Trust and signatures
Who may sign. Signing in is not a signature. What a file you send contains. How a stranger checks it without us.
Who signs what
People sign. Software never does. Staff never do.
| Line | Who signs |
|---|---|
| What the owner claims, what they did, hours they accept | The owner, or someone acting for them |
| A survey Finding | The surveyor |
| Work a yard performed | The yard, when that ships |
| A sale of the book | Seller and buyer, when that ships |
| A file sent to an insurer | The owner shares; the insurer signs nothing |
| A suggestion from software | Nobody, until a person accepts and signs the result |
Every signature shows how sure we were who signed. Basic is an email and a sign with your phone. Verified is a stronger check. Concept Stronger identity later, only if a party requires it.
Closed alpha In the alpha a surveyor's Finding on the labelled demo is signed on the phone with a stand-in key, under a stand-in identity, and every page says so. No yard has signed through the product yet. In progress An owner or invited surveyor signs with their phone. No phone sign, nothing signs. Devices never sign. Usable once sign-in is on. Sale and insurer rows describe the rule, not a shipped flow; see the roadmap.
A session is not a signature
Signing in tells the door who you are. Signing a line is a separate act on one thing.
- A signed-in session opens the door. It never produces a signature.
- The sign-in service says who may enter. It holds no signing key and never signs.
- A person signs. The phone never signs on its own.
- Nothing is labelled signed unless the signature still checks.
In progress Sign-in is by invitation and a waitlist. Identity only. With the lock on, visitors sign in before a private page or a write. A file you send stays readable without an account. Sign-in opens on Email and Send code. A session still signs nothing.
Three labels
- Signed by a professional (verified identity) — a surveyor or a yard signed it with their own key.
- Owner's entry — the owner said so. Kept, labelled, never in a file you send.
- Not signed — draft, imported or proposed.
The shape carries the label as well as the colour, so it survives printing. Labels never depend on what anyone paid.
What a file you send contains
A file you send is the signed ink, for whoever you give the link to. Planned A file addressed to a named buyer, and an insurer summary, come later. The rules are the same on the page and in the file:
- A line is in only if a professional or a yard signed it and that signature still checks.
- The owner's notes never enter.
- Parts the owner added that the class does not list never enter.
- A photo enters only when a signed line names it.
- Receipts and amounts never enter.
- No shop, no score.
In short: only checked professional and yard signatures, and the photos they name, pass into the file.
Check a file without us
Closed alpha The file contains the signed lines, the photos they name, and what is needed to check them. A stranger can check the signatures with SailOS switched off. A line that does not check is not shown as signed.
Concept Later: a trusted time on each signature, a public log so a signature can be shown to have existed, and a published description so anyone can write their own checker.
Four rules
- No software holds a signing key. Nothing automated can sign or pretend a person was present.
- Signed lines stay. Corrections add. Originals remain readable.
- A buyer cannot see another hull's private photos. Every read is for that boat only.
- Support cannot silently sign as the surveyor. Every signature needs the signer's own credential.
What we do not claim
Not "tamper-proof": tamper-evident. Not "certified": a surveyor's credentials are self-declared and shown as such. Not "insurer-approved": no insurer has agreed to anything. Not a court-grade signature yet: the alpha proves the shape with stand-ins and says so on every page.