PAdES lifecycle
PAdES B-B and B-T depend on certificate and timestamp configuration. B-LTA requires the configured EU DSS upgrade path.
B-B → B-T → B-LTA
Securely architected
Security controls and signing evidence are built into the workflow. Encryption, certificate, timestamp, and long-term validation levels depend on deployment and document configuration.
Signature integrity
Designed around eIDAS and durable PDF signature standards.
PAdES B-B and B-T depend on certificate and timestamp configuration. B-LTA requires the configured EU DSS upgrade path.
B-B → B-T → B-LTA
When configured, an X.509 certificate seals the completed document and binds the final PDF to a verifiable signature chain.
X.509 · SHA-256
External RFC 3161 timestamps can prove when a signature and final seal existed when a timestamp authority is selected.
RFC 3161
Defense in depth
AES-256-GCM document encryption is available when enabled. Keys and envelopes remain separated.
Uploaded PDFs are inspected before entering a signing workflow.
TOTP, WebAuthn and email OTP. Identity checks without weakening the audit chain.
No third-party CAPTCHA. A privacy-respecting proof-of-work challenge limits automated abuse.
Export and deletion workflows support data-subject requests and retention policies.
IP address, user-agent and geo context accompany signing and access events.
Regional context
Electronic-signature requirements, excluded documents, and higher-assurance signature rules vary by country.
ESIGN Act · UETA
eIDAS · eIDAS 2.0
UK eIDAS context
MP 2.200-2 · ICP-Brasil context
Commercial Code · NOM-151 context
Law 527 context
This overview is educational, not legal advice. Suitability depends on the document, identity level, trust service, and local law.
Ready when you are
Start free, then review security and verification on a real completed document.