# SignPlus for Confluence

SignPlus signs a Confluence page where it is. The page is rendered to PDF inside Atlassian's
runtime, sent to [Dokobit](https://www.dokobit.com) for qualified electronic signing, and the
signed document comes back as an attachment on the same page.

From then on the byline under the page title says whether the page is still what was signed.
SignPlus stores a SHA-256 of the page's space, id and version number with each signing, and
Confluence moves the version on every edit, so an edit after signing is visible to anyone who
opens the page.

<Aside type="note" title="Beta, with no Marketplace listing yet">
SignPlus is in beta and cannot be installed from the Marketplace yet. These pages describe the
current build. [Ask to join the pilot](/contact/) if you need it before the listing appears.
</Aside>

## A qualified signature, through Dokobit

SignPlus does not draw a signature on a page. The signing itself happens at
[Dokobit](https://www.dokobit.com), and the signer uses their own national eID: Smart-ID, an ID
card, Mobile-ID or another method on
[Dokobit's list of supported eIDs](https://www.dokobit.com/eids).

- **Equal to a handwritten signature.** A signature made with an eID that carries a qualified
  certificate is a qualified electronic signature (QES). Under Article 25(2) of
  [eIDAS, Regulation (EU) No 910/2014](https://eur-lex.europa.eu/eli/reg/2014/910/oj), a QES
  has the legal effect of a handwritten signature in every EU member state. Dokobit's eID list
  says which methods produce a QES and which an advanced signature (AdES).
- **Dokobit is a qualified trust service provider.** Dokobit states that it is a QTSP for the
  validation of electronic signatures and seals, supervised by Lithuania's
  [Communications Regulatory Authority](https://www.rrt.lt/) and listed on the
  [EU Trusted List](https://eidas.ec.europa.eu/efda/tl-browser/#/screen/tl/LT). Its practice
  statement is the
  [Signature Validation Service Practice Statement and Policy](https://www.dokobit.com/signature-validation-service-practice-statement-and-policy).
- **The data stays in the EU.** Dokobit states that it stores and processes data in the EU/EEA,
  mirrored in two locations, encrypted with TLS in transit and AES-256 at rest. Its information
  security is certified to [ISO/IEC 27001](https://www.dokobit.com/docs/compliance/Dokobit-iso27001-certificate.pdf)
  and [ISO/IEC 27018](https://www.dokobit.com/docs/compliance/Dokobit-iso27018-certificate.pdf),
  audited every year by DNV. All of it is on [Dokobit's compliance page](https://www.dokobit.com/compliance).
- **The signer's credentials never reach SignPlus or Oktul.** The personal code, the PIN and
  the verification code are entered on Dokobit's page and on the signer's own device.
- **Anyone can check the result without SignPlus.** The signed file is a standard ASiC-E
  container or a signed PDF, which DigiDoc4,
  [Dokobit's own validation](https://dokobit.support.signicat.com/hc/en-us/articles/19932798495004-How-to-validate-signed-documents)
  or any other eIDAS validation tool reads.

These are Dokobit's commitments, not Oktul's, which is why each one links to Dokobit's own page.
If Dokobit changes one, that page is the one to believe.

<Aside type="caution" title="The level comes from the eID, not from SignPlus">
A signature is only as strong as the eID used to make it. To accept qualified signatures only,
set **E-signature levels** to **QES only** in the [settings](../configure/). A signing in **Test** mode
has no legal effect at all.
</Aside>

## What it does

- **Signs from the page.** Choose signers, set a deadline and start the signing from the panel
  under the page title. Colleagues are picked by name, partners by email address, and a whole
  Confluence group at once.
- **Signs at company scale.** A policy can go to up to 25,000 people. SignPlus sends it in the
  background, so closing the page does not stop it, and the signing details show who has not
  signed yet.
- **Returns the signed file on its own.** When the last signer has signed, the signed document is
  attached to the page. Nobody downloads it from Dokobit by hand.
- **Reports edits after signing.** The byline, the panel, the REST API and an optional webhook
  all say when a signed page has been edited since.
- **Holds the page still while it is signed.** Editing can be limited to SignPlus, and viewing to
  the participants, while a signing is out.
- **Prints the page as Confluence shows it.** Panels, status lozenges, Jira work items tables,
  Oktul Work Item Selector fields and Jira Assets tables come out as they look on the page, in
  your company's styling: your font, logo, first page, header and footer.
- **Starts signings from outside Confluence.** A Jira automation flow, a Confluence rule through
  Send web request, or any system that can call the REST API.

## What it does not do

- **It cannot sign for anyone.** A qualified electronic signature is made by the signer, with
  their own Smart-ID, Mobile-ID, ID card or another method Dokobit supports.
- **It cannot make a page unchangeable.** No Confluence app can: a space administrator can
  always remove a restriction. What SignPlus guarantees is that a change is detected.
- **It does not say what changed.** It says that the page changed and links to
  Confluence's own page history, which answers what and who.
- **Test mode is not signing.** A new installation starts in Dokobit's test environment,
  where documents come back watermarked and are not legally binding.
- **Real signing needs your own Dokobit account.** Oktul provides the test environment so you
  can try SignPlus, and does not sell signing. Your agreement with Dokobit decides your volume
  and price.
- **It does not run outside Atlassian Cloud.** There is no Data Center or Server version.

## Where to start

| If you are | Start with |
|---|---|
| The administrator installing it | [Install the app](../install/), then [configure SignPlus](../configure/) |
| Sending a page for signing | [Sign a page](../sign-a-page/) |
| Asked to sign | [What a signer sees](../for-signers/) |
| Checking a signed page | [After signing](../after-signing/) |
| Making the document look like your company's | [Style the exported document](../export-styling/) |
| Building a flow or an integration | [Automation and webhooks](../automation/) and the [REST API](../rest-api/) |
| Reviewing it for security or procurement | [Privacy and data handling](../privacy/) |

---

A problem or a question? Write to [support@oktul.com](mailto:support@oktul.com) or open a request in the [Help Center](https://oktul.atlassian.net/servicedesk/customer/portals). Both reach the same service desk, so either way the request gets a reference and an SLA measuring the response.
