Sign a PDF with your .p12 or .pfx certificate (FNMT and other software certificates) producing a PAdES-B digital signature that validates in Adobe Acrobat and VALIDe. Both the PDF and your certificate stay on your computer: nothing is ever uploaded. Free includes one PDF per day; the 7-Day Pass and Pro are unlimited.
100% private: everything runs on your computer, your files never leave your device.
Sign with certificate produces a real digital signature on a PDF using a certificate you already hold, on your own computer. You supply your .p12 or .pfx file and its password, the document is hashed and signed in the browser, and the signature is embedded in the file as PAdES, the PDF signature standard that Adobe Acrobat and the Spanish VALIDe service both know how to check.
It works with software certificates, which is what the FNMT issues to individuals and companies and what most people have installed on their machine. The certificate and its password are read inside the browser tab and used there; neither is uploaded.
This is not a picture of a signature. It binds the signed bytes of the document to your certificate, so a reader can say who signed it and can tell whether anything has been altered since. If someone edits a single character after signing, that shows up when the signature is checked.
There is a family of PAdES levels, and it is worth knowing which one you are producing so that nobody is surprised at the other end.
The .p12 or .pfx file is parsed and the signature computed inside your browser tab. The certificate, the private key it contains and the password you type are never uploaded, never stored and never kept between sessions. The document is not uploaded either.
That is the whole reason to sign this way rather than on a site that asks you to send your certificate somewhere. A software certificate contains your private key: whoever holds it can sign as you, and it should never be handed to a server.
The free plan includes one signed PDF per day. The 7-Day Pass and Pro remove that limit.
Software certificates in .p12 or .pfx format, which is what the FNMT issues and what most people have. A certificate held on a smart card or a cryptographic token cannot be read by a browser tab and is not supported.
No. Both are read inside your browser, used there to compute the signature, and never sent, stored or remembered.
Only if you ask for a timestamp, and then only the SHA-256 hash of the signature value, relayed through OléPDF's own domain to the timestamp authority. The document itself never leaves your browser.
Sign PDF draws a picture of your handwriting on the page. This one produces a cryptographic signature that identifies the signer and detects any change made after signing. When a request names a certificate, a qualified signature or Adobe validation, this is the one you need.
Yes. Existing signatures are detected and reported before you sign, so you know you are adding to a document rather than starting it.