Skip to content
QUALIFIED TRUST SERVICES

Legally compliant digital signatures (eIDAS) to drive forward the digitalization of your business processes.

CORPORATE TRUST SERVICES

Cryptography-based trust services
to protect your digital identities,
data and business secrets.

Qualified electronic signature products based on eIDAS - legally binding and secure.

API GUIDE

Upgrade your application with electronic signatures by primesign.





DOCUMENT SIGNING API

Signing of PDF documents. primesign handles document processing and adds a visual signature stamp.

HASH SIGNING API

Signing of hash values. Your application handles document processing and provides the document viewer.

CASH BOX API

RKSV-compliant JWS- or raw signatures for cash box receipts.





primesign TRUST CENTER

All documents for our qualified trust services, certificate revocation list, root-/CA- certificates, etc.

RESOURCES

Fact sheets, product documentation and more.



BLOG

Insights on digital signatures, eIDAS and trust services.

BG_ICON_ARROW_3-1
Back to all questions

On-premise, managed service or cloud — which deployment model fits?

Signing solutions are typically deployed in one of three ways. On-premise means running in your own data centre with full control over infrastructure and data. A managed service means the provider runs a dedicated environment for you. The cloud variant is a multi-tenant service with the lowest operational overhead.

The choice rarely follows technology; it follows regulatory and organisational constraints. One thing is worth knowing up front: the qualified trust service itself — certificate issuance and the QSCD — always remains with the listed provider and cannot be moved into your own data centre.

Here's what should drive the decision:

  • Regulation: Requirements in financial services, healthcare and the public sector narrow the options and should be assessed first.
  • Data classification: For highly sensitive content, hash signing can defuse the question entirely, independently of the deployment model.
  • Operational capacity: On-premise requires your own staff for operations, patching, monitoring and round-the-clock availability.
  • Scaling and peak loads: With volatile volumes — month-end invoice runs, for instance — cloud deployment shows its strengths.
  • Integration depth: The tighter the coupling to internal systems, the stronger the case for on-premise or a managed service.
  • Cost structure: On-premise ties up capital and staffing; cloud and managed service shift these into operating expenditure.

A common misconception:

  • On-premise does not equal sovereignty: The qualified trust service always remains external. What can run on-premise is the signing and workflow application.
  • Hash signing as the alternative: For data protection concerns, the Hash Signing API is often the more effective answer than the deployment model — documents never leave your boundary.
  • Hybrid is the norm: Many organisations run the workflow component internally while consuming the qualified trust service externally.

primesign supports all three deployment models — on-premise, managed service and cloud with EU hosting — with both primesign ENTERPRISE and the primesign SIGNATURE SERVER. The operating model can therefore be matched to regulatory requirements without changing trust service provider.

Benefits

  • Regulatory requirements met without changing provider
  • Operating model matched to your own IT capacity
  • EU hosting as standard for privacy-sensitive processes
  • Scaling for peak loads without your own infrastructure
  • Later change of deployment model without re-integration

Still have questions?

Have our architects assess your target deployment model.

Talk to an expert