Home » privacy

By Shamsh Hadi, CEO & Co-Founder of ZorroSign, Inc.

As CEO of ZorroSign, Inc. I am committed to advancing technology while advancing sustainability. With regard to technology, I am always looking for ways to stay ahead of the curve—especially in cybersecurity.

But lately, there’s an emerging technology that keeps me up at night: Quantum computing.

While quantum computing promises potential breakthroughs in AI, chemistry and medicine, physics and materials science, it also presents a significant threat to cybersecurity.

Think of it like this: The locks guarding our digital data are built on complex mathematical problems (cryptography). Today’s computers struggle to crack these problems, taking years with longer encryption keys, keeping our information safe. But quantum computers, capable of massively parallel processing, could potentially shatter these locks and access encrypted data with ease.

This isn’t just science fiction anymore—experts believe quantum computers capable of breaking current encryption could be a reality within the next decade.


A sufficiently powerful quantum computer could break the public-private key encryption that secures digital communications, data, and transactions today, explains ScienceNews. “’All of those public-key algorithms are vulnerable to an attack that can only be carried out by a quantum computer,’ says mathematician Angela Robinson of NIST, ‘Our whole digital world is relying on quantum-vulnerable algorithms.’”

That’s why I’m urging businesses to start exploring post-quantum cryptography (PQC).

PQC is the next generation of encryption—designed to withstand the challenges of quantum computing by providing greater cybersecurity resilience. While the market is still evolving, PQC initiatives are rolling out and it is crucial to start assessing PQC solutions to future-proof your data security:

  • Protecting sensitive information — from financial records to customer data, a data breach can be catastrophic but strong PQC safeguards your most valuable digital data assets.
  • Maintaining customer trust — consumers expect their data to be safe, and implementing PQC demonstrates your commitment to robust, future-proof data security.
  • Staying competitive — businesses that embrace PQC early will be recognized as leaders in cybersecurity, gaining a potential edge in competitive markets.

The future of quantum computing is uncertain, but one thing is clear: Business leaders cannot afford to be unprepared.

By proactively adopting PQC, you can ensure your business data and your customer data remains secure—no matter what the future holds. I invite you to start exploring PQC solutions today and safeguard your business for the quantum tomorrow. Please connect with me on LinkedIn or email me to start a conversation . . .

Global ZorroSign
(Originally published on LinkedIn by Shamsh Hadi, CEO and Co-Founder of ZorroSign)

Last year, I shared how ZorroSign’s early roots in Dubai, UAE, helped us grow into an international company. I want to update that theme today and talk about ZorroSign’s role as a global company providing global solutions that improve data democratization, privacy, and security.

As CEO and co-founder of ZorroSign, I have dedicated my career to advancing technology while simultaneously advancing sustainability:  Ensuring the new technologies we bring to market elevate information privacy, data security, and data democratization while not coming at the expense of future generations.

At ZorroSign, we saw very early a market need to push past web2 solutions for digital signatures and digital transactions—escaping centralized information architectures that consolidate data with a provider (and expose that data to the risks of single-point-of-failure cyber-attacks) while simultaneously pulling data ownership away from users (to be housed and monetized by the web2 provider). Alternatively, ZorroSign empowers our users by deploying web3 solutions that decentralize data and ensure users will always own their documents and transaction metadata—even after their subscriptions with us end.

Dubai Start, Dubai Strong

As a long-time resident of Dubai, I was greatly inspired by the Digital City Vision—Smart Dubai of H.H. Sheikh Mohammed bin Rashid Al Maktoum. ZorroSign’s technology very purposefully supports Dubai’s paperless initiatives for Digital Dubai and helps to advance Dubai’s leadership in digital operations, specifically focused on:

  • Security—providing superior digital privacy and security by leveraging a private, permissioned blockchain technology
  • Digital Signatures—a platform that is easy-to-use and legally compliant to global standards
  • Chain of Custody—delivering immutable records of every step of every digital transaction: Authenticating users, securing data, and verifying documents for legal enforceability
  • Advancing UAE’s 10 Principles for the Next 50 Years—specifically helping Dubai to build the best and most dynamic economy in the world; defining new UAE development with digital, technical, and scientific excellence; and promoting a value system based on openness and tolerance

Initially, our company served government departments in UAE but soon grew into an international business—helping people to build, sign, store, and track mission-critical documents on the blockchain in Sri Lanka, India, and the United States.

Last year, ZorroSign was named Blockchain SaaS Innovator of the Year at the UAE Business Awards 2021, then at the turn of the year, Unlock News Desk showcased a story on UAE Based ZorroSign introducing six new features to our blockchain platform.

This spring, Tech Channel wrote a great article on ZorroSign making waves in digital signature space using blockchain technology, and TahawulTech.com interviewed me on how ZorroSign helps tackle identity theft on our now multi-chain blockchain platform.

And most recently, ZorroSign was highlighted in a Zawya article for UAE businesses and a TECHx article on ZorroSign’s mission to provide businesses across the Middle East with seamless integration of document management and secure digital signature solutions.

I am incredibly proud of our continued success in my home town, and while ZorroSign expands our global presence, the UAE and other Gulf Cooperation Council countries will be a strategic market for us.

Success in South Asia

From the start, ZorroSign has had close ties with the south Asia countries of India and Sri Lanka. While operations started in Dubai, our development center of excellence has always been in Colombo!

Our blockchain architecture was conceived, coded, and cultivated entirely in Sri Lanka with a vision to provide global customers with the ability to securely transform paper-based workflows to digital operations. I could not be prouder of our Sri Lanka team, and though they are struggling through that beautiful country’s difficult political and economic crisis, they have proven again and again the resilience and tenacity of their engineering genius.

Recently, APAC Business Headlines recognized the ZorroSign team as the “Most Innovative Blockchain Company from Sri Lanka” for 2022! The award validates the hard work of our center of excellence team, and further proves blockchain’s prominence on the global stage.

This recognition followed our 2021 success where the International Business Awards® named ZorroSign a Gold Stevie® Award Winner for Blockchain Solutions. The Stevie’s are the world’s premier business awards program, where in 2021 more than 3,700 nominations from organizations across 63 nations and territories—of all sizes and in virtually every industry—were submitted for recognition. We were delighted to be awarded a gold Stevie for our blockchain solution and to be recognized as a Company of the Year, and Most Innovative Tech Company of the Year. Most flattering, the judges were quick to note that ZorroSign is “one of the few companies that are able to use blockchain technology to solve a real business problem” . . . a strong endorsement of our digital signature technology, built on blockchain, and paired with identity-as-a-service (IDaaS) and patented fraud detection, to authenticate users and verify documents across digital transactions.

Tackling North American Markets

As a U.S. citizen who has lived in Canada, China, and the UAE at various times over the past forty years, my goal was always to return home and bring ZorroSign’s blockchain solutions to North American users.

In August 2020, we opened our global operations hub in Phoenix, Arizona—ushering in a new phase of business growth. We quickly established local partnerships with Arizona State University, Grand Canyon State University, the Arizona Commerce Authority, Arizona Technology Council, City of Phoenix, Global Chamber®, the Greater Phoenix Economic Council, and many other incredible organizations!

And we’ve engaged government agencies, financial services providers, IT businesses (and departments), legal services firms, real estate companies, and several other verticals to prove the value of a paperless life and the most private, secure, compliant digital transactions hosted on blockchain. Early adopters of our web3 solutions are excited to embrace ZorroSign’s robust platform to advance their digital operations and gain a competitive advantage in a market place still dominated by legacy, web2 technologies.

Global Privacy and Security Compliance

Our unique combination of blockchain architecture, web3 technologies, artificial intelligence/machine learning, and patented fraud prevention grants ZorroSign compliance across many international standards for privacy and security.

The list continues to grow as we expand our markets, but already includes:

  • Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA)
  • Canada’s Uniform Electronic Commerce Act (UECA)
  • The European Union’s Data Protection Regulation (GDPR) for data privacy and security
  • EU’s electronic IDentification, Authentication and trust Services (eIDAS) regulation
  • India’s Information Technology Act 2000 (IT Act of India)
  • International Standard on Assurance Engagements (ISAE) No. 3402, Type II audited
  • International Organization for Standardization (ISO) 27001 certified
  • PDF Advanced Electronic Signatures (PAdES) is a set of restrictions and extensions to PDF and ISO 32000-1
  • The UAE’s Federal Law No. 1 of 2006 regarding Electronic Transactions and E-Commerce granting electronic signatures legal force and effect
  • The American Institute of Certified Public Accountants (AICPA) SOC 2 Type I audit
  • USA’s California Consumer Privacy Act (CCPA)
  • USA’s Department of Commerce’s National Institute of Standards and Technology (NIST) encryption standards
  • USA’s Digital Millennium Copyright Act (DMCA)
  • USA’s Electronic Signatures in Global and National Commerce Act (E-Sign Act)
  • USA’s FDA Title 21 of the Code of Federal Regulations; Electronic Records; Electronic Signatures
  • USA’s Health Insurance Portability and Accountability Act (HIPAA)
  • USA’s Uniform Electronic Transactions Act (UETA)

I am proud of all ZorroSign has achieved for our international customers and incredibly excited about some big announcements later this summer! ZorroSign is truly a global company delivering global solutions, and we are not resting on our laurels—the best is yet to come.

Contact us to learn more . . . or start your free trial to put our digital signature software to the test!

The way that the legal industry conducts business has changed drastically over the last few years, foremost due to the shift during the COVID-19 pandemic to a remote lifestyle. A recent survey by the American Bar Association shows that more than half of all attorneys are now working from home almost exclusively. This switch to remote work has caused the legal industry to look towards technology to move the bulk of their processes and workflows online.

With that industry shift in mind, here are three ways that ZorroSign helps to law firms, legal departments, and attorneys worldwide to thrive in an online environment!


Lawyers are often swamped with paperwork and the hassle of printing, signing, and scanning documents. While much of this work is important to the successful operation of legal services, future-thinking law firms and legal departments are identifying repetitive, manual processes and incorporating automation to drastically improve their workflows. This allows attorneys to spend more time on client development and for staff to become more productive.

Incorporating technology into your legal service workflows can expedite operations, accelerate growth, and increase the value of the services delivered to clients. When used strategically, technology can also free up your teams from mundane tasks and enable them to apply their expertise to higher-value work. As a result, law firms and legal departments become more efficient, innovative, competitive, and profitable.

ZorroSign’s blockchain platform allows firms to build and automate templates and approval workflows, ensuring compliance with business regulations while streamlining processes from a single dashboard. Our contract lifecycle management (CLM) capabilities support automation and help move attorneys to digital record-keeping, digital communications, and digital chains-of-custody.

Expanding Privacy Regulations

Gartner predicts that by the end of 2023, modern privacy laws will cover the personal information of 75% of the world’s population. It is also expected that more state legislatures will enact privacy laws similar to the California Consumer Privacy Act (CCPA) which gives consumers more control over the personal information that businesses collect about them. Eventually the United States can expect a law that mirrors the EU’s General Data Protection Regulation (GDPR)—one of the toughest privacy and security laws in the world.

The increased demand for privacy has been driven by individuals’ demands for improved protection of their personally identifying information (PII), healthcare records, autonomy, and digital data privacy. Expanding regulations have pushed organizations to take the necessary steps to support data sharing, while preserving the privacy of those that they are working with and who are within their organization. All in all, organizations that choose to prioritize privacy have an opportunity to win greater loyalty and more business from their customers.

So how can ZorroSign help?

ZorroSign was created with the privacy of users in mind. Built from the ground up on blockchain technology for a zero-trust digital ecosystem, we deliver top notch security that has evolved to meet the legal enforceability needed in a court of law. ZorroSign is already compliant with CCPA and the EU’s GDPR policy—plus many Canadian, Indian, UAE, and United States data protection and privacy standards, ISO 27001 certification, American Institute of Certified Public Accountants (AICPA) SOC 2 Type I audit, and International Standard on Assurance Engagements (ISAE) No. 3402 Type II audited.

For the growing list of ZorroSign privacy and security standards, visit our recent blog on global compliance.

Transfer to the Cloud

While storing information on a hosted cloud server is not a new concept, the legal industry has been slow to migrate its data because of the security concerns that this presented. Telecommute work, however, has pushed legal organizations towards cloud solutions to better connect remote workers. The cloud’s cost-effective delivery of near-unlimited storage, paired with technology like blockchains, bridges the gap between the risk of remote connections and the need for elevated data security.

ZorroSign’s multi-chain blockchain platform can be deployed in a public, private, hybrid, or on-premise cloud, while ensuring your data and privacy and security needs are met:

  • Our standard deployment is on Amazon Web Services (AWS) public cloud computing network
  • In our private cloud configuration, all your data and the ZorroSign application run in a private and secure cloud network dedicated to your organization
  • In a hybrid cloud configuration, your data can be stored on either ZorroSign data centers or in the private cloud, while the ZorroSign platform and applications run on their standard public cloud configurations
  • On-premise deployments require your law firm or department to manage and maintain your own data centers, but gain the benefits of unlimited API calls and total control over identity access management (IAM), data privacy and security, and data integrity processes

To learn more about how ZorroSign serves the Legal Industry, please contact us or start your 14-day free trial subscription today!

Banks, credit unions, investment groups, lenders, and other financial service providers use ZorroSign’s digital platform to lower operating costs while protecting privacy and data security. Only ZorroSign pairs digital signatures with blockchain technology—delivering 21st century security to the age-old ceremony of signing agreements.


Anyone managing technology for a financial services provider feels the stress of managing data, networks, and endpoint devices in a world where cyber attacks, regulatory compliance, and customer needs are changing quickly. 

To ensure their financial organizations are secure, compliant, and delivering easy to use customer-facing solutions, IT departments need the latest technologies but also proven solutions. ZorroSign is proud to protect financial services data—for customers, for regulators, and for the institutions themselves.


Whether you’re a financial advisor or lender, a bank, credit union, or other services provider, you need fully compliant, automated, blockchain-level security and digital transactions you can trust. ZorroSign delivers:

  • Unbeatable user authentication, validation and privacy, with superior data and document security
  • A secure, paperless digital signature solution that’s easy to use, so you can “sign it and forget it”
  • Workflow automation that saves times and eliminates paper—streamlining approvals, signatures, and workflows
  • Error-free forms filled out and processed faster via artificial intelligence and machine learning

Financial institutions need privacy and security, but also need to know their technology solutions meet regulatory compliance.  ZorroSign’s platform is compliant with the Digital Millennium Copyright Act, UETA, the ESIGN Act, GDPR, plus ISAE 3402 Type II certified, SOC II Type 1 certified, and ISO 27001 certified while supporting HIPAA, ADA, WCAG 2.1, CCPA, New York SHIELD Act, and other standards varying country by country.

For banks, credit unions, and other financial service providers that desire to securely transform paper-based workflows, ZorroSign’s digital signature and document management platform can decrease costs, reduce errors, and increase productivity.

As a private blockchain, ZorroSign can ensure privacy is always maintained as only approved nodes (endpoint users) can write to ZorroSign’s blockchain. As a result, ZorroSign’s architecture has even tighter privacy and security measures than other blockchains.


Beyond digital signatures, ZorroSign delivers identity-as-a-service (IDaaS) to verify financial services users and support know-your-customer (KYC) requirements:

  • ZorroSign technology leverages the biometric capabilities of hardware endpoints to verify user identities
  • ZorroSign is the first to adopt password-less login amongst our digital signature competitors
  • ZorroSign MFA provides maximum security, as before a user can sign a document, our platform can validate multiple dimensions of authentication based on the transaction security needs: What you know (i.e., your ZorroSign login password), what you have (e.g., your laptop or mobile device), who you are (e.g., biometrics such as fingerprints or eye iris on the device securing who can access it), etc.

Additionally, ZorroSign users can optionally use our dynamic knowledge-based authentication (KBA) feature provided by LexisNexis. KBA requires the knowledge of private information of the individual to prove that the person providing identity information is the actual person.

Moving forward, ZorroSign will be adding further user verification capabilities, including integrations with U.S. driver licenses via state motor vehicle departments, verification via passports (with approximately 72 countries to start), other government-issued identities (with approximately 100 countries to start), and even tapping U.S. credit union databases for identity verifications.

Further, we will be implementing a blockchain-based audit trail for all user activities—including profile updates, signature changes, etc.—and will maintain a separate blockchain to maintain users’ signatures. With these immutable blockchain records, we can uniquely validate users in ways no competitive solution can.

We invite you to request a copy of our ZorroSign Security Brief to learn how our private blockchain architecture, document storage and protection, and platform security measures can support your financial service clients today!