All writing
Security28 May 20266 min read

How the tamper-evident seal works, and what it is not

Vendors in this market have a habit of describing their seals in language borrowed from certificate authorities. Here is ours described in language borrowed from nobody.

Every completed eFirma document is sealed. That word carries weight, so it deserves a definition rather than an impression.

What happens at the moment of completion

When the last signer finishes, three things are recorded together, and it is the combination that does the work.

  • A fingerprint of the finished file. A SHA-256 hash over the exact bytes of the completed document, computed once and stored in the record.
  • The evidence of how it came to be. Every signer, the check each one passed, the channel it was sent to, and the moment each signature was made.
  • A closing entry in the trail, hashed together with every event before it, so that the history cannot be rewritten without the chain failing to recompute.

From then on the document is fixed in the sense that matters: not that it cannot be edited — anyone can edit a PDF — but that an edit cannot be hidden. Recompute the fingerprint of the file you were handed, compare it with the one in the sealed record, and the two either match or they do not.

Why the fingerprint is computed in your browser

On the verification page, the hash is computed on your own machine from the file you dropped in. The file is never uploaded and never stored. This is a deliberate design choice with a nice property: it means we cannot fake the answer for you, because the number you are comparing against our record was produced without us.

What it is not

Three claims we do not make, and which you should treat with suspicion when you see them made by anyone in this market.

It is not a certificate issued by a certification service provider. Ethiopian law contemplates a licensing regime for those. We are not licensed under it, and a seal we apply is not equivalent to an instrument issued by a provider that is.

It is not a PAdES or long-term-validation signature embedded in the PDF itself. Our record is held and verified by eFirma and by anyone holding the file, not by a validation chain baked into the document that a PDF reader will render a green tick for.

It is not proof of who a person is in the way a state-issued identity credential is. It is proof that a specific channel — a phone number, an email address — was in someone's control at the moment of signing, recorded so that it can be produced later.

Why this is still the right bar for most documents

The Proclamation's general rule asks for a method reliable for the purpose the document serves. For a supplier contract, an employment offer, a loan schedule, a policy sign-off or a consent form, an identity-checked electronic signature over a sealed, independently timestamped record with a replayable history is a strong answer — considerably stronger than the ink-and-scan process it replaces, which typically proves nothing at all about who held the pen.

Where a document genuinely needs a licensed certificate, the honest answer is that it needs one. We would rather say so than sell a seal as something it is not, because the first time that claim is tested is exactly the moment our customer is least able to afford it being wrong.

Written by Dawit Bekele, Co-founder & CTO at eFirma. Corrections and arguments are welcome at [email protected].

Read next

All writing
Security30 April 2026

Why a passcode, and what it actually proves

One-time passcodes over SMS and email are the most-questioned part of the signing flow. The questions are fair, and the answers are more interesting than “it's secure”.

Saba Mekonnen6 min read
Read

Try it on one real document.

The free plan sends five a month, sealed and verifiable, without a card. It is a faster way to judge any of this than reading about it.

No card needed