Secure PDF signing on iPhone
Sign PDFs with your certificate or by hand
Import a .p12 or .pfx certificate, place a visible signature on the page, and export a signed PDF copy without changing the original file.
Privacy policy
Cert Sign is designed around local processing. This page explains what stays on your device, what may leave it, and how you can control your data.
Last updated: 2026-07-11
What the app processes
- PDF files you choose to sign or scan.
- Imported .p12 or .pfx certificate files and certificate metadata.
- Signature placement, signing preferences, and signed document history.
What stays on your device
- PDF signing and manual signatures are created locally on your iPhone or iPad.
- Imported certificates remain in app storage and sensitive secrets can be protected by the iOS Keychain.
- If you choose biometric unlock, the saved certificate password is stored in Keychain on your device.
What may leave your device
- Cert Sign does not upload your PDF or certificate to our server for signing.
- If you contact support by email, the information you choose to send is handled by your email provider.
- Apple may process diagnostics, crash reports, or App Store data under its own terms.
Your control
- You can remove imported certificates, signed document history, and local settings at any time.
- If you saved a certificate password with biometrics, you can delete it from the app settings.
Optional online signature validation
- PDF signing remains entirely on your device. Online validation is a separate, optional action and the app asks for your confirmation before every upload.
- If you continue, the complete PDF is sent over HTTPS to the Cert Sign DSS endpoint on CarspecsLab to check signature integrity, certificate chains, revocation information, EU Trusted Lists, timestamps, and qualification.
- The validation service does not provide document storage and has no mounted document volume. Request bodies and validation-path access requests are not logged at the origin. Processing and temporary runtime data are discarded; certificate, revocation, and Trusted List data may be cached.
- Cloudflare processes the encrypted request in transit and Hetzner provides the origin-server infrastructure. Their handling of network and service data is governed by their respective privacy terms.
- You can decline an upload, remove the configured service, or use only private on-device verification at any time. Your signing certificate and password are never uploaded for validation.