Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Let's Seal

Let's Encrypt for document signing, free and self-hosted

Details

External ID
49071365
Source
HN
Company
—
Product
Seal
Website domain
github.com
Launched
July 27, 2026
Cohort
—
Upvotes
94
Upvotes percentile
0.9056152927120669
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

TLDR, Let's Seal gives the finger to Adobe and every doc signing tool (docusign, google, etc) who pay to play with the Adobe Approved Trust List and then charge you for something that should be free.Currently even the person checking if a document/contract is sealed or code is authentic has to also be inside the same Adobe walled garden too. Verification, the part that should be free is the part everyone charges for. Thats the shape Let's Encrypt fixed for TLS, and I wanted the same thing for documents and files.The core idea therefore needed to go a bit beyond e signatures and i created an open standard (SEAL), plus free tools that implement it.When you seal a file, three independent things happen.1. it gets a signature from a certificate authority, chaining to a public root. 2. its record is appended to an RFC 6962 transparency log. and 3. its SHA256 is timestamped on a public blockchain (Bitcoin) via OpenTimestamps. Those three give you integrity, transparency and a timestamped proof. And importantly, none of those depend on Let's Seal and none are gated.You can verify with the tools you already have, no Let's Seal account and no Let's Seal software. A sealed PDF carries a standard PAdES signature, so any PDF reader validates it. A sealed build artefact carries a cosign compatible signature and a SLSA provenance attestation. The Bitcoin timestamp verifies with stock ots.3 ways to use it.1. The free web app. We kindly have backing from Backblaze to cover storage costs for the foreseeable. So you can upload or issue any number of documents, get a public proof page at /d/<hash> and verify it at https://verify.letsseal.org for free. Multiple accounts, multiple seats, enterprise functions. Free.2. Self host the whole thing. Apache-2.0, one Next.js app plus a signing service that holds the CA key on localhost. Storage is any S3-compatible bucket or local disk. If you'd rather run your own root of trust, you can.3. Programmatically. via the CLI and a hosted API. This is the Let's Encrypt/certbot angle. Seal or anchor things from CI, or have a backend seal every invoice or report as its generated.The CLI is sealbot. It runs anywhere Node runs (npx sealbot) and there are native binaries for macOS, Linux and Windows with no runtime needed.Theres a GitHub Action wrapping the same tool, so a release workflow can seal its own artifacts. Its what proves our own releases.KYC is semi-handled (to a degree) it's hard to do for free (at least for now), but issuers (your companies or websites) domains can be authenticated with a DNS record added, which proves the issuer has control over a domain. Sign-in can be authenticated to an email via Google Sign in and a few others will be added to the web app in time (Same as Docusign currently). Ideas welcome on future KYC should there be a demand.Feedback welcome on the standard (SPEC.md in the repo).Repo: https://github.com/letsseal/letsseal Site: letsseal.orgThx

Enrichment

Theme
self-hosted infrastructure and security tools
Vertical
Legal
Function
Vertical SaaS
Audience
B2B
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
free self-hosted document signing
Manually corrected
False

Could you build this?

Partial The UI and basic cryptographic document signing (PDF digital signatures via PKCS#7/PAdES) can be vibe-coded, but setting up a widely trusted, compliant PKI/CA infrastructure like Let's Encrypt is a hard cryptographic and trust-governance problem.

What it would actually take: A real version requires implementing standard PDF signature specifications (ISO 32000 / PAdES / RFC 3161 timestamping) combined with an automated certificate management protocol (ACME-like) and cryptographic key infrastructure (HSMs or KMS). The hardest part is operating a trusted root or establishing trust anchors that PDF viewers accept without security warnings, requiring deep knowledge of X.509 PKI, cryptographic hardware, and trust store requirements.

Discussion

20 comments analyzed.

Competitors mentioned: DocuSeal, DocuSign, Adobe, ProofOfExistence.com, Open Claiming Protocol

Concerns raised: Does not meet EU qualified signature/seal requirements, Self-hosted model undermines trust anchor value vs centralized entity, No legal entity accountable for verification or culpability, Bitcoin dependency raises environmental concerns, Lacks third-party security review and validation

Feature requests: Support RFC 3161 timestamping as optional feature, Integrate certificate transparency logs for PKI-based proofs, Use alternative blockchain (Ethereum vs Bitcoin), Embed validation info for LTA (Long Term Archival), Support Open Claiming Protocol interoperability

Competitors

Other products that read as similar to this one — 261 launches clear the similarity bar, closest 8 shown.

Attention rank: #17 of 262 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 270 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a vertical saas tool for Insurance yet.