I also don't understand this retrograde step. I will repeat it. It is trivial to COPY and FORGE a graphical signature! And from a cloud provider??
What about S/MIME and PGP? These are cryptographically strong, essentially unforgable signatures that capture time and can ONLY be signed by the party that holds the private key. That is what i would want from a 'signing' provider.
I used to love the FireGPG plugin for firefox to "do this on gmail from firefox", however the javascript model in firefox meant that this plugin needed to be discontinued. (It could lead to private key disclosure).
Also S/MIME and PGP are open, free, standards that totally make 'graphical' signatures ancient exploitable technology.