I sign my PDFs (quotes, invoices, CVs) with my own certificate. Your PDF viewer will say the signer’s identity is “unknown”, because I don’t pay a commercial certificate authority. This page gives you everything you need to check that a PDF really comes from me and hasn’t been altered.
Verify a PDF
Drop the PDF below. Every step of the chain of trust is checked in your browser.
How the trust works
My PGP key is the anchor. It’s published independently on keys.openpgp.org and GitHub, so you can check its fingerprint somewhere other than this site.
The PGP key signs the fingerprint of my root certificate (x509.cert.sha512.asc).
The root certificate stays offline. It issues my signing certificate and publishes a revocation list (CRL), so a stolen signing key can be revoked.
The signing certificate signs my PDFs, together with a timestamp from an independent authority that proves when each one was signed.