Documents & signing
Generate, sign, and prove trade documents.
Sixteen commodity trade document types, generated from a guided wizard, signed with a tamper-evident hash chain, and verifiable by anyone with the link. No blank pages, no unsigned Word files, no doubt about whether a signature is real.
16
Document types
HMAC-SHA-256
Signature hash chain
RFC 3161
Trusted timestamp
Public
Verification page
Why it matters
Built to be believed.
No blank pages
Every document starts from an industry-standard template with the right fields, so you fill in the deal, not the format.
Tamper-evident by math
Each signature is hashed and chained to the one before it. Alter, reorder, or remove a signature and the chain breaks.
Counterparties sign in place
Invitees sign from an email link bound to their party role. No account, no app download, no impersonation.
Generation
16 templates, built for commodity trade
From the first offer to the bill of lading, every standard document is a guided template with per-field AI assistance, so a complete, professional draft takes minutes.
- Compliance and offer documents: ICPO, FCO, SCO, LOI, MOU, NCNDA, NDA, IMFPA, CIS, KYC, SPA
- Commercial documents: Commercial Invoice, Proforma Invoice, Packing List, Bill of Lading, Air Waybill
- Per-field AI generation writes realistic, deal-specific clause text
- Mutual, single, or upload-only signing rules applied automatically per document type
Document templates
16 typesGuided wizard · per-field AI assistance
Signing
Signatures you can prove later
Signatures are sealed with an HMAC-SHA-256 hash chain. Each one carries the previous signature's hash, so the whole sequence is verifiable and any tampering is detectable.
- Each signature linked to the last in a verifiable chain
- An independent RFC 3161 timestamp from a public authority binds a trusted time to the signed content
- Optional access-code step-up signing on any paid plan
- Signed documents lock to preserve integrity, enforced in the database
- Void with a recorded reason when a signed document must be retired
Signature chain
Tamper-evident- Buyer: J. Okafor
HMAC a3f9…d21c
- Seller: A. Reyes
HMAC 7b2e…9f04
Each signature linked to the last
Sharing & proof
Verifiable by anyone, no login
Share by link or email, export to PDF with an embedded verification QR code, and let any counterparty, auditor, or bank confirm a document is genuine and unaltered.
- PDF export with an embedded verification QR code and printed link
- Email-bound share links with optional expiry and access codes
- Public verification page validates the signature chain independently
- Link documents to deal rooms and counterparties for a full record
Public verification
Verifiedtradeflow-os.com/verify/document/8f2a…
Teams
One shelf your whole team can reach
On Business and Enterprise, the Vault is a shared shelf for the documents a team keeps coming back to: shelve one you generated here, or upload an external file, and link either straight into a deal.
- Shelved generated documents stay references, never copies, so the original is untouched
- Uploaded files live in private storage and are read through short-lived signed links
- Any member can add; a member manages what they added, and an org admin manages anything
- Every add, rename, reclassification, and removal is recorded in a trail the whole team can see
Team Vault
3 seatsAssay report Q3.pdf
Uploaded · added by Priya
SPA - Rotterdam
Generated · added by You
Certificate of origin
Uploaded · added by Marc
Marc removed Draft LOI.docx · 2h ago
How it works
From start to proof.
Pick a document type
Choose from 16 templates, or describe the deal and let AI assemble the draft for you.
Fill and refine
Complete the guided wizard with per-field AI assistance and an AI quality score before you send.
Invite parties to sign
Define each signing party and invite them by email; everyone signs as their assigned role.
Share and verify
Export a PDF or send a link. Anyone can verify the signature chain on the public page.
FAQ
Common questions.
Does TradeFlow read the files I upload?
Yes, with self-hosted OCR. Uploaded deal and passport files are read on our own servers to power advisory checks (expiring certificates, quantities that disagree with your deal terms, duplicate or unreadable files, and document-type suggestions) and full-text search across your uploads. The extracted text is encrypted at rest and is never sent to any AI provider or external partner.
What makes the signatures tamper-evident?
Every signature is sealed with an HMAC-SHA-256 hash and chained to the signature before it. Removing, reordering, or editing any signature breaks the chain, which the public verification page detects. Signing also records an RFC 3161 timestamp from a public Time Stamping Authority over the content hash, so an independent third party attests to when the document existed in that exact form.
Is a signature here legally binding?
That depends on the governing law of your contract, and it is a question for your counsel rather than for us. What we can tell you precisely is what the signature proves: the content has not changed since signing, the order of signatures is intact, a trusted third party attests to the time, and the signer controlled the invited mailbox. What it is not is a qualified electronic signature under eIDAS or a certificate-backed digital signature, and we do not claim either. Our published signature methodology sets out the mechanism and its limits in full.
Do counterparties need an account to sign?
No. Signers receive an email link bound to their specific party role and sign in place. They cannot sign as anyone other than their assigned party.
Can a document be verified by an outside party?
Yes. Every document has a public verification page, and exported PDFs embed a QR code and link so a bank, auditor, or counterparty can confirm authenticity without logging in.
Can my team share documents with each other?
Yes, on Business and Enterprise, through the Vault: a shared shelf where any member can upload an external file or shelve a document generated here, and anyone on the team can find it and link it into a deal. Because a shared shelf means a colleague can remove your entry, every add, rename, reclassification, and removal is written to an activity trail the whole team can read, including who did it and when.
Which documents require both parties to sign?
Mutual documents such as the SPA, MOU, NCNDA, IMFPA, and NDA require buyer and seller signatures. Offer documents need a single signature, and commercial documents are upload-only.