Add compliant electronic signatures and a tamper-evident audit trail to your Confluence approvals — built on Atlassian Forge, so your signature data never leaves Atlassian.
Incumbent workflow apps mark their own e‑signatures “Limited.” We make the signature the whole point.
What you get
Signatures an auditor can trust, evidence you can prove.
Two‑component signing
Atlassian account identity plus your own signing credential, verified on every signing. Each signature records its meaning — Reviewed, Approved, or any you define — the signer, and the exact page version.
§11.100 · §11.200 · §11.50
Tamper‑evident audit trail
Every signature is linked into a SHA‑256 hash chain. Alter one entry and the chain breaks, visibly. Export a standalone certificate anyone can verify — without our app.
§11.10(e) · §11.70
Data never leaves Atlassian
Runs on Atlassian: no remote backend, no third‑party API, no egress. Signature data stays inside Atlassian‑hosted storage — data residency you can prove, not promise.
Forge · hosted storage
Ordering, authority & approvals
Require Reviewed before Approved. Restrict who may apply each meaning to the right groups. Notify the right people — inside Atlassian, no email. Keep your workflow app, or use ours.
§11.10(f) · §11.10(g)
The evidence
A chain of signatures, each locking the last.
Reordering, editing, inserting or deleting a signature breaks the chain at a detectable point. Verification recomputes it from the published method at gxpseal.com/verify.
Authored
e1 · 3c9a…7f2b
prev · null
→
Reviewed
e2 · a17d…c04e
prev · 3c9a…7f2b
→
Approved
e3 · 9f2c…a71b
prev · a17d…c04e
→
verified ✓
recomputed · matches
no gap · no edit
How it works
Three steps, all inside Confluence.
Step 1
Install from the Marketplace
One Forge app, no servers to run and nothing to connect. It inherits your site’s data‑residency controls.
Step 2
Sign a page
From a page’s menu, choose a meaning and enter your signing credential. The signature binds to that exact version.
Step 3
Keep the evidence
A permanent, tamper‑evident record on the page, and a self‑verifying certificate for your validation pack.
“The two‑component signing model and audit controls were reviewed against 21 CFR Part 11 and confirmed sound.”
Independent review by qualified regulatory counsel. The signed position paper and continuing‑obligations record are retained in the validation pack for your auditors.
Security & privacy
Your signature data never leaves Atlassian.
GxP Seal runs entirely on Atlassian Forge. There is no remote backend to breach and no third party in the path — so “data residency” is something you can demonstrate to an auditor, not just assert.
No external egressNo emails, no outbound API calls, no analytics. Nothing leaves Atlassian’s infrastructure.
No sub-processorsBeyond Atlassian itself, there are none. Your data-processing map is short and honest.
Data residency, inheritedStorage is Atlassian-hosted, so it follows your site’s residency controls automatically.
Credentials never loggedSigning credentials are salted-hash stored (scrypt), verified in constant time, and never written to a log.
Tamper-evident by designA SHA-256 hash chain makes any alteration detectable, and certificates verify without our app.
Least-privilege scopesOnly the Confluence permissions the app needs to read pages and record signatures — nothing more.