Some things aren’t
one person’s to sign.
In five places a second signature is already legally required — and in all five it lands on paper, where one person can produce both, it can be completed afterwards, and the record is held by whoever would be investigated. The requirement is real. The proof isn’t. That is the gap we’re building for.
The five.
Each one has its own failure mode. Every one of them already mandates a witness who currently signs a piece of paper.
Controlled-substance waste →
DEA · second licensed witness
A nurse wastes part of a vial. A second licensed person must witness and sign. That signature lands in a paper log where one person can produce both.
High-alert medications →
Joint Commission · independent double-check
Insulin, heparin, chemotherapy. A second clinician independently verifies dose and rate. What is recorded is initials, which cannot show whether the check was independent.
Blood administration →
Two-person bedside verification
Two people verify patient identity against the unit before transfusion. The bag and tag are discarded; a form survives.
Surgical counts →
Retained-item prevention
Circulating nurse and scrub count sponges and instruments and must agree. The count lives on a whiteboard and is charted afterwards.
Chain of custody →
Releasing and receiving officer
Every evidence transfer needs two signatures. They land on a form that travels with the item and is the first thing attacked at trial.
What they have in common.
We’re not inventing a workflow. Every one of these already requires two people — we’re making the second signature mean something.
Both parties sign the same record, so they are co-signers of one fact rather than two people making adjacent claims.
Each signature carries the signer’s credential and role as part of the sealed content. A credential added afterwards is not a credential.
You cannot witness yourself. If both signatures resolve to the same credential the record refuses to seal — the check lives in the cryptography, not in policy.
Any later edit breaks the seal visibly, and an auditor can confirm that independently against a published key — without trusting the institution being audited.
Where this actually stands.
Said plainly, because you’d find out on the call anyway.
What exists today
- The two-person seal is built and tested in our signing library
- Self-witnessing is refused at the cryptographic layer, not by policy
- Tamper-evidence and independent verification already run in our live review product
- The signing key is published, so anyone can verify a sealed record without an account
What does not exist yet
- Any point-of-work capture flow for these five cases
- Integration with an EHR, pump, cabinet, perioperative system or RMS
- Per-signer keys — credentials are captured, but signing runs on a service key today
- Any live deployment in a clinical or law-enforcement setting
One of these is going to be built first, with whoever has the problem badly enough to help design it.
Talk to us about a pilot.
The founder reads every message and will tell you honestly whether this fits what you need.