KagazoIndia PKI Verify
Cryptographic Workflow

How Kagazo Works

From an unverified yellow question mark to a tamper-evident green checkmark in 3 simple steps.

01

1. Upload PDF to Ephemeral Memory

Drag and drop your e-Aadhaar, community certificate, or PAN card into Kagazo. The file is uploaded through an encrypted TLS 1.3 tunnel directly into volatile RAM. If password-protected, the password is used in-memory solely for decryption and is never retained.

02

2. ByteRange Audit & RCAI Root Chain Verification

Our cryptographic engine (powered by pyHanko) parses the PDF's /ByteRange array and calculates the SHA-256 digest to verify that 0 bytes were modified after signing. It validates the intermediate certificate (NIC Sub-CA, eMudhra, Protean) against the official Root Certifying Authority of India (RCAI) repository.

03

3. Long-Term Validation (/DSS) Stamping

Kagazo constructs and embeds an ISO 32000-1 compliant Document Security Store (/DSS) dictionary containing all necessary certificate paths, CRLs, and OCSP tokens into the document via an incremental update. The resulting PDF displays a permanent green tick mark across all PDF viewers globally.

The Math Behind the Green Tick

Unlike physical ink signatures, a PDF digital signature is an encrypted cryptographic digest. The signer's private key encrypts the document hash. When opened, the viewer decrypts the digest using the public key and compares it to the calculated hash.

Adobe Acrobat displays a yellow question mark because it cannot confirm that the public key originates from a trusted root. By connecting the dots back to the Indian Ministry of Electronics & Information Technology's sovereign root certificates, Kagazo provides mathematical certainty of authenticity.

Try It on Your PDF

See the verification engine in action. Free, instant, and completely private.

Verify Document Now