CorporateWebMobile

Electronic Signature Application

Sign your PDF documents one by one or in bulk with e-signature and mobile signature. Via the REST API, your EBYS, portal or own application sends a document and receives a signed PDF within seconds — Law 5070 compliant, timestamped.

5070
Full legal compliance
60K+
Signatures per month
3 s
Average signing time
100%
Verifiable signatures
About the service

What does the E-Signature Application solve?

When every application uses its own signing tool, you get driver issues, version conflicts and piles of waiting documents. The E-Signature Application provides a single signing layer for all of the institution's systems.

Managers see pending documents in one list and bulk-sign the ones that are ready; people in the field keep processes moving with mobile signature. Every signature gets a timestamp compliant with Law No. 5070, and a public verification screen lets anyone check a signature's validity.

Key capabilities

Capabilities that work in the field

1

E-signature & mobile signature

Smart cards, USB tokens and mobile signature in one interface; driver issues solved in one place.

2

Bulk signing

Filter pending documents and sign them all with a single PIN entry; hundreds of documents take minutes.

3

Timestamping

Every signature carries a qualified timestamp; the moment of signing is legally provable.

4

Signature verification screen

Upload any signed document to instantly verify the signature and its certificate chain.

5

Mobile app

iOS and Android apps keep the signing flow moving wherever managers are.

6

PDF signing via REST API

Send the document to the API, get the compliant signed PDF back. Embeds into EBYS and your own apps with a few lines of code; sandbox environment and OpenAPI docs provided.

How it works

Hybrid architecture: cloud API + thin client

Under Law No. 5070, a qualified signature's private key can never leave the card or token — so the signature itself is created where the key lives, and everything else is managed in the cloud. Your document reaches the API; the hash and PAdES structure are prepared server-side, the timestamp and verification record are produced server-side, and the signed PDF is archived.

When signing with a card or token, the thin client on the user's computer does exactly one job: it signs the prepared digest with the card and returns the result to the API. On the mobile-signature channel no installation is needed at all — the whole flow runs in the cloud and the user approves with a PIN on their phone.

Your EBYS or your own application talks to a single REST API; because the client carries no business logic, update and support costs stay minimal. When remote (cloud) qualified signing becomes widespread through trust service providers, it plugs into the same API as another channel.

Integrations

In harmony with your existing systems

KamuSM
Timestamp Authority
EBYS
Document & Approval Automation
Mobile Operators
REST API / SDK
Reference

Proven in the field

Ula Municipality — installed and in use
Product page

The product behind it: eimzaonay

The productised form of this service, eimzaonay (eimzaonay.com), adds qualified electronic signatures compliant with e-Signature Law No. 5070 to applications through a single REST API: PAdES, CAdES and XAdES formats, smart-card and mobile-signature channels, timestamping and public QR verification. The private key never leaves the user's card or phone.

View the eimzaonay product page

Frequently asked questions

Good to know

Does my signing key ever go online?
No. Your qualified certificate's private key never leaves your card or token; only the document digest and the produced signature value travel to the cloud. With mobile signature, the key stays on your SIM.
How do we connect the API to our own application?
You send the document to the REST API; if a card signature is needed the user's thin client steps in, and mobile signature runs directly through the operator flow. Either way you get back a legally compliant signed PDF. With the sandbox and OpenAPI docs, a typical integration takes a few days.
Which e-signature providers are supported?
Cards from all authorized Turkish trust service providers and common card readers are supported; tested with KamuSM certificates.
Is bulk signing legally valid?
Yes. Each document is signed individually with its own signature value; the bulk flow only speeds up the user experience.
Trusted by institutions

Let's build yours

Tell us what you need; we will demo the E-Signature Application live and reply with a tailored offer.