EST · ADDIS ABABA · 2026

Misikir Digital Trust

We Provide Trust

Building Ethiopia's financial trust infrastructure. From secure document signing to becoming the nation's first Sub-CA under the Ethiopian National Root Certificate Authority, we engineer confidentiality, integrity, authentication, and non-repudiation for banks,MFIs, and payment systems.

Enter the Vault
CIAN · Four Pillars

The Four Locks

Every trust relationship is built on four immutable pillars. We engineer each one.

The Vault

Confidentiality

End-to-end encryption, tenant-isolated data planes, and FIPS 140-3 Level 3 HSM-backed key custody. Your documents never touch our application keys. We do not hold signing keys; we orchestrate them.

Technical Commitment
AES-256-GCM | Tenant Isolation | mTLS Everywhere
The Keystone

Integrity

Deterministic hash lineage from upload to seal. SHA-256 original → prepared → signed. Any tampering invalidates the chain immediately. Our preparation pipeline rejects encrypted or malformed PDFs before signing.

Technical Commitment
SHA-256 Lineage | ByteRange Integrity | PAdES Compliance
The Key Ceremony

Authentication

All humans authenticate via OIDC/SAML federation with ABAC-RBAC resolution; machine clients use OAuth2 or mTLS. Every request carries mandatory tenant context and correlation ID. Privileged actions require WebAuthn step-up, logged to the hash-chained audit trail.

Technical Commitment
Federated Human Auth | Machine Client Auth | X.509 v3
The Chain

Non-Repudiation

Append-only audit trails with cryptographic chaining. Every event carries a previous_hash and event_hash, creating a tamper-evident linked list. Evidence packages are sealed and legally admissible under Proclamation 1072/2018 and ETSI.

Technical Commitment
Merkle Audit | RFC 3161 Timestamp | Legal Hold
System Boundary

Trust is Externalized

We built a control plane, not a shadow CA.

01 · Application Plane
SignOrc
Signature OrchestrationSVC
Document PreparationSVC
ValidationSVC
Audit & EvidenceSVC
Public Verification EdgeSVC
03 · Trust Core
PKI + Our Trust Signing Core
Hardened
HSM — Thales Luna 7FIPS-140 Level 3
National Root CAINSA
Issuing CATrusted CA
Misikir Trust Signing Core (MTSC)Signing Engine
Hash Lineage
a3f7c91b8e2d4f6a → prepared:b9c2..1f0a → signed:7e44..d28c → sealed:fa01..9e2d
SHA-256 lineage · deterministic · tamper-evident

SignOrc is a document signing control plane. It orchestrates signing workflows, enforces policy, and seals evidence. But the actual cryptographic signing, certificate issuance, and key custody live inside hardened trust-core services. This is not an architectural preference — it is a regulatory mandate. We do not hold your keys. We hold your trust.

Products & Services

Capabilities

Cryptographic trust for Ethiopian banks, MFIs, and payment systems.

Pre-Launch

SignOrc

Enterprise Document signing and workflow orchestration for Ethiopian banks. PAdES-compliant PDF sealing with sequential, parallel, and countersignature flows. Integrated with external and domestic CAs. Evidence packages are sealed and legally admissible under Proclamation 1072/2018 and ETSI.

Future Services

HSM Integration

Payment HSM deployment and management. ATM PIN translation, card key generation, and 3D Secure authentication. Local expertise for Thales payShield and Utimaco PaymentServer.

Learn More
Future Services

RegTech Automation

Automated NBE prudential reporting with cryptographic integrity. Hash-based tamper evidence before submission. Digital signature of regulatory filings using National PKI.

Learn More
Future Services

Digital Certificate

Digital certificate issuance and management. Sub-CA under the Ethiopian National Root CA for high-assurance certificates for the financial sector.

Learn More
Future Services

PKI Enabling Services

PKI enabling your existing applications. We integrate your existing systems with the National PKI for secure authentication, encryption, and digital signatures. From document signing to secure email, we provide the cryptographic backbone for your enterprise.

Learn More
Future Release

Digital Identity & KYC

Remote customer onboarding with Fayda ID integration, biometric liveness, and cryptographic consent capture. Non-repudiable identity binding for account opening.

Learn More
Phased Ascent

The Trust Construction

A phased ascent from software vendor to national trust anchor.

01

Foundation

Now

SignOrc operates as a document signing workflow platform which can be integrated with recognized foreign or domesticCAs. Banks use our software to sign, validate, and archive. Evidence packages are sealed and legally admissible under Proclamation 1072/2018 and ETSI.

02

Construction

Future Goal

Facility construction, HSM procurement, and trust core development. SignOrc is integrated with the trust core for cryptographic signing and evidence sealing. The facility is going to be hardened, audited, and certified.

03

Operation

After Construction

Licensed Sub-CA under the Ethiopian National Root CA. Issuing Class 3 High Assurance certificates. Public Verification Edge live. DR site operational with 6-hour RTO.

0
Signing keys held in application memory
6
Trust-core adapters with contract tests
4
Deployment profiles: SaaS, Dedicated, Hybrid, On-Prem
100%
Evidence-first architecture. Signed PDF is the output; the evidence package is the product.

Designed for Ethiopian banking regulation · Built for bank-grade audit

Begin

Ready to Seal Your Documents?

Join Ethiopia's financial institutions in adopting cryptographic trust. Whether you need document signing today or PKI consulting for tomorrow, we provide the trust layer.