An electronic signature is worth exactly what it can prove later. Most of the time nobody tests it. The one time somebody does, the question is never whether a signature exists — it is whether this signature, on this version, by this person, can be shown to a third party who was not in the room.
The problem
Across the Gulf, agreements are increasingly signed electronically and the signing itself has become trivial. What has not kept up is the evidence. A signature image pasted into a PDF, or drawn in a tool that stores nothing but the drawing, is a picture of consent rather than a record of it.
The weakness only surfaces under challenge, which is the worst possible moment to discover it.
What it is
TOTHIQ is an agreement workflow for individuals and businesses across the GCC: a locally reviewed template, review anchored to the clause, one approved and locked version, and a signature that carries its own evidence. It works in Arabic and English and is launching in the United Arab Emirates alongside Kuwait, Saudi Arabia, Qatar, Bahrain and Oman.
What a signature has to carry
A drawn signature in TOTHIQ is bound permanently to four things, and the binding happens at the moment of signing rather than being reconstructed afterwards.
The verified account that signed. The email address that account holds, preserved as it was at signing rather than as it is today. The exact version of the document that was displayed. And the recorded signing time. Consent, date, time and the transaction history stay together as one record.
None of that is exotic. What is unusual is treating it as the deliverable rather than as metadata nobody expects to read.
Preventing the silent change
The failure mode that matters is not forgery. It is the quiet edit — a number adjusted in a document after agreement, in a file that looks identical.
Document and signature fingerprints make that detectable. If the bytes change, the fingerprint no longer matches the one recorded against the signature, and the mismatch is visible rather than arguable. This is the difference between a system that stores agreements and one that can answer questions about them.
Bilingual by construction
In the UAE a single agreement routinely has an Arabic-reading party and an English-reading party, and sometimes an Arabic original with an English working copy.
That has to be handled in the data model rather than by a translation layer. Both languages are first class: the same clause, the same anchored comments, the same locked version, read in either direction. A product that treats Arabic as a display option will eventually produce two documents that disagree, which is precisely the problem it was meant to solve.
Six countries, six sets of rules
Electronic transaction law is not uniform across the GCC, and inside the UAE the free zone financial centres run their own regimes alongside the federal one. A workflow that hard-codes one country’s assumptions cannot cross a border.
The design response is to keep the evidence model constant and let the template and the jurisdiction vary. What is recorded about a signature is the same everywhere. What is being signed, and which law it names, is local.
What it demonstrates
That trust is an engineering property rather than a marketing claim, and it is built by deciding what you will be able to prove before you build the interface. That the evidence bundle is the product in any system whose output is a commitment. And that a bilingual market rewards products designed bilingual from the first schema, not adapted later.
Where it is now
In build, launching across the Gulf. The public site sets out the four-step process, the signing model and what the record contains.