Skip to content

ToFF Sign System Architecture ​

Technical architectural specification of the sovereign electronic signature stack deployed at https://sign.tomoffinland.org.


1. Container Topology ​

ToFF Sign is orchestrated via high-availability Docker containers on the Foundation primary infrastructure:

ContainerImage / TechnologyPurposePort / Scope
isf-prod-documenso-1documenso/documenso:v2.18.0Next.js core application, PDF manipulation engine, signing UI3000 (Internal)
isf-prod-database-1postgres:16Relational document store, audit logs, recipient state, signatures5432 (Internal)
isf-prod-caddy-1caddy:2Automated Let's Encrypt TLS termination and edge routing80, 443 (Public)
isf-prod-worker-1Python worker runtimeBackground document processing and PDF certificate generation8080 (Internal)

2. Cryptographic Security & Tamper Evidence ​

The system enforces cryptographic guarantees at multiple layers:

  • Pre-Sign Hashing: Upon document upload, a SHA-256 cryptographic digest of the source PDF binary is committed to the PostgreSQL ledger.
  • Signature Block Embedding: Signatures and initial stamps are embedded into the PDF structure using low-level PDF manipulation libraries, rendering each page immutable.
  • Post-Execution Certificate Synthesis: Upon completion by all recipients, an appended Certificate of Completion is generated containing:
    • Universal Document ID
    • Initial Document SHA-256 Hash
    • Final Document SHA-256 Hash
    • Signatory IP addresses, email identifiers, and UTC millisecond timestamps
  • Data at Rest: PostgreSQL volumes and document storage paths are mounted on encrypted persistent host volumes.

Configured, deployed, and managed by CultureOS. CultureOS is an AI-native practice helping cultural institutions modernize digital infrastructure, archives, and research workflows responsibly.