK) and PIN, so they don't have to buy a certificate. Operators and authorised signatories use a qualified electronic certificate (NES).

Each signature gets an RFC 3161 timestamp, and the document is upgraded automatically to the PAdES-B-LTA long-term archive level. The certificate chain and the validity and revocation evidence are embedded in the file, so the signature can still be verified years after the certificates expire. The private key stays on the card. The server only prepares the document hash.

Ready-made flows cover single-customer standard contracts, doorstep signing in the field and multi-party corporate agreements. Internet service providers and other organisations, more than 89 in total, sign their subscription and contract paperwork on Sign. A REST API and webhooks connect it to your existing CRM and subscription systems.

RFC 3161
Developed / operated by
Sign Bilişim ve Sanayi A.Ş.
Website
sign.wi.tr
Category
E-Signature & Document Verification
Status
Live

Compliance & standards

  • 5070
  • ETSI PAdES (EN 319 142)
  • RFC 3161
  • KVKK
  • eIDAS (PAdES profilleri)
  • ISO 27001
  • ISO 9001

Sign

Key features

Sign with Turkish ID card

Customers sign with the chip on their ID card and a PIN, without buying a qualified certificate.

Qualified e-signature (NES)

Operators and authorised signatories sign with NES, and because the signature value is created on the card, the private key never reaches the server.

Timestamp & LTA

Every signature gets an RFC 3161 timestamp and the document moves up to PAdES-B-LTA automatically.

Multiple signers (Mode X)

Any number of signers sign in a fixed order, each with its own NES or TCKK requirement, and the next one gets a link, SMS or email automatically.

Verification link & QR code

Every signed document gets its own shareable verification page and a QR code for quick checks.

Open API & webhooks

REST API, Swagger documentation, a Postman collection and a webhook on every status change.

Capabilities

Signing flows

  • Standard flow: the customer signs with TCKK and the operator closes with NES
  • Field sales: several customers plus a field agent, signing at the door on tablet or phone
  • Full chain: customer and agent signatures are timestamped separately and the operator closes with TCKK or NES
  • Operator closing: corporate approval with no customer step, resealing an existing signed document to refresh its archive level (re-LTA)
  • Mode X: any number of signers, strict order, automatic timestamp and LTA
  • Custom signing chains for your workflow, built through the API

Key & data security

  • The private key stays on the card and the server only prepares the document hash
  • WYSIWYS: the PDF is frozen before signing, so preview and signature use the same bytes
  • Certificate chain, revocation evidence and archive timestamp are embedded in the document
  • Per-company data isolation with database row-level security (RLS)
  • Turkish ID numbers are stored masked and PINs are never logged at any layer
  • Data is hosted in Türkiye

Integration & delivery

  • REST API, Swagger (OpenAPI) and a Postman collection
  • Webhook notification on every status change
  • Automatic delivery of completed documents to Dropbox, Google Drive, FTP, SFTP or email
  • Free analysis tool for PDFs signed on other platforms
  • Plugin-free browser support: Chrome, Edge, Firefox, Safari, Opera
  • Works on Windows, macOS and Ubuntu

How it works

  1. 01

    Prepare the document and flow

    Send the contract from the portal or through the API. Set the signers, their order and whether each one signs with TCKK or NES.

  2. 02

    Signers sign

    The customer signs with ID card chip and PIN, and the operator with NES. The next signer is notified by link, SMS or email.

  3. 03

    The document is sealed

    Each signature is fixed with an RFC 3161 timestamp and the document is upgraded to the PAdES-B-LTA long-term archive level.

  4. 04

    Deliver and verify

    The signed document goes to your chosen destination automatically. Anyone can check it through the shareable link or QR code.

Integrations

  • REST API
  • Swagger (OpenAPI)
  • Postman
  • Webhook
  • Dropbox
  • Google Drive
  • FTP
  • SFTP
  • E-posta

Frequently asked questions

Do our customers need to buy an e-signature certificate?

No. Customers sign with their chip-enabled Turkish ID card and PIN. A qualified electronic certificate (NES) is only used where the flow calls for it, for example for operators and authorised signatories.

How can a signed document be verified years later?

The evidence needed to verify it is stored inside the file. At PAdES-B-LTA level the certificate chain, validity and revocation evidence and an archive timestamp are embedded, so the signature still checks out after the certificates expire. Each document also has a shareable verification link and QR code.

Is the private key sent to the server?

No. The server only prepares the document hash and the signature value is generated inside the card, so signing on the server is technically impossible. PINs are never logged at any layer.

Can we check PDFs signed on another platform?

Yes. Upload the PDF to the free document analysis tool to see whether its signatures, certificate chain and timestamps are valid.

Can we integrate Sign with our own software?

Yes. There is a REST API with Swagger (OpenAPI) documentation and a Postman collection, and a webhook fires on every status change. You can send documents for signing from your own panel and build custom signing chains through the API.

Is there a free trial?

Yes. New portal accounts get 20 free contracts for the first month. No installation or credit card is needed, and there is no obligation if you stop.

Have a project in mind?

Tell us briefly what you want to set up, or give us a call. We'll pass it to the right team.