SIGIL · DOCUMENTS AND SIGNATURES

The document stayson your computer.

Sigil is a desktop application. Opening a PDF, marking it up, editing it and signing it all happen on the machine in front of you — nothing is uploaded in order to be worked on. When a document does have to travel, you start that, and this page says exactly what goes.

Diagram of the Sigil editor: a page thumbnail rail, annotation tools, and a document on the desk. Sigil The pages The marks The page
The editor, drawn: page rail, annotation tools, the document on your machine. A diagram of the product, not a screenshot of the window.

MEASURED

Four numbers, each one countable in the source.

COMMANDS ON THE DOCUMENT
47

The desktop backend wires 55 commands. Forty-seven of them act on the document; the rest are sign-in, sharing and text extraction.

ANNOTATION TOOLS
10

Highlight, underline, strike-through, free text, note, ink, line, arrow, shape and redaction.

SIGNING KEY
PKCS#12

You sign with a PKCS#12 certificate you already hold. Sigil does not issue one, does not store one and does not send it anywhere.

INTERFACE LANGUAGES
5

English, Italian, German, French and Spanish. A change of language takes effect at the next start, and the settings panel says so.

THE SIGNATURE

What a signature proves, and what it does not.

Sigil signs with your certificate, and when it checks a signature it tells you two separate things rather than one green tick. Scroll through the four steps.

The whole file, a certificate, the range of bytes the signature covers with the excluded window, and a verdict of two rows: bytes intact, identity not verified. The file, whole Your certificate What the signature covers excluded window Bytes intact Identity not verified
  1. 01 The file, whole

    Sigil reads the bytes from disk. Nothing is uploaded in order to be signed.

  2. 02 A certificate you hold

    Signing takes a PKCS#12 file and its password. Sigil issues no certificates and keeps none of yours.

  3. 03 The signature covers a range

    Two spans of the file are signed and the window that holds the signature itself is left out. Sigil measures how much of the file is outside those spans, so content appended afterwards cannot pass unnoticed.

  4. 04 The verdict is two claims

    Sigil can say the signed bytes are unchanged. It cannot say who signed: there is no trust store, no revocation check and no timestamp, so a self-signed certificate reads exactly like any other. The app shows both facts side by side instead of collapsing them.

ON THE DOCUMENT

Seven kinds of work, done on your machine.

Two of these call another program that has to be installed alongside Sigil. Both are named further down, not buried here.

Ten tools beside the page, drawn rather than captured. A diagram of the product, not a screenshot of the window.
What the signature coversexcluded windowBytes intactIdentity not verified
What a signature covers, and the window it leaves out. A diagram of the product, not a screenshot of the window.
On your machineSend to signWhen it has to travel
The file stays local until you send it. A diagram of the product, not a screenshot of the window.
Read and search
Render pages, pull out text and text blocks, search with the hit rectangles, read bookmarks, page count and page size.
Annotate
Ten tools, plus a flatten step that writes the marks into the page so they travel with the file.
Edit
Change text in place, lay text over the page, and redact — which removes the content rather than drawing a black box on top of it.
Assemble
Merge, split, extract pages, reorder, insert a blank page, delete one, rotate a page or the whole file, and compare two documents.
Convert
Export to DOCX, CSV and plain text, build a PDF out of images, save a page as an image, print.
Sign and verify
Sign with your certificate, read what the certificate says, and check a signature against the byte range it covers.
Protect
Encrypt with a password, watermark, and run a whole folder through the same operation in one pass.

WHEN IT HAS TO TRAVEL

The moment a second person is involved.

A signature that needs somebody else cannot stay on one machine. Sigil has a service side for exactly that, hosted in the EU, and nothing more of the document leaves than the workflow needs.

Sign in with Altovar
The app authenticates against Altovar's identity service. The token stays on the machine and can be cleared from the app.
Send for signature
Documents, share links, templates and signature requests are handled by the Sigil service. Starting one is an explicit act, never a side effect of opening a file.
The assistant, only when asked
Page text is extracted locally and travels only when you start an assistant request, billed to your organisation's wallet.
On your machineSend to signWhen it has to travel
On your machine, then out only when you start that. A diagram of the product, not a screenshot of the window.

DOWNLOAD

Every file in this release.

Versioned links: the file you get today is the file this page describes, and the sizes are the ones the server reports.

VERSION 0.2.4

Windows installer Sigil_0.2.4_x64-setup.exe · 18 MB Download
Debian and Ubuntu package Sigil_0.2.4_amd64.deb · 19 MB Download
Portable AppImage, no installation Sigil_0.2.4_amd64.AppImage · 91 MB Download
Fedora and openSUSE package Sigil-0.2.4-1.x86_64.rpm · 19 MB Download
macOS Not yet

Two things worth knowing before you click. The Windows installer is not signed with a certificate yet, so on first run Windows will say it protected your PC — choose “More info”, then “Run anyway”. And in 0.2.3 the Linux packages cannot draw a page: the rendering library ships inside the package but the application looks for it somewhere else, so a document opens to an error instead of its first page. The fix is being released; until it is, use the Windows build.

WHAT THIS RELEASE DOES NOT DO

Read this before you plan around it.

This is the section that goes stale first. It describes 0.2.3, and it is here so the rest of the page can be taken at face value.

Qualified signatures and timestamps

Sigil signs with the certificate you give it. It does not obtain a qualified certificate, does not attach a trusted timestamp and does not check revocation, so on its own it cannot make a document qualified under eIDAS.

Judging who signed

Verification proves the signed bytes are unchanged. There is no trust store and no chain building, so a self-signed certificate produces the same “intact” result as any other. Sigil reports that difference rather than hiding it.

OCR without Tesseract

Making a scan searchable calls Tesseract on your machine. If it is not installed the tool says so and stops, instead of returning an empty result.

Office files without LibreOffice

Turning a Word or Excel file into a PDF drives LibreOffice locally. Going the other way — export to DOCX, CSV and text — needs nothing extra.

A macOS build

There isn't one, and you will not find a button here pretending otherwise. Tell us if you need it: knowing how many people are waiting changes the order of the work.

Try it on a document that matters.

Download it, open a contract you actually care about, sign it with your own certificate and check the signature. That is the whole product in five minutes.