Pricing is published — Personal is free, and Family is R99/month for a household of 5 (R79/month billed annually). Every price includes VAT. See pricing
Sign in Start free
Security & trust

Here's exactly how KuduDoc protects your documents.

Every document you complete gets three independent, checkable proofs — explained in plain language below, including precisely what each one protects against. No badge walls. No invented stats. And further down, a plain account of what we don't claim yet.

Tamper-evident SHA-256 fingerprinted OpenTimestamps anchored

Personal plan available · Hosted in South Africa · The ECT Act recognises electronic signatures as a class — it does not accredit KuduDoc, and we are not an accredited provider. What we don't claim

How verification works

Three independent proofs, on every completed document.

Each one checks something different. Together, they mean nobody — including KuduDoc — can quietly alter a signed document without it being detectable, and none of them require a KuduDoc account to check.

Proof 1 of 3

Certification signature (DocMDP)

When every party finishes signing, KuduDoc applies a certification signature to the file using DocMDP (Document Modification Detection and Prevention) — a mechanism built into the PDF standard itself, not something KuduDoc invented.

What it protects against. Any change afterwards — a swapped page, an edited clause, even a single altered byte — breaks or flags the certification. That's true in any PDF reader, not just KuduDoc's.

How to check it. Open the file in a PDF reader that displays signature panels, or drop it at /verify — free, no KuduDoc account required.

Certification signature
Method
DocMDP (PDF certification signature)
Applied
The instant every party finishes signing
Detects
Any change to the file, however small
Check it
Free at /verify, or any PDF reader
Being straight with you

Tamper-evident, yes. Adobe-trusted — not yet.

KuduDoc's certification signature is currently self-signed. Here's exactly what that means, and what it doesn't.

Open a KuduDoc-signed PDF in Adobe Reader today and you'll likely see something like "signature validity unknown" — not a green trusted checkmark. That's expected, and it's true for a specific, checkable reason: the certificate isn't yet in Adobe's trusted root list. It doesn't mean the file might have been altered. Those are two different questions.

Has this file changed since it was signed?

This is what the certification signature answers, and it doesn't depend on who issued the certificate. It's cryptographic math: either the file's current bytes match what was certified, or they don't. A self-signed certificate does this exactly as reliably as one issued by a trusted authority — tamper-evidence isn't a trust-list feature.

Do PDF readers trust the identity behind it?

This is a different question — whether the certificate is on a trust programme like Adobe's Approved Trust List (AATL), the way a browser trusts a bank's SSL certificate. KuduDoc's certificate isn't on that list yet, so readers correctly show it as unverified. Not because the file might be altered — because they don't yet recognise who issued it.

What you might see today

Signature panel — generic PDF reader
Signature validity unknown

"The signer's identity has not been verified — the certificate isn't in this reader's trusted list."

Expected, right now — and it's the honest state of things.

What independent verification shows

/verify result
Unchanged since sealing

Unchanged since signing. SHA-256 fingerprint matches the file on record, and the OpenTimestamps anchor is confirmed.

This part doesn't depend on any trust list at all.

Why we're telling you this: tamper-evidence and trusted-CA validation are genuinely different guarantees. We could describe only the reassuring one and let you assume the other. Instead we're telling you both, and pointing you at /verify so you can check either one yourself — independent of anything written on this page.

Joining a trusted root programme is on our roadmap. We'll update this page the day it's true, not before.

Data residency

Hosted in South Africa. Built with POPIA in mind.

Where your documents live and how your data gets handled matters — especially for leases, employment contracts and other documents with real legal weight.

Hosted in South Africa

Documents and account data are stored on infrastructure located in South Africa — not routed offshore by default.

POPIA-minded from the ground up

The Protection of Personal Information Act shapes how we collect, store and process personal information — considered from the start, not retrofitted after the fact.

You can access, export or delete your data

Your documents and account information are yours to retrieve or remove — reach out and we'll action it directly.

There's no "POPIA-certified" badge to show you here — the Act doesn't work that way. Compliance is an ongoing practice enforced by South Africa's Information Regulator, not a one-time certificate a company earns. What we can do is describe our practices plainly, and correct this page the moment anything changes.

Nothing to hide

What we don't claim — yet.

KuduDoc is a young product. Being upfront about what isn't true yet matters just as much as what is. Expand each one.

No customer counts, logos, or "trusted by" claims

We don't publish user numbers or a client logo wall. If we ever do, it'll be a real, sourced figure — not a rounded-up marketing number.

No ISO 27001, SOC 2, or GDPR certification

We don't hold these yet. KuduDoc is built around South Africa's POPIA, not GDPR, and we're not going to hang a certification badge we haven't earned. If that changes, we'll link the actual certificate here — not just say the word.

No "bank-level security" talk

It's a phrase with no fixed meaning or standard behind it. We'd rather tell you exactly which mechanism protects what — that's the entire point of this page.

No Adobe-trusted checkmark

Covered in detail further up this page: KuduDoc's certification signature is tamper-evident, but it isn't yet in Adobe's trusted root list, so readers show it as unverified. That's expected, and we're not dressing it up as something else.

No ECT Act accreditation, and no Advanced Electronic Signature

The ECT Act recognises electronic signatures, and a KuduDoc signature is an ordinary one — captured with consent and intent, with an audit trail and a seal behind it. That recognition attaches to the signature, not to us: no provider is "ECT Act certified", and the Advanced Electronic Signature is a separate category the Act reserves for accredited providers, which we are not. Some documents are off electronic signing altogether — Schedule 2 keeps wills, bills of exchange, sales of land and leases over 20 years on paper, and a suretyship needs the advanced signature we don't offer. Sign those in ink; you can still seal the scan here afterwards.

No invented statistics

Every number on this site is either independently checkable — like a SHA-256 fingerprint or a timestamp anchor — or it simply isn't published.

Try it yourself

See it for yourself. Verify a document, free.

No account needed. Upload any completed KuduDoc document and check all three proofs yourself, in under a minute.

Personal plan available · Hosted in South Africa · The ECT Act recognises electronic signatures as a class — it does not accredit KuduDoc, and we are not an accredited provider.