Khatm
FAQ · Khatm
Every answer, in one place.
Product, API, demo, production, trust, languages, data and pricing: short answers to the questions we hear most.
Product
What is Khatm?
Khatm adds PDF signing to your software, under your brand, in Arabic, French and English. The same engine is available from the web platform, with no development, and through the REST API v1, built into your product.
Who is Khatm for?
B2B software vendors that need documents signed inside their product: SaaS, HR software, customer portals, CRM and ERP, property software. Khatm focuses on products used in Morocco and the Gulf.
Can I use Khatm without development?
Yes. The web platform lets you prepare a PDF, add signers, place fields, send and track requests. Templates you prepare in the platform can then be reused through the API.
Can Khatm replace DocuSign?
It depends on your need. An established suite remains a good choice for internal sending. If signing must be part of your product, under your brand and in Arabic, an embedded engine like Khatm is often a better fit. Our guide lists the criteria to check.
API and sandbox
How do I integrate Khatm into my application?
With the REST API v1: you create a request (PDF, signers, fields or a template), activate it, then track its status and download the signed PDF and evidence. Your product keeps its interface; Khatm runs the signing flow.
How do I test the API?
The sandbox is self-serve: create an account, generate a test key (khatm_test_…) and follow the quickstart in the documentation. You test the complete flow, from requests to signed files.
How does my product know a document is signed?
Through a webhook. Khatm sends a signed event (HMAC-SHA256) when a request is completed, declined or cancelled, with your client reference. You can also check a request’s status at any time.
What are the limits of a request?
Up to 10 signers and 100 fields per request, and a PDF of at most 8 MiB. In the sandbox, content is deleted 10 days after the PDF upload, even if signing is not finished.
Demo and production
What can I do with the demo?
Without an account, you upload a PDF (or the sample one), place fields, add signers and get a genuinely signed PAdES PDF with its evidence report. The demo uses a self-signed test certificate.
Why does my PDF reader show a warning?
The demo and sandbox certificate is self-signed: it belongs to no public chain of trust, so an “unknown identity” message is expected. In production, the certificate comes from your trust service provider. Do not turn off your reader’s checks.
Self-signed or trusted certificate
How do we go live?
With our implementation support, in five steps: scoping your use case, adapting the flow and branding, integrating with your developers, connecting identity and certificates, then a gradual rollout.
Which certificate is used in production?
The one from the infrastructure chosen for your project: your PKI, an HSM or a trust service provider. Khatm does not issue certificates. RFC 3161 timestamps are added when your provider supplies them.
Trust and legal value
Is Khatm a qualified trust service provider?
No. Khatm orchestrates PDF signing and issues neither qualified signatures nor certificates. The signature level depends on the certificate and identification chosen for your project.
Does a signature made with Khatm have legal value?
It depends on the certificate, signer identification, the type of document and the country. The demo validates the technical flow, not legal value. For your documents, check the applicable requirements with your advisers.
Are Nafath or UAE Pass included?
No, not by default. If your use case requires national identity, connecting it is planned as part of the integration, with the provider concerned.
What is a PAdES signature?
A cryptographic signature embedded in the PDF: it protects the integrity of the whole document, reveals any later change and shows the certificate used. It is very different from an image of a signature pasted into the document.
Languages and branding
Which languages can my signers use?
Arabic, French and English, natively. Arabic is displayed right to left across the whole flow, not only in translated text.
Can I choose each signer’s language?
Yes. A signer’s locale field (fr, en or ar) sets the language of their signing page and invitation e-mails. Without it, the page follows the browser language.
Do you offer white label?
Yes, as part of an integration project: the flow, e-mails and appearance carry your brand. Through the API you can already set the sender name, message and logo of invitations. There is no self-service white-label offer yet.
Data and security
How are documents protected?
PDFs are encrypted at rest (AES-GCM) and their SHA-256 digest is kept. Each request has an activity log and an evidence report. The JSON evidence contains no IP address or user-agent.
How long are documents kept?
In the demo and sandbox, 10 days after the PDF upload, then content is deleted. Download the signed PDF and evidence before that date. In production, the retention period is agreed with you.
Do I need a password?
No. You sign in with a magic link sent by e-mail or with a passkey. Google sign-in is offered when it is enabled.
Which document should I test with?
The sample PDF offered in the demo, or a fictitious document. Do not use real or confidential data in the demo or sandbox.
Pricing and implementation
How much does Khatm cost?
There is no public price list. The cost depends on your scope: application, volumes, languages, connections and signature level. You first build your integration in the sandbox, then we prepare a proposal after scoping.
Should we build signing ourselves?
Building means mastering PAdES signing, certificate management, evidence and maintenance. Integrating an engine lets you keep your interface and focus on your product. Our guide compares both approaches.
Where do I start?
Try the demo, test the API in the sandbox, then write to us with your application, a sample document, your signers and volumes. We come back with a scoping proposal.
Can’t find your answer?
Write to us with your question or project: we answer directly.
contact@khatm.io