Appearance
ToFF Sign
Powered by Documenso
Managed by CultureOS
ToFF Sign (https://sign.tomoffinland.org) is the Foundation's official electronic document execution platform.
All board resolutions, donor agreements, non-disclosure covenants, independent contractor agreements, and intellectual property licensing instruments must be executed through ToFF Sign to ensure legal enforceability and digital chain-of-custody compliance.
System Operations & Engineering
This operational system is configured, deployed, and managed by CultureOS. CultureOS is an AI-native practice helping cultural institutions modernize digital infrastructure, archives, and research workflows responsibly.
Access Details
- Portal URL:
https://sign.tomoffinland.org - Underlying Engine: Documenso Open Source Project
- Infrastructure Engineering: Configured, deployed, and managed by CultureOS
- Access Scope: Institutional staff, board trustees, and invited external signatories.
- Authentication: Administrative credential authentication for document creators; passwordless secure token links for signers.
Feature Highlights
Core operational capabilities available to Foundation personnel and signatories:
- Legally Enforceable Electronic Execution: Execute board resolutions, artist contracts, non-disclosure agreements, and licensing covenants with binding digital validity.
- Cryptographic Audit Trail & Certificate of Completion: Automatically generate verifiable execution certificates containing SHA-256 document digests, participant IP addresses, and RFC 3161 timestamps.
- Self-Hosted Data Sovereignty & Vault Storage: Retain 100% of sensitive institutional contracts on encrypted Foundation-controlled storage, completely free from third-party vendor surveillance.
- Multi-Role Signatory Routing: Configure flexible recipient roles with customized signing orders for active signatories, countersigning trustees, and read-only CC observers.
- Browser-Based Zero-Install Execution: Allow trustees and external partners to review and execute agreements smoothly on any desktop, tablet, or smartphone without software installation.
- Institutional Reusable Templates: Maintain standardized, pre-anchored legal templates for recurrent board consents, artist agreements, and contribution releases.
Standard Execution Procedure
1. Initiating a Document for Execution
- Log in to
https://sign.tomoffinland.orgwith your institutional administrative credentials. - Select New Document or choose an authorized standard template.
- Upload the finalized legal PDF document.
- Define recipient roles:
- Signer: Parties required to execute the document.
- Viewer / CC: Parties who receive an executed copy for record keeping without signing authority.
- Place required field anchors:
- Signature block
- Signer printed name
- Execution date
- Initials (where multi-page verification is mandatory)
- Review the dispatch summary and select Send Document.

Demonstration: Document Dispatch & Field PlacementSOP-SGN-01
2. Signing Protocol for Signers
Signers receive an authenticated electronic transmission from sign.tomoffinland.org.
- Open the invitation link in any secure modern web browser.
- Review the document text thoroughly.
- Click the highlighted field to apply your digital signature (drawn or cryptographically typed).
- Select Complete Signing.
- Once all signatories complete execution, an immutable signed copy and Audit Certificate are automatically distributed to all designated parties.
Reusable Contract Templates
To maintain institutional consistency and prevent formatting errors, standard legal instruments should be deployed as templates:
- Board Resolutions: Pre-configured signature blocks for all sitting trustees.
- Non-Disclosure Agreements (NDAs): Standardized bilateral covenants for visiting researchers, contractors, and partners.
- Art Loan & Exhibition Consents: Pre-anchored condition report sign-offs and transit liability agreements.
Cryptographic Audit Trail
Every completed transaction automatically appends an immutable Certificate of Completion to the legal document package:
- Cryptographic Hash Verification: The unexecuted original and finalized signed PDF are digested using SHA-256 hashing to certify zero tampering.
- Timestamp & Network Provenance: Signer IP addresses, user-agent signatures, and RFC 3161 timestamps are immutably logged for legal chain-of-custody compliance under US ESIGN, UETA, and EU eIDAS frameworks.
Document Retention & Governance
- Vault Ingress: Completed documents are retained on encrypted storage volumes on the Foundation primary host.
- Periodic Verification: The internal worker process performs continuous integrity verification against the primary PostgreSQL database to guarantee uncorrupted storage.
- No External Storage: Documents remain strictly on Foundation-controlled infrastructure, preventing vendor surveillance or unauthorized third-party scanning.