Skip to main content
LeonAI
PRODUCT 03 · E-SIGN

LeonAI SignFlow

Smart Hebrew-First E-Signatures

Every signed document is digitally sealed and stamped with an RFC-3161 timestamp — with an audit chain that cannot be rewritten. Hebrew and RTL as a first-class citizen.

A PKCS#7 seal on every PDFRFC-3161 timestamp · DigiCertSHA-256 audit chainMake app · 15 modules
ISO/IEC 27001HOSTED ON CLOUDFLARE · GLOBAL EDGE
CAPABILITIES

Everything your business runs

01

Seal and verification

Every completed PDF gets a PKCS#7 digital seal and an RFC-3161 timestamp from DigiCert. If the seal fails, the document does not close. Verification has a dedicated endpoint, alongside an audit certificate detailing IP addresses, browser and operating system, times and the signing route — per ICT Authority directive 180123-1.

02

Audit chain

Every event in the process enters a SHA-256 hash chain that is also anchored outside the system. A retroactive change breaks the chain, and that shows immediately in verification.

03

Gates before signing

You can require each signer to enter a one-time email code — six digits, valid for ten minutes, five attempts — a signing password and a read confirmation. Each gate is switched on separately, by document sensitivity.

04

Multi-signer signing ceremonies

Sequential or independent signing for any number of signers, with per-signer fields and a mobile-friendly ceremony on any device.

05

AI-powered field auto-detect

Automatically finds where signatures, dates, and signer details belong — even on scanned documents — no manual setup required.

06

Hebrew, in depth

A BiDi engine written specifically for PDF, the Noto Sans Hebrew font embedded in the file itself and a fully translated interface. A Hebrew document stays aligned and readable after signing too.

07

Integrations

A Make app with 15 modules and an instant trigger, and 17 webhook event types signed with HMAC and protected against SSRF.

08

User management

Sign in with Google or Microsoft, TOTP two-factor authentication and enterprise SSO with SAML or OIDC.

HOW IT CONNECTS

How a document flows through SignFlow

The Make app and webhooks feed and receive events from SignFlow; the document itself goes out to the signers by email.

Make
15 modules
Webhooks
17 event types
LEONAI SIGNFLOW
Signers
Received by email
PRICING

Pricing that is simple and clear

Free
/month · ex-VAT
Starter
49
/month · ex-VAT
Pro
129
/month · ex-VAT
Business
249
/month · ex-VAT
Enterprise
799
/month · ex-VAT

One-time top-up, valid for 12 months. Available on all paid plans.

Add-ons

Add only what you need. Monthly, on top of the plan.

  • Custom domain + custom email domainIncluded in: Business, Enterprise₪49
  • Unlimited AI smart detectIncluded in: Enterprise₪49

Prices are before VAT. Credit packs can be added on any plan.

SECURITY & HOSTING · VERIFIABLE

Built to pass security reviews

The questions your IT and compliance teams will ask — answered up front.

  • Files sit behind an authenticated, fail-closed proxy — no public storage bucket and no pre-signed links.
  • A fail-closed PKCS#7 seal: a document does not complete without a valid seal.
  • An RFC-3161 timestamp from DigiCert on every completed document.
  • A SHA-256 audit chain with anchoring outside the system and a verification endpoint.
  • Documents retained for seven years by default, with deletion refused within the period.
  • An Israeli tax-compliance mode.
  • Google/Microsoft sign-in, TOTP two-factor authentication and SSO with SAML/OIDC.

ISO/IEC 27001

ISO 27001 certified.

HOSTED ON CLOUDFLARE · GLOBAL EDGE

SignFlow runs on Cloudflare's global edge network

Full security page
FAQ

Questions that keep coming up

How do I know a signed document was not changed afterwards?

Every completed document is sealed with a PKCS#7 digital seal and stamped with an RFC-3161 timestamp from DigiCert, and every event in the process enters a SHA-256 hash chain that is also anchored outside the system. Changing a single character in the document or the chain breaks verification — and there is an endpoint that checks exactly that.

What is required of a signer?

The document reaches the signer by email, and identification rests on the gates you enabled: a one-time code to the email address, a signing password and a read confirmation. Every signature is recorded in the audit certificate with the IP address, the browser and operating system, and the time.

How deep does the Hebrew support really go?

Down to the PDF engine. We wrote our own BiDi engine and embedded Noto Sans Hebrew inside the file, so the Hebrew does not break after signing, and the entire interface is translated.

How does billing work?

The subscription is billed through Sumit. When the flow includes a payment by the signer themselves, it is collected with Pelecard or PayPlus.

Smart moves — it’s in our nature

Want to see SignFlow at your company?