Why We Built OneSigner: A Certificate Reseller's Confession
Most product stories start with a founder and a whiteboard. Ours starts at a support desk, reading the same tickets over and over.
Since 2019, One Sign Pte. Ltd. has been a certificate provider and authorized reseller — SSL/TLS, code-signing and document-signing certificates from the world's major CAs, delivered to thousands of customers around the world. Issuing a certificate is the easy part. What happens after delivery is what eventually changed the direction of our company.
The tickets that would not stop
Different countries, different industries, the same four stories:
- The software company. Their OV or EV code-signing key lives on a USB token — as the CA/Browser Forum now requires. Which means every release can only be signed on the one PC where that token is plugged in. The build pipeline cannot reach it. At midnight, someone remote-desktops into an office machine to sign a hotfix by hand.
- The finance team. One document-signing token, three hundred invoices a day. One person typing a PIN into a dialog box, all afternoon, every afternoon.
- The five-person team. Sharing a single token by couriering it between offices — or worse, sharing the PIN in a group chat.
- The compliance officer. They chose a token from their national CA precisely so that documents would be legally valid at home and stay in-country. Then every convenient signing tool they tried wanted the files uploaded to a foreign cloud.
The answer we could have sold
The industry has a standard answer to all of this: cloud signing. Move the key into a hosted HSM, meter every signature, bill monthly. As a reseller we know that business well — and we will be honest with you: it is the more profitable thing to sell. Recurring revenue, per-seal fees, renewals every year.
But we kept doing the arithmetic with our customers. A US$300 certificate, wrapped in thousands of dollars a year of signing fees — to work around the fact that a perfectly good token is stuck in one machine. The cost had quietly moved from the certificate to the meter. For most of the companies we serve, that is not a service; it is a burden.
So we built the other answer
OneSigner turns the token a customer already owns, plugged into a Windows machine they already have, into their own signing service:
- A browser portal for the team, with drag-and-drop signature placement;
- A REST API and watched folders for ERP and zero-code automation;
- A Key-Vault-compatible endpoint so build servers sign releases remotely;
- eSign envelopes for inviting external signers by email;
- And underneath all of it: only the document digest ever reaches the token. Private keys cannot leave the chip, and files never leave the customer's infrastructure.
One payment, unlimited signatures. The legal weight comes from where it always came from — the certificate their own CA issued — under Singapore's ETA, the EU's eIDAS, and the e-transaction laws of each customer's country. OneSigner just removes the friction between that certificate and the daily work.
Where we stand
We still provide cloud and managed signing where it genuinely fits — some teams need it. But when a customer already holds a token from their CA, we would rather sell them a US$99 license once than a meter forever.
That is the whole story, and the whole point. If it sounds like your situation, the how-it-works page shows the architecture in detail — or just try it free for 30 days with the token you already have.