secure2sign is an advanced digital signing tool which is integrated into Microsoft Office Word in a manner that allows and encourages natural document signing. secure2sign allows multiple persons to digitally sign and/or time-stamp a document.
secure2sign makes signing documents as quick and easy as picking up a pen. Security features such as validation of digital certificate revocation and expiry status is checked for, and hidden data and embedded documents are supported. secure2sign supports the use of smart cards and two factor authentication such as the use of a PIN.
secure2sign signatures can be used to ensure a document:
- Has not been altered since it was signed this gives proof of content and assures integriity.
- Existed in this form at the time it was it was time-stamped, i.e. proof of existence.
secure2sign is an advanced digital signing tool which is integrated into Microsoft® Office Word in a manner that allows and encourages natural document signing. secure2sign makes signing documents as quick and easy as picking up a pen.
secure2sign enables you to digitally sign and timestamp Microsoft® Office Word documents so that it can be shown that the document:
- Full integration with Microsoft Word.
- Has not been altered since it was signed. (Proof of content.)
- Existed in this form at the time it was time-stamped. (Proof of existence.)
In addition secure2sign allows the signer to associate an electronic approval with their signature which shows why they are signing that document at that point in time, some examples include:
- Approved – Final – Audited - etc
Other features include:
- Full integration with Microsoft Word.
- Supports Microsoft Word 2000, 2002 (XP), 2003, 2007.
- Time stamping from an authorised time stamp time source to RFC 3161.
- Multiple signatures with co-signing and countersigning.
- Support for two-factor authentication.
- Supports certificate validation using OCSP or CRL.
- Optional visible signature.
- Display of signatures from Microsoft Office signing.
- Signature includes objects that are embedded into content.
- Stores log entry, from OCSP client validation of certificate at signing time, with signature.
- Full administrator control over functions, acceptable certificate revocation, etc.
- Permits signing of the entire file or just the content.
- Option to store detached signature independently for audit, business process validation, etc.
- Check for revocation status of digital certificate – if revoked, can’t sign.
- Support for unlimited number of signatures on the same document.
- Includes objects that are embedded into content, such as a worksheet embedded into a Word document, in the signature.
- Helps with compliance such as ESIGN, etc.
- Support for smart cards and eTokens.
secure2sign supports the US Government HSPD-12 PIV cards and also banking and financial institutions requirements including the IdenTrust scheme for digital identities. secure2sign also enables the use of two factor authentication for signing of documents.
Unlike other digital signing tools, secure2sign checks Microsoft® Office documents for potentially malicious content before you sign, to ensure that you don't sign content that you are unaware of, or that may display differently at a later date. For example, a field could be set to change a number, such as $45,000 to $450,000 on a given date, you would have signed the document showing the lesser amount and unbeknown to you, that amount would be changed at a later date with no associated acknowledgement of that change.
In addition, unlike other digital signing tools, secure2sign:
- Does not use ActiveX controls, macros or Visual Basic code.
- The ability to sign without introducing active content.
- Eliminates the possibility of active content being maliciously exploited.
- Prevents the problem of firewalls filtering out documents with active content.
- Avoids conflicts with using documents with active content in secure environments.
- Ensures compatibility with Microsoft® Office 2007 default native file formats (.docx) that specifically exclude any active elements (ActiveX, scripts or macros).
- Checks Microsoft Office documents for potentially malicious content before you sign, to ensure that you don't sign content that you are unaware of or that may display differently at a later date.
- Is resistant to the attacks that have been shown to affect other signing programs.
With secure2sign, both signers and systems administrators can:
- Restrict choice of certificates to those from specified certificate authorities.
- Enforce certificate validation on signing.
- Enforce the use of OCSP validated certificates.
- Disable editing of the document, except for form fields, after signing. (Users with selected certificates can be allowed to edit the document.)
These restrictions may be applied within an enterprise, so that documents signed within the enterprise can conform with the enterprise’s signing policies. However, uniquely, secure2sign stores these rules within the signed document, so that signers outside of the enterprise can be forced to comply with them.