Open-Source & Globally Compliant Electronic Signature & Document Workflow Platform
Key Features • Architecture • Quick Start • Tech Stack • Testing • Documentation • Compliance
Graphsign.ink is a modern, high-performance, enterprise-grade electronic signature and agreement lifecycle platform. Engineered from the ground up for privacy, edge performance, and global compliance, Graphsign empowers everyone to design, review, sign, and seal contracts with cryptographic auditability and zero vendor lock-in.
- 📑 Visual PDF & Markdown Field Editor: Drag and drop interactive signature blocks, initials, text fields, dates, checkboxes, and radio buttons directly on top of real PDF documents or live Markdown previews.
- 🔄 Multi-Party Signing Workflows: Route agreements sequentially (ordered routing) or in parallel across external signers with automatic reminder dispatches and status progression (
Draft➔In Review➔Approved➔Sent➔Completed). - ⚖️ Scoped Review Decision Engine: Built-in internal review gates strictly accessible by designated reviewers and administrators before contracts are dispatched for execution.
- 🛡️ Enterprise Multi-Tenancy & RBAC: Strict tenant boundaries enforced via PostgreSQL Row-Level Security (RLS) policies, organization roles (
owner,admin,member,reviewer), and granular permission enforcement (documents:read,documents:write,templates:manage). - 🔒 Tamper-Evident Hash Chains: SHA-256 hash-chained cryptographic audit logs capturing user agent, IP address, exact timestamps, and certificate validations for forensic admissibility.
- ⏱️ Timezone-Standardized Records: All dates and audit logs formatted deterministically in
DD-MON-YYYY HH:mm (TZ)(e.g.23-AUG-2026 15:45 (GMT)), automatically localized to the user's configured profile timezone. - 🔑 Dual-Factor Authentication (MFA): TOTP authenticator app enforcement, secure session token rotation, and single-session settings controls.
Graphsign is designed as a modular, lightweight monorepo running on distributed edge compute and serverless database infrastructure:
graphsign.ink/
├── apps/
│ ├── web/ # Next.js 16 (Turbopack) on Cloudflare Pages
│ │ # Visual field editor, public signer portal, admin consoles
│ └── api/ # Hono 4.13 REST API on Cloudflare Workers
│ # State machine, JWT auth, Web Crypto, email notifications
├── packages/
│ └── db/ # Prisma ORM schema, migrations, RLS tenant isolation
├── services/
│ └── signing/ # JVM cryptographic signing microservice (PAdES B-LTA / DSS)
├── Environment_Setup/ # Setup guides, Neon migrations, and local dev guides
└── .github/workflows/ # CI pipelines, deployment matrix, and secret scans
| Layer | Technology | Purpose |
|---|---|---|
| Frontend Framework | Next.js 16.3.1 (React 19, Turbopack) | Responsive, server-rendered and static web application |
| Backend API | Hono 4.13.3 | Ultra-fast, edge-native TypeScript REST API |
| Language & Runtime | TypeScript 5.9.3 | Type-safe end-to-end schemas and contracts |
| Styling & Icons | Tailwind CSS 3.4 | Modern, accessible, clean design system |
| Database & ORM | PostgreSQL (Neon Serverless) + Prisma 6.19 | Multi-tenant schema with driver adapters |
| Authentication | Web Crypto JWT + TOTP | Stateless, standards-compliant authentication |
| Package Manager | pnpm 9+ | Fast, disk space-efficient monorepo workspace |
| Testing Suite | Vitest 3.2 + React Testing Library | 100% unit and integration test coverage |
- Node.js:
v20.xor higher - pnpm:
v9.xor higher (npm install -g pnpm) - PostgreSQL: Local instance or free Neon Serverless Postgres database
# Clone repository
git clone https://github.com/graphomy/graphsign.ink.git
cd graphsign.ink
# Install monorepo dependencies
pnpm installCopy the example environment files:
cp .env.example .env
cp packages/db/.env.example packages/db/.env
cp apps/api/.dev.vars.example apps/api/.dev.vars
cp apps/web/.env.local.example apps/web/.env.local# Generate Prisma Client & push schema to database
pnpm db:generate
pnpm db:push# Run both API Worker and Web Application concurrently
pnpm dev- 🌐 Web Portal: http://localhost:3000
- ⚡ REST API: http://localhost:8787
Every Pull Request must pass the complete CI verification pipeline:
# 1. Check code formatting with Prettier
pnpm format:check
# 2. Run ESLint code quality checks
pnpm lint
# 3. Perform TypeScript typechecking across all packages
pnpm typecheck
# 4. Run entire Vitest unit & integration test suite (310+ tests)
pnpm test
# 5. Validate production build (Next.js & Hono)
pnpm build- 🤖 CLAUDE.md: Master developer workflow, Git policy, and AI pair-programming instructions.
- 📘 Local Development Setup Guide: Step-by-step developer setup and troubleshooting.
- 📖 Product Specifications: Product goals, compliance matrices, and roadmap.
- 🏗️ System Architecture: Edge architecture, component boundaries, and security.
- 🔒 Security & Privacy Architecture: Threat modeling, KMS encryption, and audit controls.
- 🌐 REST API Documentation: API routes, payload validators, and error schemas.
Graphsign.ink is engineered to comply with major global electronic signature frameworks:
- United States: Electronic Signatures in Global and National Commerce Act (ESIGN) & Uniform Electronic Transactions Act (UETA)
- European Union: Electronic Identification, Authentication and Trust Services (eIDAS Regulation EU No 910/2014)
We welcome contributions! Please adhere to our standard Git workflow:
- Ensure work is linked to a Jira issue or GitHub Issue.
- Create a branch from
develop:feature/<issue-id>-<description>. - Verify all formatting, linting, tests, and builds pass locally.
- Submit a Pull Request targeting
develop.
This project is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0).