Engagement · live & scaling

Industry
Cybersecurity & identity
Solution
Blockchain
Engagement model
Enterprise engineering partnership
Engagement length
12+ months
Market stage
Live & scaling
Team
6+ team members
Scope
End-to-end product engineering
Platform
Web
100%
On-chain immutability

Every meaningful event in the agreement lifecycle is recorded on-chain, so the record of what happened cannot be altered after the fact.

Reported post-launch, platform-wide

98%
Core components integrated

Biometric identity, the rules engine, on-chain event tokens, tokenised value, authority validation and the interaction trail working as one flow.

Reported at handover, across the delivered platform

95%
Compliance with URPERA, UETA & ESIGN standards

Legal requirements were mapped before design started, so the data model and the finalised artifact were built against those standards rather than retrofitted.

Reported post-launch, platform-wide

Context

The situation before the platform

Why signing faster was never the same thing as proving who signed, and with what authority.

The business

A blockchain solutions provider building an enterprise digital agreement and contract execution platform for organisations whose agreements carry legal, financial or regulatory weight — real estate closings, financial agreements, regulated supply chains and healthcare consent.

The starting point

A standard e-signature proves that someone opened a document, clicked a button and had an email address on file. Who that person really was, whether they were authorised to sign for a company, and whether the contract's own conditions were satisfied are all left unanswered.

The trigger

For low-stakes transactions the appearance of validity is enough. For anything a court might examine it is not — and completion certificates showing timestamps and IP addresses have become increasingly easy to challenge in legal settings.

What they wanted

One ecosystem unifying identity verification, legal enforceability, smart contract automation and blockchain-backed auditability, where every participant is biometrically verified, the contract enforces its own validation checks, and the output is a tamper-proof artifact carrying cryptographic proof of who agreed, under what conditions and with what authority.

Constraints

The build sat at the intersection of identity, smart contract logic and legal compliance, so no layer could be designed without understanding its effect on the others · six components had to hand off to each other in a deterministic sequence or the audit trail would contain gaps · the interface had to present smart contract conditions, token minting and biometric attestation to users who have no mental model for any of them.

System

What it runs at today

The platform as delivered, live and scaling.

Disputes possible without forensic evidence
0%
Every completed agreement carries identity records, authority proofs and a full interaction trail in one place
Core components
6
Biometric identity, rules engine, on-chain event tokens, tokenised value, authority validation and the interaction trail
Engagement length
12+
Months, as an enterprise engineering partnership through build and scaling
Team size
6+
Design, engineering and QA covering the web platform, smart contracts and compliance validation
The engineering problem

Six failures traditional e-signature tools leave behind

E-signature tools removed wet signatures from the workflow and quietly introduced a different problem: agreements that look verified but aren't. Each gap below is paired with what we did about it.

0 1
A device log is not proof of a person

Standard platforms log a device, an IP address and an email, and call that proof. It tells you something accessed a document, not who that person actually was. Shared inboxes, delegated accounts and outright impersonation all pass through without friction — and the signature looks valid right up until someone challenges it.

What we did

Biometric identity verification at the point of action: a face scan, liveness detection and government ID tied to the individual before they can take any step, so every signed agreement is backed by proof of a real, physically present person.

0 2
Nobody checks whether the signatory could sign

Companies sign through people — officers, executives, authorised representatives. Most digital agreement tools have no way to confirm that the person signing held the legal authority to do so for their organisation. The assumption holds until a deal falls through and the counterparty argues the signatory had none.

What we did

Authority resolution against the organisation's verified role registry before a representative can finalise, with that resolution written into the agreement record so the check is documented at the time of signing rather than assumed afterwards.

0 3
Everything after signature lived outside the contract

Fund disbursements, licence activations and service triggers have always sat beyond the agreement itself. They required manual follow-through, separate systems and trust that both parties would honour the terms. There was no mechanism inside the contract to make any of it happen.

What we did

A tokenised consideration framework that embeds funds, licences, rights or digital deliverables inside the agreement and releases them when conditions are satisfied — escrow release, licence activation, asset transfer — so the contract becomes the mechanism rather than a description of one.

0 4
Contract conditions described, never checked

Agreements are full of conditions: age restrictions, jurisdiction clauses, approval requirements, time-sensitive terms. In a typical digital agreement those conditions exist as text and are enforced nowhere. The platform lets anyone sign whether or not they meet the contract's own requirements.

What we did

A business rules engine that runs before execution is allowed — age checks, jurisdiction validation, role restrictions, multi-party approval — evaluated as conditions rather than written as prose. If a check fails, execution does not proceed.

0 5
Thin evidence a determined challenge can unpick

Courts want to know whether a real person with a real identity was present at the point of signing, and an IP address does not answer that. Most e-signature audit trails are thin enough that a serious challenge can put the whole agreement in question.

What we did

On-chain event tokens capturing who acted, what they did, when, where, on which device and with what identity verification strength — each graded on biometric quality, device trust and data integrity, and woven into a complete interaction trail.

0 6
Proof scattered across five systems

Even organisations with sound compliance practices ended up with an e-signature certificate in one place, an identity check in another and a screening result somewhere else. Reconstructing a complete picture for an audit or a dispute took significant effort, and the pieces did not always fit together cleanly.

What we did

A single finalised artifact holding the identity records, authority proofs, contract terms, rules engine outcomes, tokenised value state and full audit trail together — blockchain-stored, jurisdiction-tagged and built for court admissibility.

Architecture

How it fits together

Simplified — the shape rather than every service.

0 1 Clients
React.js · HTML5 · CSS3 · JavaScript

A full-stack web application covering agreement creation, templating, rule configuration and finalisation, designed to read as a professional agreement tool rather than a blockchain demo.

0 2 Gateway
Node.js · Biometric Identity Integration · Authority Validation

Every request passes identity and authority checks before it reaches the agreement lifecycle, so biometric verification and organisational authority resolution happen ahead of any action rather than alongside it.

0 3 Services
Smart Contracts & Business Rules Engine · Tokenised Consideration Asset · Token Grading · Audit Trail Logging · Finalisation & Minting

Each component owns one concern, but they intersect at several points in the agreement lifecycle — so execution order is deterministic and every state transition is logged for the audit trail to hold.

0 4 Data & infra
PostgreSQL · AWS · On-chain Artifact Storage · Zero-knowledge Audit Trail

PostgreSQL holds platform and agreement data, with finalised artifacts and event tokens stored on-chain and the audit trail built to stay privacy-preserving while remaining verifiable.

Component sequencing was treated as an architectural requirement, not an implementation detail: what triggers an event token, at which moment, and how execution state is tracked across a multi-party flow determines whether the audit trail contains gaps.
Solutions

Six components, one enforceable artifact

Not a features list — what replaced passive document signing with an identity-verified, logic-governed process.

Biometric identity at the moment of agreement

A verified face scan, liveness detection and government ID tie the action to the individual, so every agreement is backed by a real, physically present person rather than a logged-in device.

A rules engine that can say no

Age checks, jurisdiction validation, role restrictions and multi-party approval requirements are conditions the system evaluates before execution, not text in a document. If one fails, the agreement does not go through.

Organisational authority, documented not assumed

A representative's authority is resolved against their organisation's verified role registry before finalisation, and that resolution becomes part of the agreement record.

Value embedded directly in the agreement

Funds, licences, rights or digital deliverables sit inside the agreement and execute when its conditions are satisfied — escrow releases, a licence activates, an asset transfers.

A forensic record, not a log file

Event tokens capture who acted, what they did, when, where, on which device and with what verification strength, each graded on biometric quality, device trust and data integrity.

Everything sealed into one artifact

The finalised output is a blockchain-stored, jurisdiction-tagged document holding identity records, authority proofs, contract terms, rule outcomes, tokenised value state and the full audit trail in one place.

Key features

What the platform does day to day

Five capabilities where the blockchain layer does real work rather than sitting decoratively behind the product.

Capability Runs Refresh What it does
Biometric contract execution Per signer At point of action Ties each signature to a verified identity, establishing who agreed, what was agreed and when
On-chain finalised artifacts Per agreement On completion Generates a cryptographically sealed, blockchain-anchored document that can be verified independently
Audit tokens for transaction integrity Per event On release Records a step-by-step immutable trail across the contract lifecycle that cannot be altered
Tokenised value settlement On conditions met Per interaction Settles contract value on-chain, reducing manual reconciliation and settlement risk
Interaction trail for every contract Continuous On reuse Logs every interaction on-chain for an unbroken record from creation to completion
Integrations

How the moving parts plug in

Identity, authority and blockchain capabilities reach the agreement lifecycle through one platform layer rather than sitting beside it as separate checks.

Connected capabilities

Biometric identity verification
Face scan, liveness, government ID
Organisational authority registry
Verified roles and representatives
Blockchain network
Artifact and event token storage
Cloud infrastructure
AWS hosting and delivery
↓ Through one platform layer ↓

Platform integration layer

Node.js API layer
One contract for every client
Business rules engine
Conditions evaluated before execution
Zero-knowledge audit trail
Verifiable without exposing data
↓ Into the core services ↓

Core services

Agreement creation & templating
Identity verification
Event tokens & grading
Tokenised value
Finalisation & minting

Because identity, authority, rule outcomes and tokenised value all resolve into the same finalised artifact, proving what was agreed is one object to point to rather than records pulled from five systems.

Security

What protects identity and compliance evidence

The platform was designed to produce court-admissible evidence, so identity strength, privacy and immutability were architectural requirements from the first sprint.

Identity established before action

Face scan, liveness detection and government ID verification run before a participant can take any step, so authentication precedes execution rather than accompanying it.

Authority resolved, then recorded

Signing authority is checked against the organisation's verified role registry and that outcome is embedded in the agreement, closing the "I assumed they were authorised" argument.

Privacy-preserving audit trail

A zero-knowledge audit trail keeps the interaction record verifiable and biometrically anchored while limiting what has to be exposed to prove it.

Compliance built into the data model

URPERA, UETA and ESIGN requirements and non-repudiation standards shaped the data model and artifact specification from the start, rather than being retrofitted into a finished architecture.

Process

How we got there

Five moves, starting with what a court needs to see rather than with a feature list.

0 1
Discover

We started with the legal question, not the product question: what a court needs to accept a digital agreement as evidence, what URPERA, UETA and the ESIGN Act require, and where existing platforms fall short of those standards.

0 2
Define

Six components — biometric identity, the rules engine, on-chain event recording, tokenised value, authority validation and the interaction trail. Most of the architectural thinking went into how they fit together and hand off in sequence.

0 3
Design

The platform handles concepts most users have no mental model for — smart contract conditions, token minting, biometric attestation — through an interface that had to feel like a professional agreement tool. Several rounds of redesign before the complexity read as invisible.

0 4
Develop

Agreement creation and templating, rule configuration, event token minting, tokenised value embedding and release, authentication, authority checking, interaction logging and finalisation — with deterministic execution order and every state transition logged.

0 5
Validate

On a platform built to be evidence, failure paths matter more than the happy path. We tested the scenarios that create legal exposure: rules that should block execution but don't, an unauthorised signer being rejected, tokenised value triggering before conditions are met.

Business impact

What changed for the business

Twenty years of digital agreements made signing faster without answering whether a signature meant anything. Three things changed for organisations on the platform.

Agreements with different evidentiary weight

Organisations aren't just running a more efficient signing process. Each finalised artifact carries the full picture: who was verified, that they had authority, that the contract's conditions were met, and how it all unfolded.

Evidence, not a signed PDF
Ambiguous disputes get a clear answer

In real estate closings, financial agreements, regulated supply chains and healthcare consent, disputes that used to reach arbitration because the evidence was ambiguous now resolve against a single record.

Proof isn't reconstructed
Built from the ground up

Architecture, smart contract infrastructure, biometric integration, the blockchain layer and the compliance logic running through all of it — one of the more complex builds we've taken on.

End-to-end engineering
Commercial outcome

What the engineering choices are worth in operating terms

Every headline number traces back to a specific decision, not a vague platform effect.

Engineering decision Operating outcome Measured effect
Tokenised event pipeline recording every interaction on-chain The lifecycle record cannot be altered after the fact 100% on-chain immutability
Six components sequenced into one agreement flow Identity, authority, logic, value and audit hand off without gaps 98% core components integrated
Legal requirements mapped before the data model was designed Finalised artifacts stand up against the standards courts apply 95% compliance with URPERA, UETA & ESIGN
Biometrically anchored, graded interaction trail Every agreement arrives with forensic evidence attached 0% disputes without forensic evidence
Stack

What it's built on

The actual technologies, not feature names with icons attached.

Frontend

  • React.js
  • HTML5
  • CSS3
  • JavaScript

Backend

  • Node.js
  • Smart contracts & business rules engine
  • Tokenised consideration asset framework

Data & infra

  • PostgreSQL
  • AWS
  • On-chain artifact and event token storage

Integrations

  • Biometric identity integration
  • Zero-knowledge audit trail
Full case study

Get the complete write-up as a PDF

The same content on this page, plus the extended module breakdown and delivery phases, in a single document you can share internally.

  • Component architecture and execution sequencing
  • Legal research to launch, phase by phase
  • Identity, audit and compliance decisions in detail

Download the case study

No spam · unsubscribe anytime · reply within 24 hours if you ask a question

More work

Other platform builds

Hospitality

Every stay, extraordinary.

Hospitality group transformed guest experiences through IoT-enabled room automation, reducing service requests by 58%
Hospitality group transformed guest experiences through IoT-enabled room automation, reducing service requests by 58%
Transportation & Mobility

Share the ride. Own the journey.

Mobility platform optimized commuter matching, increasing successful ride bookings by 48%
Mobility platform optimized commuter matching, increasing successful ride bookings by 48%
Sports & Entertainment

Fans in. Athletes up.

Sports engagement platform increased fan participation by 3x through gamified digital experiences
Sports engagement platform increased fan participation by 3x through gamified digital experiences