Why a passcode, and what it actually proves
The strongest identity check available is not the one that stops the most people signing. Choosing where to sit on that curve is the most consequential design decision in the product.
Every serious conversation about eFirma reaches the same point: how do you know it was them? And the honest answer is layered, so it is worth laying it out rather than reaching for the word “secure”.
What the check is
The sender addresses a document to a person at a specific channel — a phone number or an email address — before it goes anywhere. When that person opens the link, eFirma sends a one-time passcode to that same channel and will not open the signing page until it comes back. The code is short-lived, single-use, and rate-limited against guessing.
What that establishes, precisely: at the moment of signing, someone had control of a channel that the sender had already named as belonging to the counterparty. Not that they hold a particular national ID. Not that they are legally authorised to bind their employer. Control of a nominated channel, at a recorded moment.
Why that is worth more than it sounds
It sounds modest until you compare it with what it replaces. In an ink-and-scan process, a document is emailed to a company, someone prints it, a signature appears, and a scan comes back. Nothing in that chain establishes who held the pen, and the returning email address is often a shared inbox. The evidence is a picture.
The passcode check also has a quality courts like: it is contemporaneous and recorded by a third party. The sender chose the number in advance, the network delivered a code to it, and the code came back within minutes. That is a much harder story to walk away from than “that isn't my signature”.
The objections, taken seriously
SIM swap. A real risk, and the reason we do not describe SMS as strong identity. Two things reduce it: email and SMS can be required together for high-value documents, so an attacker needs both; and every check is recorded with its channel and time, so a swap performed around a signing date is discoverable rather than invisible.
A shared phone or a delegated assistant. Common, and not always improper — plenty of signing is legitimately delegated. What we can do is make the delegation visible: the record says which channel was used, so a signature made from the office manager's handset does not silently masquerade as the director's.
Message delivery. Ethiopian networks are not uniform, and a code that never arrives is a document that never gets signed. Codes go over both SMS and email where both are known, delivery is tracked, and a failed send is a visible state in the workspace rather than a silence the sender has to notice for themselves.
Where we draw the line
We could demand more. Selfie capture, document scanning, liveness checks — each raises assurance and each loses signers, particularly outside Addis, on older handsets, over patchy data.
An identity check nobody can complete is not a stronger signature. It is an unsigned document with a good excuse.
So the default is the passcode, the record says exactly what was checked, and organisations that need more can require both channels on the documents that warrant it. What we will not do is describe the default as more than it is. A signature is worth what its evidence is worth, and evidence that has been oversold is worth less than none.
Written by Saba Mekonnen, Co-founder & Chief Executive at eFirma. Corrections and arguments are welcome at [email protected].
