Skip to content

Hand over a document that can be proved.

A return, a computation, a certificate or a KYC pack — sealed the moment it arrives, traceable to the person you gave it to, and checkable by anyone without an account.

01

On upload, it is sealed

The file’s raw bytes are hashed with SHA-256 and a detached CMS signature is made over that hash by Fortax’s own certificate authority — the SEAL generic-file-seal profile. The signature travels as its own sidecar, so the document itself is never altered.

02

The original is never touched

There is no “edit”. Replacing a document writes a new version and marks the old one superseded; the earlier file and its seal stay exactly as they were. The history cannot be rewritten.

03

The CA cannot write on its own

A client issues a time-limited grant (up to 30 days) from their own vault. The CA must present it to upload or replace, and only the hash of that token is stored. Access ends when the client says so.

04

Every recipient gets their own copy

Watermarking a file would change its bytes and break the seal, so the original stays sealed and untouched and each recipient receives their own sealed derivative carrying a trace code. A copy that leaks says who it was given to.

05

Opening is recorded

A recipient needs no account — the link is the credential — and every view and download goes into the access log with the time and the address it came from.

06

Anyone can verify, without us

The public portal checks a seal by its ID, or you upload your copy and it is hashed and compared. Your file is not stored: the hash is taken and thrown away.

Plainly

What it is, and what it is not.

Where files live

Outside the web root, on Fortax’s own server in India. No URL reaches them directly.

What can go in

PDF, images, Excel, Word, CSV, text, XML, JSON and zip, up to 25 MB a file.

What a seal proves

That these exact bytes existed at that time and were sealed by this issuer — integrity and time.

What it does not claim

Our certificate authority is self-hosted and self-signed, so the issuer’s name is our own assertion, not a public CA’s. Adobe’s automatic green tick does not come from it; our verification portal is the trust anchor.

Where it is used

  • A CA firm handing back a filed return — the acknowledgement, the computation and the workings go out sealed, each client copy traceable.
  • A business sending papers to a bank or a buyer — GST certificate, PAN, financials and KYC, as a link that expires instead of an attachment that travels.
  • Due diligence and tenders — the other side can verify every document without calling you, and you can see what they opened.
  • The Blockchain Security Card — the client taps the card; the verified profile and its sealed documents open from the same vault. See the card.

Verify a document

Anyone holding a sealed file or its seal ID can check it at the public portal — no account, nothing stored: ai.fortax.in/verify.

Questions

Asked before trusting it.

How is this different from emailing a PDF?
An email attachment can be edited, re-saved and forwarded with nobody the wiser. A sealed document carries a signature over its exact bytes, each recipient’s copy is traceable, and every opening is logged. If a version is disputed later, there is something to check instead of a memory of who sent what.
Can Fortax change a document in the vault?
Not without it showing. A replacement is a new version; the old file and its seal remain. Any change to the bytes of a sealed file makes verification fail — including a change by us.
Does the recipient need an account?
No. The link they receive is the credential, and it carries their own trace code. You can see who opened it and when, and stop the link.
Who can verify a document?
Anyone, without a login. They can enter the seal ID, or upload the copy they hold and have it hashed and compared. The uploaded file is not kept.
Is this a digital signature under the IT Act?
No, and it does not pretend to be. It is proof of integrity and time from a self-hosted issuer. A statutory e-signature or DSC is a separate thing, and where a filing needs one you still use the DSC.
How does a CA get access?
The client issues a grant from their vault, for a period they choose, up to 30 days. The CA uses it to upload or replace; the client can end it at any time and sees every action in the log.

Seal your first document

It is inside every Fortax account — business or CA firm.

Open your vault Verify a document