About firmar.ec

Why firmar.ec exists

We want to make certificate-based PDF signing and review accessible from a browser without sending the private key to the service. Tools have different requirements and trust models; our approach is to make ours explicit and inspectable.

firmar.ec solves this with a public, free, registration-free, tracking-free PWA where your private key never leaves the browser.

Who is behind it

firmar.ec is a non-profit open-source project by IDK Manager, a software and technical services workshop in Quito, Ecuador. We build and operate this tool as a contribution to Ecuador’s digital ecosystem.

We charge nothing for the service. There is no premium plan. No subscription. No advertising. No telemetry.

The cost of maintenance (domain, hosting, certificates, code upkeep) is borne by IDK Manager. The guiding philosophy: a critical digital sovereignty tool should not be profit-driven.

Why open-source?

A tool that processes a private key should be inspectable. We publish the source code and AGPL-3.0 licence, tests and development instructions. Inspect the code for the version you are evaluating; an open licence alone does not constitute an independent audit.

Our verification methodology explains what each check demonstrates and which limitations to record. Alfonso Kuen Arroyo’s profile identifies the project’s technical lead.

How does it stay sustainable?

Project status

Consult the published releases, changelog and open proposals to distinguish available features from proposed work. Each signature’s capabilities depend on its configuration, certificate and available evidence.

Contact

Who it's for

Anyone with an Ecuadorian electronic certificate (.p12).

Open source

Audit the code yourself.

AGPL-3.0. Releases signed with Sigstore Cosign + Rekor transparency log + SLSA L2 with L3 elements (signed per-release provenance). Reproducible builds on roadmap.