ML-DSA-44 · FIPS 204

The signature you make today has an expiry date.

Electronic signatures today rest on RSA and ECDSA. A large enough quantum computer breaks both — and the contract you are signing may need to hold up for longer than that takes. We sign with ML-DSA-44, the NIST post-quantum standard.

The problem is not speed. It is time.

A lease runs five years, a title deed a lifetime, a patent twenty. A signature has to prove itself not on the day it is made but on the day it is disputed. Today's signature has to survive until then.

Today

RSA-2048 and ECDSA are everywhere, fast, and secure right now.

Later

A quantum computer running Shor's algorithm breaks both. When is unknown. That it happens is not.

The answer

Lattice-based signatures. ML-DSA-44 rests on a hardness no known quantum algorithm defeats.

How signing works

You do not name the signatories in advance. The document carries a code; whoever reads it signs, and you decide what to accept.

  1. 01

    Verify your identity once

    Hold your phone against your ID card or passport. The app reads the chip, checks the issuing state's signature, and compares the portrait against your face. A separate key, used only for signing, is created at that moment.

  2. 02

    Share the document

    A code appears on the document. Anyone in the room can scan it, and anyone who is not can be invited by national ID number.

  3. 03

    They read it, then sign

    Whoever scans the code reads the document on their own phone before signing. Signatories appear on the list as they sign, not before.

  4. 04

    You accept

    Every signature comes to you for a decision. The document completes with the ones you accept, and the signed PDF is produced.

What you are left holding

What survives the process is a PDF. It has to be verifiable on its own even if this platform is gone, and it was built that way.

Signed by: Said Nadeem · Ayşe Çiğdem Yılmaz Page 4/9

Signatories on every page

Who signed is printed at the foot of every page, not only the last one. Someone holding page four does not have to go looking to find out whose document it is.

A verification code

The address printed on the document is fixed. Years later, someone holding the printout can scan it and check the signatures.

Anchored on chain

The document's hash is recorded on SciChain. Change one character and the hash no longer matches, and every signature fails.

The signing key never leaves the phone

The key used for signing is separate from your wallet and is created at the moment your identity is verified. It cannot be exported and cannot be imported — the app offers no way to do either. The server sees only the public half. The one thing that can produce your signature is that key, on that phone.

The key is used only after a biometric check.

Where this stands legally

These signatures are not a "güvenli elektronik imza" under Turkish law 5070. That requires a qualified certificate from a licensed provider, and the regulator's algorithm list does not yet include ML-DSA. Cryptographic strength is not a substitute for it.

What we do is put a signature that will not break tomorrow alongside the one the law recognises today. If you hold a qualified certificate, both can be used together: one for the courtroom, one for the archive.

Frequently Asked Questions

Do the people signing have to install anything?
They install the app and verify their identity once. After that they scan the code on the document and sign; there is no setup per document.
What happens to my documents if this platform closes?
The signed PDF is yours and verifies on its own. The document's hash is written to SciChain, so the signatures can be shown to belong to that document independently of us.
Is my ID and face data stored?
The chip portrait and the face comparison never leave the phone; the comparison runs on the device and the portrait is discarded when it finishes. The server holds only your national ID number and your public key.
Can I use this alongside my existing qualified e-signature?
Yes — that is what it is designed for. Your qualified certificate provides the signature the law recognises today; this one carries the document past quantum. Both can sit on the same document.
Who can see the document?
Whoever holds the code can read it and sign it. Whether a signature is recorded on the document is your decision; one you do not accept does not appear on it.

Put a document out for signature

Identity verification takes a few minutes and is done once.