Skip to main content

Legal validity


Three levels of electronic signature

eIDAS — Regulation (EU) No 910/2014 — is the framework that governs electronic signatures across the European Union. It recognises three levels.


Basic

An electronic signature in its simplest form: a name typed into a document, a scanned image of a handwriting, a tick in a box. Nothing about it establishes who applied it.


Advanced

A signature uniquely linked to its signer, capable of identifying them, created using means the signer controls, and linked to the document such that any later change is detectable. This is the level eSoppari produces.


Qualified

An advanced signature created on certified signature-creation hardware with a certificate issued by a qualified trust service provider. eSoppari does not offer this level.


What eSoppari delivers

Each signature is applied as an advanced electronic seal (Reg. 910/2014 Art. 36) over the signer's verified eID authentication, with an RFC 3161 timestamp from an EU-qualified timestamping authority and long-term validation data embedded in the document (PAdES-B-LT).

The identification underneath that seal is not incidental. Every signer authenticates with a national eID at the eIDAS High assurance level, so the question a dispute usually turns on — was it really this person — is answered by the identification scheme rather than by us.


Why we target the advanced level

The choice to stop at the advanced level is deliberate, not a gap we intend to close. Qualified signatures require certified signature-creation devices and a qualified certificate for each individual signer; that adds cost and friction for every person you ask to sign.

For the great majority of business documents — contracts, minutes, employment papers, financial statements — an advanced signature backed by strong identification is what counterparties actually look for. We would rather do that level thoroughly, on every signature, than offer a qualified tier alongside a weak one. If your situation genuinely requires a qualified signature, eSoppari is not the right tool for it, and we would tell you so.


Integrity and non-repudiation

The signature covers the document as a whole. Any alteration made after signing — a changed figure, an added page, a removed clause — breaks the cryptographic link and is detectable by anyone who checks the file. There is no way to modify a signed document quietly.

Because the validation data travels inside the PDF, the evidence that a signature was valid at the moment it was made stays with the document. A signer cannot credibly claim afterwards that the signature was never theirs, and a holder cannot alter what was signed without it showing.


When an electronic signature is not enough

Some document types are required by law to follow a specific form, and for those an electronic signature — at any level — may not satisfy the requirement. The rules differ between countries and between document types, and they change.

Before moving a class of document to electronic signing, check the requirement that applies to that document type in the jurisdiction that governs it. We are not able to make that determination for you.


Checking a signed document

Anyone holding a finished document can open the verification link the document itself carries, free of charge and with no account. The check confirms the document has not been altered and reports what each signature covers.

The same file can also be opened in any PAdES-aware PDF reader, which will validate the signatures from the data embedded in the document. That path does not involve us at all — which is the point.

How we secure it

The legal argument rests on the technical one. Security sets out the mechanisms behind every claim on this page.