Pledge is RavenFuture's internal signing platform. Create, route, sign, and archive documents — with the rigour of enterprise compliance and the feel of software built this decade.
Single sign-on via RFConnect. No passwords to manage.
Document
RF-XKBM4Q7A2E
Rahul Nair
Creator
Maya Chen
Signatory
Jordan Lee
Signatory
Document
RF-XKBM4Q7A2E
Rahul Nair
Creator
Maya Chen
Signatory
Jordan Lee
Signatory
Engineered for internal enterprise use
SHA-256
Hashed session tokens
OAuth 2.0
RFConnect SSO
CSP-strict
Content Security Policy
24h
Document recovery window
Product
Pledge replaces the scattered PDF-and-email workflow with a single, auditable pipeline.
Drop a PDF in, mark where signatures and fields belong, and route it to any number of assignees. Field positions are stored as relative coordinates so they scale with the document.
Every document is locked behind an RF-code. Only invited collaborators can open it — the server authenticates the user before a single byte of PDF is sent to the browser.
Watch status update as assignees sign, without refreshing. When the last signature lands, the document is ready to export.
Assign collaborators as editors or signatories. Editors can adjust fields before publishing; signatories can only fill their assigned fields.
Export completed documents as flattened PDFs with signatures embedded — no external fonts, no editable overlays, ready for archive.
Accidentally removed a Pledge? You have 24 hours to restore or re-export it before it's permanently purged.
Workflow
From PDF upload to signed and archived.
An admin drops in the PDF and marks signature, date, and text fields.
Assign collaborators as editors or signatories. Pledge generates a unique RF-code.
Signatories paste the code, authenticate through RFConnect, and sign in-browser.
Export the completed document. Pledge keeps a recovery copy for 24 hours.
Security
Pledge inherits the full stack of controls documented in the RavenFuture platform standard.
Identity via RFConnect only
Every session is established through your RavenFuture account. No passwords stored, no shared links.
Zero client-side secrets
OAuth client secret and database credentials exist only on the server. The browser never sees them.
Parameterised queries throughout
All database access uses parameterised mysql2 queries — no string concatenation, no SQL injection surface.
Hard security headers
Strict CSP, HSTS (2-year, subdomains, preload), X-Frame-Options DENY, nosniff, strict referrer policy.
Rate limiting + subnet bans
Edge-layer blocking for known scanners and proxy chains. Per-IP rate limits enforced in the database.
Sign in with your RavenFuture account to begin.