Security & Compliance
How a NextSign signature is secured
Every signature leaves a chain of cryptographic evidence that you can easily verify yourself.
Advanced electronic signatures (eIDAS)
Qualified seal from a QTSP on the EU Trusted List
GDPR with a data processing agreement
Documents in EU data centers
- Fetching the signed example document
- Cryptographically verifying the seal (PAdES)
- Looking up the fingerprint in NextSign's registry
- Sealed by
- Certificate issued by
- Algorithm
- Certificate valid until
The validation runs live against the same service as our public document validation. Nothing is prerecorded.
The chain of evidence
From signing to verifiable signature
Every signature goes through four documented steps, all of which leave evidence and traces that follow the document.
Identification with an eID
The signer identifies with MitID, MitID Erhverv or your preferred means of identification. The eID proof is verified cryptographically before the identity is accepted.
Complete audit log
The entire process is logged with timestamps: the link is opened, every document is read, the identity is confirmed, and the signature is placed. The log follows the case and can be exported as documentation.
Digital sealing
The signers' identity evidence is embedded in the document, which is then sealed with a qualified electronic seal and timestamp. Any subsequent change can be detected.
Independent validation
The evidence lives in the file itself and not only with us. Anyone can validate the document in Adobe Acrobat Reader, the European Commission's validator or NextSign's own document validation.
Verify it yourself
Validate a real example yourself
Download a genuine NextSign-signed document and inspect the evidence with your own eyes at an independent validation service.
Signed example document
A genuine PDF signed with MitID and sealed by NextSign. Drop the file into one of the validators and see the result for yourself.
Download example (PDF)What the validators show
- Qualification
- Qualified electronic seal (QESeal)
- Signature format
- PAdES-BASELINE-LT
- Indication
- TOTAL_PASSED
- Certificate chain
- NextSign → SK ID Solutions (EU Trusted List)
- Timestamp
- Qualified timestamp embedded in the file
Because the seal, the timestamp and the certificate chain live in the file itself, the evidence is independent of NextSign. The document can be validated many years from now, even without us.
Validate the document here
The European Commission's DSS validator
Official eIDAS validation against the EU Trusted Lists.
The Danish public-sector validator
The authorities' signature validation at validering.ca1.gov.dk.
Adobe Acrobat Reader
Open the file and see the seal shown as valid in the signature panel.
NextSign's document validation
Free validation that also matches the file's fingerprint against NextSign's registry.
eIDAS
Which signature level do you get?
Signatures with eID at NextSign meet the requirements for advanced electronic signatures (AES) in Article 26 of the eIDAS regulation: the signer is uniquely identified via their eID, the signature is uniquely linked to the signer, and any subsequent change to the document can be detected.
Once the last signature is placed, the document is sealed with a qualified electronic seal (QESeal) issued by SK ID Solutions, a qualified trust service provider (QTSP) on the EU Trusted List, along with a qualified timestamp. XML and iXBRL documents are sealed with an XAdES signature in the same way.
Data protection
Your data is secure with us
Concrete technical measures that keep your data and documents private.
EU data centers
Documents are stored with Hetzner in EU data centers in Germany and Finland. Other subprocessors are listed in the data processing agreement.
Encryption
All traffic is encrypted in transit (TLS). Danish CPR and CVR numbers on cases are stored encrypted, and CPR numbers are automatically deleted from cases after 30 days.
No public files
Documents are never publicly accessible. Files can only be retrieved through short-lived, signed links by users with access to the case.
Access control
Role-based access per user and per folder. Two-factor login that can be made mandatory for the whole organization, plus SSO via Google and Microsoft.
Data minimization
IP addresses are masked in the audit log, and the eID's civil registration number is never stored. Only the result of the identity check is stored.
Retention & deletion
You decide the retention period per case. Expired cases are notified by email, and after a short grace period the case and all access to the documents are permanently deleted.
Operations & resilience
Built to stay available
Signatures are business-critical. Our operations are built around procedures and processing principles that ensure high uptime and short downtime.
Geo-replicated backups
Continuous backups replicated across several EU regions, with documented and tested recovery procedures.
Redundant document storage
Document files are kept in redundant object storage and additionally backed up outside the primary storage as protection against platform-specific failures.
Monitoring & alerts
All core systems are continuously monitored, and critical incidents are escalated immediately.
Continuity plan (BCDR)
A documented business continuity and disaster recovery plan, reviewed and tested regularly.
Public status page
Follow uptime and operations in real time on our public status page.
Responsible incident handling
In the event of a security incident, affected customers and relevant authorities are notified without undue delay.
GDPR & agreements
Compliance without guesswork
Agreements and standards, in black and white.
Data processing agreement (DPA)
Every business customer receives a data processing agreement, which is a prerequisite for using the platform. All subprocessors are covered by data processing agreements.
GDPR
NextSign processes document data as a data processor. Personal data is stored in the EU/EEA as a rule, and data subjects' rights are supported. See the details in our privacy policy.
eIDAS
Signatures and seals follow the eIDAS regulation (EU 910/2014), and the evidence can be verified against the EU Trusted Lists.
ISO 27001 & NIS2
We are in the process of ISO/IEC 27001 certification and already work according to the standard's principles. Our procedures are also aligned with the principles of the NIS2 directive.
Documentation for vendor assessments
Our continuity plan (BCDR), security description and data processing agreement are gladly shared as part of vendor assessments. Contact us at support@nextsign.dk.
Danish company under EU supervision
NextSign ApS, CVR 44037505, Horsens, Denmark. Subject to the GDPR and supervision by the Danish Data Protection Agency.
Questions about security & compliance
Signatures with eID meet the requirements for advanced electronic signatures (AES), which are legally binding in the vast majority of situations in the EU. The document is then sealed with a qualified electronic seal (QESeal) from a qualified trust service provider, proving the document's authenticity and integrity at the qualified level. If your process requires an actual QES signature, contact us before you start.
Yes. The seal, the timestamp and the entire certificate chain are embedded in the PDF file itself (PAdES-BASELINE-LT with long-term validation). The document can therefore be validated in, for example, Adobe Acrobat Reader or the European Commission's validator without contacting NextSign, even many years after signing.
In EU data centers in Germany and Finland with Hetzner. The files are never publicly accessible and can only be retrieved through short-lived, signed links by users with access to the case.
Yes. Every business customer receives a data processing agreement, which is a prerequisite for using the platform, and all our subprocessors are covered by data processing agreements.
The certification process is underway, and we already work according to the principles of ISO/IEC 27001 and NIS2. Our security procedures are documented, and we are happy to take part in vendor assessments and security reviews.
Every step with a timestamp: when the link was opened, each document was read, the identity was confirmed with eID, and the signature was placed, plus delivery events for email, SMS and e-Boks. IP addresses are masked, and the log can be exported as documentation.
Ready to collect legally valid signatures?
Create a free account and get started right away – no subscription and no commitment.