Security & Compliance

How a NextSign signature is secured

Every signature leaves a chain of cryptographic evidence that you can easily verify yourself.

Advanced electronic signatures (eIDAS)

Qualified seal from a QTSP on the EU Trusted List

GDPR with a data processing agreement

Documents in EU data centers

Live validation
nextsign-signed-example.pdf
  • Fetching the signed example document
  • Cryptographically verifying the seal (PAdES)
  • Looking up the fingerprint in NextSign's registry
Sealed by
Certificate issued by
Algorithm
Certificate valid until

The validation runs live against the same service as our public document validation. Nothing is prerecorded.

The chain of evidence

From signing to verifiable signature

Every signature goes through four documented steps, all of which leave evidence and traces that follow the document.

01

Identification with an eID

The signer identifies with MitID, MitID Erhverv or your preferred means of identification. The eID proof is verified cryptographically before the identity is accepted.

02

Complete audit log

The entire process is logged with timestamps: the link is opened, every document is read, the identity is confirmed, and the signature is placed. The log follows the case and can be exported as documentation.

03

Digital sealing

The signers' identity evidence is embedded in the document, which is then sealed with a qualified electronic seal and timestamp. Any subsequent change can be detected.

04

Independent validation

The evidence lives in the file itself and not only with us. Anyone can validate the document in Adobe Acrobat Reader, the European Commission's validator or NextSign's own document validation.

Verify it yourself

Validate a real example yourself

Download a genuine NextSign-signed document and inspect the evidence with your own eyes at an independent validation service.

Signed example document

A genuine PDF signed with MitID and sealed by NextSign. Drop the file into one of the validators and see the result for yourself.

Download example (PDF)

What the validators show

Qualification
Qualified electronic seal (QESeal)
Signature format
PAdES-BASELINE-LT
Indication
TOTAL_PASSED
Certificate chain
NextSign → SK ID Solutions (EU Trusted List)
Timestamp
Qualified timestamp embedded in the file

Because the seal, the timestamp and the certificate chain live in the file itself, the evidence is independent of NextSign. The document can be validated many years from now, even without us.

eIDAS

Which signature level do you get?

Signatures with eID at NextSign meet the requirements for advanced electronic signatures (AES) in Article 26 of the eIDAS regulation: the signer is uniquely identified via their eID, the signature is uniquely linked to the signer, and any subsequent change to the document can be detected.

Once the last signature is placed, the document is sealed with a qualified electronic seal (QESeal) issued by SK ID Solutions, a qualified trust service provider (QTSP) on the EU Trusted List, along with a qualified timestamp. XML and iXBRL documents are sealed with an XAdES signature in the same way.

Data protection

Your data is secure with us

Concrete technical measures that keep your data and documents private.

EU data centers

Documents are stored with Hetzner in EU data centers in Germany and Finland. Other subprocessors are listed in the data processing agreement.

Encryption

All traffic is encrypted in transit (TLS). Danish CPR and CVR numbers on cases are stored encrypted, and CPR numbers are automatically deleted from cases after 30 days.

No public files

Documents are never publicly accessible. Files can only be retrieved through short-lived, signed links by users with access to the case.

Access control

Role-based access per user and per folder. Two-factor login that can be made mandatory for the whole organization, plus SSO via Google and Microsoft.

Data minimization

IP addresses are masked in the audit log, and the eID's civil registration number is never stored. Only the result of the identity check is stored.

Retention & deletion

You decide the retention period per case. Expired cases are notified by email, and after a short grace period the case and all access to the documents are permanently deleted.

Operations & resilience

Built to stay available

Signatures are business-critical. Our operations are built around procedures and processing principles that ensure high uptime and short downtime.

Geo-replicated backups

Continuous backups replicated across several EU regions, with documented and tested recovery procedures.

Redundant document storage

Document files are kept in redundant object storage and additionally backed up outside the primary storage as protection against platform-specific failures.

Monitoring & alerts

All core systems are continuously monitored, and critical incidents are escalated immediately.

Continuity plan (BCDR)

A documented business continuity and disaster recovery plan, reviewed and tested regularly.

Public status page

Follow uptime and operations in real time on our public status page.

Responsible incident handling

In the event of a security incident, affected customers and relevant authorities are notified without undue delay.

GDPR & agreements

Compliance without guesswork

Agreements and standards, in black and white.

Data processing agreement (DPA)

Every business customer receives a data processing agreement, which is a prerequisite for using the platform. All subprocessors are covered by data processing agreements.

GDPR

NextSign processes document data as a data processor. Personal data is stored in the EU/EEA as a rule, and data subjects' rights are supported. See the details in our privacy policy.

eIDAS

Signatures and seals follow the eIDAS regulation (EU 910/2014), and the evidence can be verified against the EU Trusted Lists.

ISO 27001 & NIS2

We are in the process of ISO/IEC 27001 certification and already work according to the standard's principles. Our procedures are also aligned with the principles of the NIS2 directive.

Documentation for vendor assessments

Our continuity plan (BCDR), security description and data processing agreement are gladly shared as part of vendor assessments. Contact us at support@nextsign.dk.

Danish company under EU supervision

NextSign ApS, CVR 44037505, Horsens, Denmark. Subject to the GDPR and supervision by the Danish Data Protection Agency.

Questions about security & compliance

  • Signatures with eID meet the requirements for advanced electronic signatures (AES), which are legally binding in the vast majority of situations in the EU. The document is then sealed with a qualified electronic seal (QESeal) from a qualified trust service provider, proving the document's authenticity and integrity at the qualified level. If your process requires an actual QES signature, contact us before you start.

  • Yes. The seal, the timestamp and the entire certificate chain are embedded in the PDF file itself (PAdES-BASELINE-LT with long-term validation). The document can therefore be validated in, for example, Adobe Acrobat Reader or the European Commission's validator without contacting NextSign, even many years after signing.

  • In EU data centers in Germany and Finland with Hetzner. The files are never publicly accessible and can only be retrieved through short-lived, signed links by users with access to the case.

  • Yes. Every business customer receives a data processing agreement, which is a prerequisite for using the platform, and all our subprocessors are covered by data processing agreements.

  • The certification process is underway, and we already work according to the principles of ISO/IEC 27001 and NIS2. Our security procedures are documented, and we are happy to take part in vendor assessments and security reviews.

  • Every step with a timestamp: when the link was opened, each document was read, the identity was confirmed with eID, and the signature was placed, plus delivery events for email, SMS and e-Boks. IP addresses are masked, and the log can be exported as documentation.

3 free signatures · no commitment

Ready to collect legally valid signatures?

Create a free account and get started right away – no subscription and no commitment.