EktarSignatures validBook a demo

Document signing & integrity · ekSign

Signing inside your own channel. Proof that outlives the session.

ekSign brings document signing back inside the bank. Customers review and sign in your app or on your own branded page, authenticated by the MFA they already use — and every signature is cryptographically bound to the document, so tampering is detectable forever. No third-party portal, no third-party brand, no third-party custody of your audit trail.

ekSign · execution status2 of 3 signed
Primary borrowerSigned
Co-borrowerSigned
GuarantorAwaiting
AuthenticationBank MFA · national ID
Seal SHA-256 a3f9·c2d1·e4b8 — any alteration after signing fails verification
CryptographyECDSA P-256 · SHA-256 document seal
AuthenticationBank MFA · national digital ID
IntegrationOne API call · no workflow change
Why banks move signing in-house

A third-party portal breaks the journey and holds your record.

Most banks sign through an external e-signature platform. That means a customer receives an email that is not from the bank, is redirected to another brand's portal, and verifies with that platform's own SMS OTP — an event with no link to their banking identity. The signed documents and the audit trail then live in the vendor's platform, where the bank is a tenant and pricing or availability changes affect access to its own records.

Experience

The journey leaves the bank

Another brand's email, domain and portal sit in the middle of a regulated banking action.

Identity

Signing is not tied to the customer

A vendor OTP proves access to an inbox or a phone number, not that your verified customer signed.

Custody & cost

The bank does not own the record

Audit trail held externally, priced per envelope. ekSign replaces that with a marginal cost per signing event on infrastructure the bank already runs.

What ekSign is

Two capabilities you already own, joined into one product.

Cryptographic engine

Tamper-evident signing and audit

ekSign creates a SHA-256 fingerprint of the document, binds each signing event to that fingerprint with an ECDSA P-256 signature, chains multi-party signatures to one another, and produces a complete audit record the bank holds.

  • Signature bound to exact document contents
  • Any post-signing alteration fails verification
  • Audit record owned and stored by the bank

Authentication layer

The MFA your customers already have

The bank's existing MFA — biometric, push approval or TOTP — fires as the signing action, so the signature is bound to a bank-verified identity. Non-customers authenticate with national digital ID (for example UAE Pass, Emirates ID-backed).

  • No new enrolment, app or password
  • Signing event linked to the banking identity
  • Step-up strength configurable per document type
Signing journeys

Three tracks, depending on who has to sign.

Track ASingle signatory · existing customer

  1. The bank initiates a signing request; the customer receives a push notification in the banking app.
  2. The customer opens and reviews the document in full, inside the app.
  3. On "Sign", the bank's MFA fires an authentication challenge — biometric, push approval or TOTP.
  4. The signature is recorded, the document sealed, and a signed copy stored in the bank's systems and delivered to the customer.

Track BMulti-signatory · sequential, parallel or mixed

  1. The bank's workflow system initiates the request, specifying each signatory, their role, and the signing order.
  2. ekSign notifies the first signatory (sequential) or all signatories at once (parallel), each in their own channel.
  3. Each party reviews and authenticates — in the banking app for customers, on a bank-branded secure page for everyone else.
  4. Each completed signature is cryptographically chained to the previous one, and the workflow system is notified after every signature.
  5. Once all required parties have signed, the document is sealed with all signature blocks and delivered to all parties.

Track CNon-customer · guarantor, co-applicant, prospect

  1. The bank shares the document as a secure link sent from its own domain, by SMS or email — no third-party domain.
  2. The recipient opens it on a bank-branded signing page in the browser.
  3. They authenticate with national digital ID — no bank account or app required.
  4. The signature is recorded and sealed; the signed document is delivered to the recipient and retained by the bank.
Signing order

The bank's workflow owns the sequence.

The workflow system sets the mode when it initiates the request, and ekSign enforces it — advancing automatically in sequential mode while the bank retains the ability to pause, redirect or escalate at any point. A document is not executed until every required signature is present.

Sequential

Signatories sign one at a time in a defined order; each party is notified only once the previous signature completes.

Borrower → Co-borrower → Guarantor
Parallel

All signatories are notified simultaneously and may sign in any order. Used where no priority sequence is needed.

Joint holder A ∥ Joint holder B
Mixed

Combines both: parties sign in parallel, then a later signatory is notified once the earlier group has completed.

(Co-borrower A ∥ Co-borrower B) → Guarantor
What the signature looks like

A visible block per signatory, and one seal over everything.

Each signature appears as a structured block on the document, labelled with the signatory's role and sequence position, and it travels with both digital and printed copies. Beneath them sits a SHA-256 seal covering all content and all signatures: alter one character of the document, or one field of any signature, and verification fails immediately.

SequenceSignature n of N, with the signatory's role on the document
SignatureECDSA P-256, bound to the document fingerprint and chained to the prior signature
SealSHA-256 hash over document content and every signature block
VerificationThrough the bank's own systems on request, or by QR seal where the bank wants third parties to verify an issued document unaided
RecordSigned copy and audit trail retained by the bank
Signature 1 of 3Primary borrower
Signed byA. Al Mansoori
Date & time23 Jul 2026 · 14:32:07 GST
Authenticated viaBank MFA (biometric)
ReferenceSGN-2026-00891-001
StatusSigned
Document hash (SHA-256) a3f9·c2d1·e4b8·f7…
Tamper-evident seal over all content and signatures
Authentication by signer type

The right identity mechanism per signatory.

SignerMethodWhat it means
Existing customerBank MFAThe same MFA used for transfers and high-risk actions. No new enrolment, and the signing event ties directly to a verified banking identity.
Non-customer (guarantor, co-applicant)National digital IDGovernment identity backed by a national ID document. No bank enrolment needed; covers residents and most expatriates.
Prospective customer (onboarding)National digital IDIdentity is established at the point of signing and linked to the customer record once the account is opened.
Priority use cases

Where banks start.

Document typeSigning modeNotes
Loan & credit card agreementsSequentialHighest legal weight. Borrower → co-borrower → guarantor, each party signing in order.
Joint account openingParallelBoth account holders sign simultaneously; completion triggers account activation.
Account mandate changesSingle / sequentialSole mandate: single signatory. Joint mandate: sequential or parallel by mandate type.
FATCA / CRS declarationsSingleRegulatory identity-verified signature; national digital ID covers non-resident signers.
Investment suitability formsSingleRisk appetite declaration. Biometric MFA adds evidentiary strength.
Insurance policy acceptanceSingleBancassurance terms acceptance; the workflow system routes to policy issuance on completion.
ekSign vs a third-party portal

The same signature, on your side of the wall.

Third-party e-signature platformekSign
Customer redirected to the vendor's portal and brandCustomer signs in the banking app or on a bank-branded page
Authenticated by vendor SMS OTP or emailAuthenticated by the bank's own MFA, or national digital ID
Signing event not linked to the banking identitySigning event cryptographically bound to a bank-verified identity
Multi-signatory routing managed inside the vendor platformRouting defined and owned by the bank's workflow system
No tamper detection on the signed documentSHA-256 seal detects any alteration after signing
Audit trail held by the vendor — the bank is a tenantFull audit trail owned and held by the bank
Vendor branding throughout the experienceBank brand on every touchpoint — app, page, signature block, emails
Fixed per-envelope licence fee at scaleMarginal cost per signing event on Ektar's platform

Replace a recurring licence with a capability you own.