Loading ...

Electronic Signature

A signature is not an image placed on top of a document.

Documenos ®

In Documenos®, an electronic signature is a cryptographic structure written into the file itself: if a single byte of the document changes after signing, the signature becomes invalid. So the signature answers not only "who approved it?" but also "has this document changed since then?"

Signing is done from Documenos®'s own screen, as a task on the document; you don't need to move the document to another application to sign it.

Four signature formats

Not every file type can be signed the same way. Documenos® produces four different formats, and the system decides which one applies to which file:

XAdES

For XML documents.

CAdES

For binary and general files.

PAdES

For PDF. The signature is embedded in the PDF, the file remains a PDF and continues to open in any PDF reader.

JAdES

For JSON and web service payloads.

Relationship with eIDAS

Signatures are produced with the DSS library developed by the European Commission, in the XAdES, CAdES, PAdES and JAdES formats defined by eIDAS; in other words, they follow the standard structure defined in the European Union and can be read and verified by other systems that support these standards.

A distinction

eIDAS certification is granted to the provider, not the software

We prefer to state this clearly: eIDAS certification is granted to the trust service provider, not to the software. What determines the legal validity of your signature is the provider from which you obtained your qualified certificate. Documenos®'s responsibility is to produce a standards-compliant signature correctly with that certificate.

Four signature levels: B, T, LT, LTA

How long a signature remains verifiable depends on the level at which it was produced. Documenos® produces all four:

B — Basic

Basic signature.

T — Timestamped

A timestamp is added to the signature.

LT — Long-Term

Long-term validation.

LTA — Long-Term Archival

Archival level; the signature can still be verified many years later.

This distinction matters directly for documents with long retention periods: a commitment letter you must keep for fifteen years may not be verifiable years later if it is signed at the basic level today. A document signed at LTA level remains verifiable for the number of years defined in your retention plan.

Is the signer really that person?

The real risk with electronic signatures is not that a signature is technically invalid, but that someone signs with another person's certificate. To prevent this, Documenos® compares the certificate owner with the user in the system at the moment of signing; if they do not match, the signing is rejected.

The result: even if a user has someone else's USB token, they cannot sign their own task with it. The person whose signature appears in the system is the person who actually signed.

Your organization can enforce its own signature standard

Signature format, level, packaging, container type and digest algorithm are configured at the organization level. If these settings are marked as "mandatory", users cannot deviate from them when signing.

In practice, this means the organization defines its signature standard once, and users no longer need to understand each technical option or risk choosing the wrong one. It is a setting whose value grows with the number of documents: having every document in your archive signed to the same standard eliminates surprises years down the line.

The signature is a step in the flow

In Documenos®, signing is not a standalone operation performed in a separate application; it is a step in the signature and approval chain. When a document reaches you, you see the task in your inbox, sign it, and the document continues on its way. Whether the signer is actually authorized at that step is verified through the chain.

Not every step in the chain has to be completed the same way: internal approvals can proceed with a click, while the final step with legal effect can be completed with an electronic signature. You require exactly as much assurance as each step needs.

Signing is done with a USB token: the user opens the task from the inbox, plugs in the token and signs. If a document has several files — the main document and its attachments — they are signed together.

Nor is signing a capability tied only to the document module: contract, quality and form flows all share the same signature infrastructure.

Documenos ®