Appearance
ToFF Sign System Architecture
Technical architectural specification of the sovereign electronic signature stack deployed at https://sign.tomoffinland.org.
1. Container Topology
ToFF Sign is orchestrated via high-availability Docker containers on the Foundation primary infrastructure:
| Container | Image / Technology | Purpose | Port / Scope |
|---|---|---|---|
isf-prod-documenso-1 | documenso/documenso:v2.18.0 | Next.js core application, PDF manipulation engine, signing UI | 3000 (Internal) |
isf-prod-database-1 | postgres:16 | Relational document store, audit logs, recipient state, signatures | 5432 (Internal) |
isf-prod-caddy-1 | caddy:2 | Automated Let's Encrypt TLS termination and edge routing | 80, 443 (Public) |
isf-prod-worker-1 | Python worker runtime | Background document processing and PDF certificate generation | 8080 (Internal) |
2. Cryptographic Security & Tamper Evidence
The system enforces cryptographic guarantees at multiple layers:
- Pre-Sign Hashing: Upon document upload, a SHA-256 cryptographic digest of the source PDF binary is committed to the PostgreSQL ledger.
- Signature Block Embedding: Signatures and initial stamps are embedded into the PDF structure using low-level PDF manipulation libraries, rendering each page immutable.
- Post-Execution Certificate Synthesis: Upon completion by all recipients, an appended Certificate of Completion is generated containing:
- Universal Document ID
- Initial Document SHA-256 Hash
- Final Document SHA-256 Hash
- Signatory IP addresses, email identifiers, and UTC millisecond timestamps
- Data at Rest: PostgreSQL volumes and document storage paths are mounted on encrypted persistent host volumes.