Skip to main content
Newcomer
October 9, 2026
Idea Submitted

I've been building a post quantum hashing certificates for docusign envelopes using Algorand

Categories:eSignature
  • October 9, 2026
  • 0 replies
  • 8 views

The idea

  Give completed envelopes a proof that (1) uses a post-quantum signature and (2) can be verified years from now without
  DocuSign's servers. As a first step, expose a stable SHA-256 of the completed document in the eSignature API, so
  integrators can anchor and verify it themselves.

  Why it matters

  - The certificate of completion and the PDF seal use RSA, which a large enough quantum computer would break. NIST
    finalised ML-DSA (FIPS-204) in 2024, and US federal guidance (CNSA 2.0) expects the move to post-quantum cryptography
    in the early 2030s. Agreements signed today will need to verify in 2040.
  - There is no stable fingerprint to build on. Downloading the same completed envelope twice
    (documents/combined?certificate=true) gives two different SHA-256 hashes. The XMP dates, the PDF /ID and the adbe.pkcs
    seal change on every download, so a hash taken today never matches a copy downloaded later.

  I built a working prototype to show it can be done today

  - DocuSign Connect sends envelope-completed. The service confirms the status through the API, downloads the combined PDF
    once, and hashes it.
  - The hash is anchored on the Algorand public ledger, and a receipt is signed with ML-DSA-65 (post-quantum). The receipt
    records DocuSign's completion time and the capture time.
  - The signer gets a private link to that exact copy and can verify it in the browser or with an open-source tool,
    without trusting DocuSign or my service. Change one byte and verification fails.
  - In three sandbox test runs, completion to anchored took 23–26 seconds, with no Connect delivery failures. Only hashes
    go on-chain.

  Try it in under a minute (sandbox, free, no account or email needed; you sign a demo contract with embedded signing):
  https://pq-verifiable-archive.vercel.app/try

  Open-source code and a guide for running it on your own sandbox:
  https://github.com/m-reynaldo35/pq-verifiable-archive

  Step-by-step test write-up:
  https://github.com/m-reynaldo35/pq-verifiable-archive/blob/main/docs/live-tests.md