Document signing & integrity · ekSign
ekSign brings document signing back inside the bank. Customers review and sign in your app or on your own branded page, authenticated by the MFA they already use — and every signature is cryptographically bound to the document, so tampering is detectable forever. No third-party portal, no third-party brand, no third-party custody of your audit trail.
Most banks sign through an external e-signature platform. That means a customer receives an email that is not from the bank, is redirected to another brand's portal, and verifies with that platform's own SMS OTP — an event with no link to their banking identity. The signed documents and the audit trail then live in the vendor's platform, where the bank is a tenant and pricing or availability changes affect access to its own records.
Experience
The journey leaves the bank
Another brand's email, domain and portal sit in the middle of a regulated banking action.
Identity
Signing is not tied to the customer
A vendor OTP proves access to an inbox or a phone number, not that your verified customer signed.
Custody & cost
The bank does not own the record
Audit trail held externally, priced per envelope. ekSign replaces that with a marginal cost per signing event on infrastructure the bank already runs.
Cryptographic engine
Tamper-evident signing and audit
ekSign creates a SHA-256 fingerprint of the document, binds each signing event to that fingerprint with an ECDSA P-256 signature, chains multi-party signatures to one another, and produces a complete audit record the bank holds.
Authentication layer
The MFA your customers already have
The bank's existing MFA — biometric, push approval or TOTP — fires as the signing action, so the signature is bound to a bank-verified identity. Non-customers authenticate with national digital ID (for example UAE Pass, Emirates ID-backed).
Track ASingle signatory · existing customer
Track BMulti-signatory · sequential, parallel or mixed
Track CNon-customer · guarantor, co-applicant, prospect
The workflow system sets the mode when it initiates the request, and ekSign enforces it — advancing automatically in sequential mode while the bank retains the ability to pause, redirect or escalate at any point. A document is not executed until every required signature is present.
Signatories sign one at a time in a defined order; each party is notified only once the previous signature completes.
Borrower → Co-borrower → GuarantorAll signatories are notified simultaneously and may sign in any order. Used where no priority sequence is needed.
Joint holder A ∥ Joint holder BCombines both: parties sign in parallel, then a later signatory is notified once the earlier group has completed.
(Co-borrower A ∥ Co-borrower B) → GuarantorEach signature appears as a structured block on the document, labelled with the signatory's role and sequence position, and it travels with both digital and printed copies. Beneath them sits a SHA-256 seal covering all content and all signatures: alter one character of the document, or one field of any signature, and verification fails immediately.
| Sequence | Signature n of N, with the signatory's role on the document |
| Signature | ECDSA P-256, bound to the document fingerprint and chained to the prior signature |
| Seal | SHA-256 hash over document content and every signature block |
| Verification | Through the bank's own systems on request, or by QR seal where the bank wants third parties to verify an issued document unaided |
| Record | Signed copy and audit trail retained by the bank |
| Signer | Method | What it means |
|---|---|---|
| Existing customer | Bank MFA | The same MFA used for transfers and high-risk actions. No new enrolment, and the signing event ties directly to a verified banking identity. |
| Non-customer (guarantor, co-applicant) | National digital ID | Government identity backed by a national ID document. No bank enrolment needed; covers residents and most expatriates. |
| Prospective customer (onboarding) | National digital ID | Identity is established at the point of signing and linked to the customer record once the account is opened. |
| Document type | Signing mode | Notes |
|---|---|---|
| Loan & credit card agreements | Sequential | Highest legal weight. Borrower → co-borrower → guarantor, each party signing in order. |
| Joint account opening | Parallel | Both account holders sign simultaneously; completion triggers account activation. |
| Account mandate changes | Single / sequential | Sole mandate: single signatory. Joint mandate: sequential or parallel by mandate type. |
| FATCA / CRS declarations | Single | Regulatory identity-verified signature; national digital ID covers non-resident signers. |
| Investment suitability forms | Single | Risk appetite declaration. Biometric MFA adds evidentiary strength. |
| Insurance policy acceptance | Single | Bancassurance terms acceptance; the workflow system routes to policy issuance on completion. |
| Third-party e-signature platform | ekSign |
|---|---|
| Customer redirected to the vendor's portal and brand | Customer signs in the banking app or on a bank-branded page |
| Authenticated by vendor SMS OTP or email | Authenticated by the bank's own MFA, or national digital ID |
| Signing event not linked to the banking identity | Signing event cryptographically bound to a bank-verified identity |
| Multi-signatory routing managed inside the vendor platform | Routing defined and owned by the bank's workflow system |
| No tamper detection on the signed document | SHA-256 seal detects any alteration after signing |
| Audit trail held by the vendor — the bank is a tenant | Full audit trail owned and held by the bank |
| Vendor branding throughout the experience | Bank brand on every touchpoint — app, page, signature block, emails |
| Fixed per-envelope licence fee at scale | Marginal cost per signing event on Ektar's platform |