Three tools, one document

A document gets written, then agreed to, then handed to someone. These are three separate apps because those are three separate jobs -- but they are built on the same idea, and none of them needs a Google account.

Step one

Write it together

Several people in the same document at once, with live cursors and no lost edits. Edits merge with a CRDT, so two people typing in the same paragraph both keep their work -- offline stretches included.

Beside the text sits a discussion that cannot be edited or deleted by anyone, including the owner. What was said about the document stays part of the document's history.

You are here

Step two

Get it signed

Once the wording is settled, the document needs signatures. SignerAuthority handles electronic signing with cryptographic verification -- the content is hashed, the signatures are verifiable, and every action lands in an audit trail rather than a status field.

When an envelope is fully executed, SignerAuthority hashes the signed document and -- where the issuer is set up for it -- issues an Ed25519-signed assertion to MIR Assertions, a separate service, binding that hash to its issuer. Anyone holding the file can hash it and look up what was asserted, without asking SignerAuthority.

signerauthority.com

Step three

Send it sealed

A finished document usually goes to one specific person. Paperseal sends it so that only they can open it -- without making an account -- and a forwarded copy gets nowhere, because opening the link grants nothing until a single-use confirmation reaches the recipient's own address.

You can see who opened it, and revoke access at any moment. No public or pre-signed URLs are ever issued, so revocation takes effect on the very next request.

paperseal.app

What they actually share

The common thread is not the file. It is the record of what happened to it -- who wrote it, who agreed to it, who opened it. Each tool's real output is evidence about a document, and in all three that evidence is append-only: the discussion here, the signing audit trail, and the access log are all written forward and never rewritten.

That is a deliberate constraint rather than a missing feature. A record you can quietly revise afterwards cannot settle an argument later, which is the only reason to keep one.

No passwords, anywhere

All three sign you in with a one-time emailed link, confirmed by a button press rather than by opening the link -- so a mail scanner fetching every URL it sees cannot burn the token or walk into an account.

No third parties in the path

No Google account, no third-party sign-in, no CAPTCHA widget reporting your visitors to someone else. Built and hosted directly, which is the point rather than a detail.