Skip to content
QUALIFIED TRUST SERVICES

Legally compliant digital signatures (eIDAS) to drive forward the digitalization of your business processes.

CORPORATE TRUST SERVICES

Cryptography-based trust services
to protect your digital identities,
data and business secrets.

Qualified electronic signature products based on eIDAS - legally binding and secure.

API GUIDE

Upgrade your application with electronic signatures by primesign.





DOCUMENT SIGNING API

Signing of PDF documents. primesign handles document processing and adds a visual signature stamp.

HASH SIGNING API

Signing of hash values. Your application handles document processing and provides the document viewer.

CASH BOX API

RKSV-compliant JWS- or raw signatures for cash box receipts.





primesign TRUST CENTER

All documents for our qualified trust services, certificate revocation list, root-/CA- certificates, etc.

RESOURCES

Fact sheets, product documentation and more.



BLOG

Insights on digital signatures, eIDAS and trust services.

BG_ICON_ARROW_3-1
Back to all questions

What is remote signing and how does it work?

Remote signing means a qualified electronic signature is triggered without a local signature creation device such as a smart card and reader at the signatory's end. The private key sits instead in a certified hardware security module operated by the qualified trust service provider.

The signature is released after strong authentication, in practice usually via a mobile phone. Remote signing is legally equivalent to card-based signing in every respect — the eIDAS Regulation does not distinguish between locally held and server-side signature creation devices.

Here's how remote signing works:

  • Identification: Once, via eID, video identification or in person. The verified digital identity is then available for all subsequent signatures.
  • Certificate issuance: The qualified trust service provider issues the qualified certificate and binds it to the verified identity.
  • Key custody in the HSM: The key pair is generated inside the certified hardware security module; the private key never leaves it.
  • Two-factor authentication: Before each signature the signatory authenticates with two factors — for example app confirmation plus biometrics or a PIN.
  • Signature release: The HSM creates the signature only for the specific authorised request and under the signatory's sole control.
  • Return and logging: The signed PDF is returned with a timestamp and validation data; every operation is logged in an audit-proof manner.

Why remote signing was the breakthrough:

  • No hardware at the user's end: Card-based signing never scaled because every workstation needed a reader, drivers and a smart card.
  • Mobile signing: Only remote signing makes qualified signing practical on a smartphone, and therefore in customer-facing journeys.
  • External counterparties: Customers and suppliers can sign without you having to issue them hardware or certificates.

primesign operates its remote signing service as a listed qualified trust service provider, with EU hosting and 99.8% guaranteed availability. Through primesign REMOTE SIGNING, documents can be signed immediately and without prior user registration using the German national ID card or ID Austria; a publicly accessible status page shows availability and upcoming maintenance windows.

Benefits

  • Qualified signing without a card reader or additional software
  • Signing from any location and any device
  • No hardware distribution to employees or counterparties
  • Central revocation and complete logging
  • Full legal effect under Article 25(2) eIDAS

Still have questions?

Try qualified remote signing with primesign.

Talk to an expert