Skip to content
QUALIFIED TRUST SERVICES

Legally compliant digital signatures (eIDAS) to drive forward the digitalization of your business processes.

CORPORATE TRUST SERVICES

Cryptography-based trust services
to protect your digital identities,
data and business secrets.

Qualified electronic signature products based on eIDAS - legally binding and secure.

API GUIDE

Upgrade your application with electronic signatures by primesign.





DOCUMENT SIGNING API

Signing of PDF documents. primesign handles document processing and adds a visual signature stamp.

HASH SIGNING API

Signing of hash values. Your application handles document processing and provides the document viewer.

CASH BOX API

RKSV-compliant JWS- or raw signatures for cash box receipts.





primesign TRUST CENTER

All documents for our qualified trust services, certificate revocation list, root-/CA- certificates, etc.

RESOURCES

Fact sheets, product documentation and more.



BLOG

Insights on digital signatures, eIDAS and trust services.

BG_ICON_ARROW_3-1
Back to all questions

What is a QSCD and where is my signing key held?

A qualified electronic signature creation device (QSCD) is the certified component in which the private signing key is generated, stored and used. In remote signing that is a hardware security module (HSM) in the qualified trust service provider's data centre.

The private key never leaves that module — not to the provider, not to the user, not to an application. Even though the HSM sits with the provider, eIDAS requires the signatory's sole control over the signature creation data.

Here's how a QSCD protects the signing key:

  • Key generation inside the module: The key pair is created within the certified device; the private key is never exported.
  • Tamper-resistant hardware: Hardware security modules are physically protected against extraction and tampering and certified against recognised criteria.
  • Sole control: Every signature requires strong authentication of the authorised signatory for that specific request.
  • Separation of operation and authorisation: The operator cannot technically create a signature on the user's behalf; CEN EN 419241 describes how this is evidenced.
  • Logging: Every use of the key is logged in an audit-proof manner and remains individually traceable.
  • Revocation: On suspicion of compromise the associated certificate is revoked centrally and becomes immediately unusable.

Local and server-side QSCDs compared:

  • Local QSCD: A smart card or USB token in the signatory's possession, used with a card reader. Requires hardware and drivers on every workstation.
  • Server-side QSCD: A certified HSM at the trust service provider, triggered remotely from a mobile device or application. No hardware at the user's end.
  • Identical legal effect: Both variants produce a full QES; the eIDAS Regulation does not distinguish between them.

primesign operates its signature creation devices itself, as a listed qualified trust service provider with hosting in the EU. Key protection, patch management and revocation therefore move out of the endpoint and into an audited environment — for many organisations a net security gain over distributed smart cards.

Benefits

  • No security-critical key material on endpoint devices
  • Central patch and revocation management in an audited environment
  • No hardware rollout to employees or contract partners
  • Signing from any device and any location
  • Complete, audit-proof logging of every operation

Still have questions?

Questions about key management? Talk to our experts.

Talk to an expert