For workspaces Aqili sets up, Seben adds a cryptographic signature to a document with the workspace’s certificate. Aqili prepares the signing key for the workspace, and a workspace owner then adds the certificate issued for it under Settings → Signing. To set this up for your workspace, write to [email protected].
Certificate signing keys are held in Azure Key Vault and never exported, and each workspace signs only with its own key.
This is different from the Draw signature tool, which places a picture of a signature and proves nothing about the file.
Checking signatures
Signing adds to the document rather than rewriting it, so signatures it already carries keep verifying in other PDF readers. File → Signatures… shows every signature the document carries, including ones it arrived with, and says for each whether it is intact, whether its certificate is trusted, and whether it covers the whole document or only an earlier revision. With a self-signed certificate, PDF readers report the signer’s identity as unverified.
Editing a signed document
Once a document carries signatures, Seben refuses every content change, even rotating a page, because any rewrite would leave the signatures unverifiable. To edit again, use Remove signatures in the banner at the top of the editor. That discards the signatures and is recorded as its own version.
In Ask mode, the default, the agent asks for your approval before it signs a document.