Signing the document isn't enough. You need to be able to prove what happened to it.
Signosoft protects document integrity throughout the entire signing process. Every operation can be recorded in an audit trail, including the user, IP address, time, and document hash.
What the document protects, and what it can prove
An electronic signature is only trustworthy when it's also provable that nothing happened to the document after signing — and who signed it, when, and from where.
Audit trail for every action
History of everything done with the document: individual operations, user accounts, IP addresses, hashes, and timestamps.
Hash & integrity checking
Document integrity is checked during processing. Any change after signing is detectable.
PKI & digital certificates
Signature data is cryptographically linked to the document.
Signature data encryption
Biometric and signature data are encrypted — precisely because they're sensitive personal data.
HTTPS/SSL
Encrypted communication between the client, server, and integrated systems.
HSM & keystores
Local keystore, server keystore, or HSM — depending on your organization's requirements.
Technical detail
[TO VERIFY] penetration testing. The source brief lists penetration testing among the security topics, with an explicit condition to state it only with a verified, current source. Until we have a current report and consent to publish it, the site makes no claim about penetration testing — it's exactly the kind of detail an enterprise customer verifies.
eIDAS and GDPR
Electronic signatures under eIDAS
The eIDAS regulation recognizes electronic signatures alongside handwritten ones and distinguishes between their levels. Signosoft works with all three signature worlds — from simple, through handwritten with biometric data, to a qualified signature with a certificate, optionally in a QSCD.
Protecting personal and biometric data
Signature and biometric data are a special category of personal data. Signosoft therefore encrypts them and lets you anonymize the ID document when needed.
Independent assessment
Signosoft's compliance with GDPR and eIDAS was confirmed by an independent assessment from a court-appointed expert in cybernetics.
EU Regulation 679/2016 — GDPR EU Regulation 910/2014 — eIDAS Issued 12/11/2019, Vít Lidinský, Ph.D., court-appointed expert
[TO VERIFY] The assessment is from 2019. Before publishing, we recommend checking whether a newer one exists since then, and adding it if so — for a compliance document, age is the first thing an enterprise customer asks about.
Description of compliance, not a legal guarantee. We describe what the product does and what properties it has — which signature level a specific document needs in your jurisdiction is a legal question for your lawyer, not for a software vendor.
[TO BE ADDED] eIDAS 2.0 / EUDI Wallet. The source brief makes this conditional on a verified source: readiness for eIDAS 2.0 and the EUDI Wallet should be stated according to the current state of the product and legislation. Until we have that, there's no claim about it here. The same applies to penetration testing (see above).
What the signature is made of
Signosoft uses standard European signature formats, so the result can be verified even by a tool that has never heard of Signosoft.
PAdES — signed PDF
The signature is embedded directly in the PDF, visible or invisible. A qualified timestamp is attached to the signature, and optionally validation data (LTV) — information about the certificate's validity at the moment of signing, so the signature can still be verified after the certificate expires.
ASiC-E and XAdES — containers
You can also sign a set of arbitrary files, not just PDFs — they're packaged into an ASiC-E container with XAdES-format signatures. Simultaneous signing by multiple people and adding another signature later are both supported.
Timestamps
Timestamps from a trusted authority per RFC 3161. You can configure your own timestamping authority.
Keys & HSM
Server signing keys can be held in a standard keystore or in a hardware security module.
Certificate quality enforcement
A minimum certificate level can be enforced for each signature field. The check runs on both the client and the server.
Someone other than us can verify the signature too. Because these are standard formats, any common tool can open a signed document. Signosoft also offers Validator — a standalone application that checks a signed PDF's document integrity, certificate and its chain, revocation, and timestamp.
A secure product also needs a stable vendor
For critical processes, it's not just the technology that gets evaluated, but who's behind it and for how long.
Enterprise references
Banks, insurance companies, telecom operators, energy, and healthcare in real production use.
ReferencesCloud & on-premise
When data can't leave your infrastructure, Signosoft Server runs on your premises.
DeploymentSupport, SLA & service desk
Defined response times and a service portal for submitting requests.
Support
[TO VERIFY] vendor details. The source brief lists '15 years of experience' (noted as from a conversation, to verify the exact date before publishing) and a large number of documents processed among the trust arguments. Neither appears here as a number — an older version of the site said '13+ years,' which is exactly the kind of discrepancy that needs verifying before it gets written down again.
Have a security questionnaire?
Send it to us — we answer technical questions directly, without marketing language.