Skip to content
QUALIFIED TRUST SERVICES

Legally compliant digital signatures (eIDAS) to drive forward the digitalization of your business processes.

CORPORATE TRUST SERVICES

Cryptography-based trust services
to protect your digital identities,
data and business secrets.

Qualified electronic signature products based on eIDAS - legally binding and secure.

API GUIDE

Upgrade your application with electronic signatures by primesign.





DOCUMENT SIGNING API

Signing of PDF documents. primesign handles document processing and adds a visual signature stamp.

HASH SIGNING API

Signing of hash values. Your application handles document processing and provides the document viewer.

CASH BOX API

RKSV-compliant JWS- or raw signatures for cash box receipts.





primesign TRUST CENTER

All documents for our qualified trust services, certificate revocation list, root-/CA- certificates, etc.

RESOURCES

Fact sheets, product documentation and more.



BLOG

Insights on digital signatures, eIDAS and trust services.

BG_ICON_ARROW_3-1
Back to all questions

Is remote signing as secure as a signature card?

Yes — legally and technically. The eIDAS Regulation does not distinguish between a qualified signature creation device held locally by the signatory and one operated server-side by the provider. Both must be certified as a QSCD and must ensure the signatory's sole control over the signature creation data.

For server-side devices, the CEN EN 419241 series defines how that sole control is demonstrated. In practice remote signing is often the safer option, because it avoids the typical weaknesses of distributed smart card deployments.

Here's how sole control is established server-side:

  • The key stays in the HSM: The private key is generated inside the hardware security module and never leaves it — not to the provider, not to the user.
  • Request-specific authorisation: A signature is released only when a correct two-factor authentication exists for that specific signing request. There is no blanket standing permission.
  • Technical separation: The operator cannot create a signature on the user's behalf; the authorisation logic is separated from the operating organisation.
  • Complete logging: Every operation is logged and remains individually traceable afterwards.
  • Certification under CEN EN 419241: The standard series specifies the requirements for trustworthy systems supporting server signing and how compliance is evidenced.
  • Regular audits: Qualified providers are audited on a recurring basis by a conformity assessment body.

Where remote signing is stronger than a card:

  • No physical tokens to lose: Smart cards and PINs can be lost, shared or copied — with an HSM that risk disappears.
  • No driver problems: Unpatched card reader drivers on endpoints are a known attack surface that does not exist with remote signing.
  • Central revocation: On suspicion of compromise the provider can revoke centrally and immediately, rather than collecting hardware.

primesign operates its signature creation devices as a listed qualified trust service provider with hosting in the EU. The corresponding evidence, root and CA certificates and revocation lists are published in the primesign Trust Center and can therefore be verified independently.

Benefits

  • Key protection inside an audited data centre environment
  • No security-critical hardware on endpoint devices
  • Immediate central revocation in suspected incidents
  • Audit-proof logging of every signing operation
  • Publicly verifiable certification and conformity evidence

Still have questions?

Questions about the security architecture? Our experts will walk you through it.

Talk to an expert