Questions we get asked before every rollout.
Straight answers, including the parts where the product has limits. Links jump straight to the deeper explanation on the other pages where one exists.
General
Is the digital signature legally valid?
Yes. Signatures use the PAdES standard (PDF Advanced Electronic Signatures) with SHA-256 digests and PKCS#11 hardware tokens, and carry the signing reason, location and time in the signature dictionary. They are valid under the IT Act, 2000 in India.
Which DSC tokens are supported?
All the major Indian DSC tokens: Watchdata ProxKey, Feitian ePass (including Hypersecu and EnterSafe), M-Token CryptoID, SafeNet eToken and InnaIT (Precision InnaIT). The app auto-detects any token presenting a PKCS#11-compatible driver.
Can I sign without a USB token?
For a document you sign and send yourself — a PDF invoice, agreement, letter or report — yes: choose “Sign with PFX/P12”, point at your software certificate, and sign. No token is needed for that document.
The token becomes mandatory as soon as the document is filed on a portal. The majority of Indian government and enterprise portals that accept a DSC — Income Tax e-filing, MCA21, the GST portal, EPFO, GeM, and state RERA and tender portals — sign only through a USB hardware token plugged into your machine. They do not accept a PFX/P12 file, and the Aadhaar-OTP based eSign route is not accepted for that filing either.
So the split is simple: PFX for the PDFs you sign yourself, USB token for anything that has to be signed on a portal. The rule is stated in full here.
Does signing modify my original PDF?
No. Flash Turbo Signer uses incremental saves: the signature is appended to the file without rewriting the original bytes. Your source document is preserved, and the signed copy is written separately.
Does it work completely offline?
Yes. There is no account, no licence server call during signing, and no document upload. The one optional outbound request in the entire product is the RFC 3161 trusted timestamp, and you only enable that when a document needs it.
Security and privacy
Where is my token PIN stored?
The PIN is passed straight to the token driver and held in memory for the current session only — it is never written to disk in plain text, and the logging engine redacts it from every log line. If you deliberately enable caching across restarts, the stored value is encrypted with Fernet.
Do my documents leave my computer?
No. Documents are read and written locally. There is no telemetry, no usage reporting, and no cloud component. Certificate chains are validated against the trust store bundled with the application, so validation works with the network cable unplugged.
Why does Adobe Reader say “Signature Not Verified”?
Adobe validates a signature only if it trusts the signer's certificate chain. Indian chains (CCA India → Capricorn / eMudhra / SafeScrypt / (n)Code / IDRBT) are normally trusted automatically. If yours is not, install your DSC provider's root certificate into the Windows Certificate Store. Note also that some older PDF viewers do not support PAdES signatures at all — check the signature panel rather than relying on the banner alone.
The same explanation, with the verification options, is on the compatibility page.
What does the application send over the network?
Nothing by default — no usage reporting, no document upload, no account check. If you switch the RFC 3161 timestamp on, the request that leaves the machine carries a hash (the message imprint) of the signature, which is what the timestamp protocol requires; the document itself is not sent. That single request is the only outbound traffic the product makes, and it is off until you enable it.
Signing in practice
Can I place the signature exactly where I want?
Yes. Drag the stamp anywhere on any page, resize it before signing, or snap it to a preset corner. On PRO and above you can also drop the word “Sign Here” into a template and let text-anchor placement find that spot on every future document.
Can more than one person sign the same document?
Yes, on every tier. Add each signer, assign their certificate, and place a stamp for each one — every stamp is signed with its own assignee's certificate. On the free tier the total is capped at 5 stamps per document; PRO raises that cap to 999.
Can I prove when a document was signed?
Enable the RFC 3161 trusted timestamp (the --tsa flag in the
CLI, or the timestamp switch in the UI). That is the only step that needs
internet; if the time source is unreachable, signing continues with a clear
warning rather than failing.
Can I verify a signed PDF later?
Yes — every tier includes signature verification. It reports whether the signature covers the whole document, whether the file has been altered since signing, and the details of the certificate that signed it.
Can I share my stamp layout with colleagues?
Yes. Templates are saved as .signscript files in a standard
JSON format, so they can be shared by email, USB drive or a network folder,
then loaded from the Stamps tab. Be aware that a template designed for one
document layout can place stamps oddly on a differently structured PDF —
check the placement before signing.
Automation and volume
Is there a command-line interface?
Yes. flash-signer tokens lists connected tokens,
flash-signer certs lists their certificates, and
flash-signer sign <pdf> signs a document with options for
token brand, stamp style, reason, location, target page, output path and
timestamping. It is the same signing engine the GUI uses, so an unattended
job produces byte-for-byte the same kind of signature.
How does batch signing work?
The SDPE batch engine (ENTERPRISE) takes a folder or list of PDFs and signs the set in one run, with progress tracking, checkpoint recovery if a run is interrupted, and a CSV report of the results. Volume throughput depends on your token and document sizes; official benchmarks for large-scale runs are still being measured.
Does the app need administrator rights to install?
It installs like a normal Windows desktop application and runs entirely on the local machine — there is no server component, database service or background agent to provision. Your token's own PKCS#11 driver must be installed, exactly as your DSC provider supplied it.
Timestamps
Which timestamp authority is used, and is it an Indian one?
Timestamping is standard RFC 3161, through the public timestamp authorities configured in the application, with a fallback if the first one is unreachable. An Indian CCA-licensed timestamp authority is not wired in yet — that integration is planned, and until it lands you should treat the timestamp as proof that the document existed at a given moment, not as an Indian-CA stamp.
If a filing specifically requires a licensed Indian TSA stamp, tell us — it changes the scope, and the current release will not produce it.
What happens if the timestamp server cannot be reached?
Signing continues, with a clear warning that the timestamp was not embedded. The signature itself is still valid — the timestamp is an addition to it, not a dependency. Nothing else in the product contacts the network.
Editions, limits and support
What exactly changes between FREE and PRO?
FREE gives you 5 stamps per document and a free-edition watermark — but the same valid signature and all six stamp styles. PRO raises the cap to 999 stamps, removes the watermark, and adds reusable templates, document-type auto-detection, text-anchor placement, per-signer reason and location, and reusable placement scripts. The three editions side by side.
Can I upgrade later?
Yes. Request a licence key from [email protected], then enter it under Settings → General → License Key and restart. Your settings, templates and session data carry over.
What are the honest limitations today?
- Windows desktop is the packaged, supported target; there is no shipped macOS or Linux build.
- Document classification currently uses source folder, filename and PDF metadata signals — the keyword and OCR stages are not implemented yet.
- Verification covers modern PAdES signatures only; legacy SHA-1 signed documents are not validated.
- Hot-folder auto-processing and OS trust-store integration are on the roadmap, not in 4.2.
- Stamps are text-only today: QR codes and logo or seal images are not implemented in 4.2.
- Timestamping uses public RFC 3161 authorities; an Indian CCA-licensed TSA is not wired in yet.
How do I get help?
Email [email protected]. Full
documentation and the built-in help book (press F1 in the app)
cover token setup, shortcuts and troubleshooting. Debug logs live at
%APPDATA%\FlashTurboSigner\logs\ — attach the log file and it is
usually obvious what the driver reported.
Anything still unanswered?
Email the question. If it is one a client will ask again, it belongs on this page — and it will be added with a straight answer, limits included.
- Free edition, no account required
- Test on one document before a bulk run
- Windows 10 and 11