Skip to main content
Certyneo

Electronic signature glossary

112 key terms to master electronic signatures, cryptography and eIDAS compliance.

Beyond the definitions, put them into practice: discover Certyneo's electronic signature solution

Updated on .

Glossaire signature électronique — références et définitions

A

Electronic authentic deed (AAE)
An electronic authentic deed (AAE) is a notarial deed drawn up, received, and kept in digital form in accordance with Decree No. 2005-973 of August 10, 2005. The notary affixes their qualified electronic signature (QES level, eIDAS) using an authorized QSCD, and the deed is then sent to the Real.not platform (Electronic Network of Notarial Deeds). The AAE has the same probative force and enforceability as a paper deed: it constitutes perfect proof of its contents and can support enforcement without prior judgment. Real estate contracts, donations, business mergers, and future protection mandates are among the deeds that may be drawn up in electronic form. Certyneo assists notary offices in implementing co-signature workflows upstream (preliminary contracts, sale mandates) before signing the authentic deed at the notary.
AES (Advanced Electronic Signature)
AES is the acronym for Advanced Electronic Signature, the advanced electronic signature defined by article 26 of the eIDAS regulation — see the advanced signature sheet for detailed requirements, the comparison SES / AES / QES and use cases. Not to be confused with the other AES in cryptography, the Advanced Encryption Standard, a encryption algorithm with no connection to signature.
Electronic signature REST API
A REST API (Representational State Transfer) for electronic signature exposes the signature engine's operations as HTTP resources accessible by any programming language. Typical workflows include: envelope creation (POST /envelopes), document upload (PUT /envelopes/{id}/documents), adding signers and fields (POST /recipients), sending for signature (PUT /envelopes/{id}/send), then retrieving the signed document (GET /envelopes/{id}/signed-pdf). Authentication relies on Bearer tokens (OAuth 2.0 / API keys). Webhooks complement the API by pushing events (document signed, rejected, expired) to your backend without polling. A good electronic signature REST API guarantees document integrity via a SHA-256 hash returned at each step and supports timestamped audit trail. Certyneo exposes a complete REST API documented in OpenAPI 3.1 with SDKs available in Node.js, Python and PHP.
Electronic archiving (signature, evidentiary value)
Electronic archiving refers to the long-term preservation of signed digital documents under conditions that guarantee their evidential value, readability and integrity over time. Not to be confused with simple backup: evidential archiving imposes precise technical and legal constraints that distinguish it from simple cloud storage.

The three pillars of evidential archiving :
• Integrity : the archived document cannot be modified — any alteration is detectable and invalidates the proof. Guaranteed by cryptographic hashing of the document at archiving and periodic verification of this hash.
• Durability : the document remains readable in 10, 20 or 50 years, independently of software evolution. This requires standardized formats (PDF/A for content, PAdES B-LTA for signature) and migration of media at regular intervals.
• Traceability : any operation on the archived document (consultation, communication, deletion) is recorded in a time-stamped and tamper-proof event log.

Regulatory framework : in France, evidential archiving is governed by the standards NF Z42-013 (French standard, AFNOR) and the international standard ISO 14641. For the public sector and certain regulated activities (healthcare, financial services), approval by SIAF (Interministerial Service of French Archives) or certification by a qualified third-party archiver are required. The eIDAS 2.0 regulation introduces a new qualified trust service dedicated to qualified electronic archiving, recognized as of right throughout the EU.

Legal retention period in France:
• Commercial contracts and invoices: 10 years (Commercial Code art. L123-22)
• Employment contracts: 5 years after employee departure
• Tax documents: 6 years (Book of Tax Procedures art. L102 B)
• Notarial deeds: 75 years (Notarial Code)
• Medical documents: 20 years after the last act (Public Health Code)

Certyneo implementation : all signed documents are archived in PAdES B-LT format (B-LTA available on Business plan for storage > 10 years), with qualified RFC 3161 time-stamping, 10-year retention included in all plans, event log viewable at any time, and download of the audit trail in PDF format. See also evidential value and LTV (Long-Term Validation). Complete guide to electronic archiving with evidential value →
Attestation France Travail
The certificate for France Travail (formerly Pôle emploi) is a document that the employer must compulsorily provide to the employee at the end of their contract (art. R1234-9 of the Labour Code). It allows the employee to claim unemployment insurance benefits; the employer also transmits it to France Travail. It can be generated and signed electronically in the end-of-contract process. Mandatory end-of-contract documents →
Authentication
Authentication is the process of verifying the identity of a user or system before granting them access to a service or authorizing the application of an electronic signature. It can be simple (password alone), strong (multi-factor) or biometric. The robustness of authentication directly determines the signature level achievable: an AES requires at least two distinct factors.
Strong authentication
Strong authentication requires the presentation of at least two proofs of identity belonging to different categories to verify a person''s identity — this is the principle of MFA (multi-factor authentication) :
• What I know : password, PIN code ;
• What I have : phone receiving an OTP code, YubiKey/FIDO2 security key, smart card ;
• What I am : fingerprint, facial recognition (biometrics).

Two regulatory frameworks require it : the DSP2 directive (art. 97) requires SCA — Strong Customer Authentication — for payments and access to online bank accounts; the eIDAS regulation requires it de facto for advanced electronic signature (AES), article 26 of which requires that the signature be created under the exclusive control of the signatory and be linked to them in a unique manner.

In electronic signature, strong authentication occurs at the moment of signing: the signatory proves they control their email address (unique link) and their phone (SMS OTP code) before the document is sealed. This double verification, time-stamped in the audit trail, is what distinguishes an enforceable AES from a simple checkbox.

On Certyneo : for envelopes at the advanced level, the email + SMS OTP combination is applied by default to each signatory; user accounts can enable MFA (TOTP or email OTP). DSP2 & strong authentication: the guide →
Certification Authority (CA)
A certification authority (CA) is a trusted organization that issues X.509 electronic certificates linking a public key to the identity of its holder. Qualified CAs are supervised by national authorities (ANSSI in France) and registered on the EU trust list. They form the foundation of the PKI and the trust chain of qualified signatures.

B

Bearer token
A bearer token is an API access token that grants whoever holds it ("the bearer") the right to access protected resources, without any other identity proof — possession alone is sufficient, like cash. It is transmitted in the HTTP header Authorization: Bearer <token>. In OAuth 2.0: bearer tokens are the standard access token format; they are generally short-lived and carry scopes that limit what the bearer can do. Certyneo''s REST API uses bearer tokens to authenticate programmatic calls: creation of envelopes, status queries, webhook configuration, and download of signed documents. Security concerns: since the token is the identifier, it must only travel over TLS, never be exposed client-side nor logged, and be renewed regularly; a leaked bearer token is as dangerous as a leaked password until its expiration or revocation. Best practice: limit each token to strictly necessary permissions, set a short expiration, and prefer one token per integration so you can revoke one without affecting others.
Biometrics
Biometrics encompasses identification techniques based on a person''s physical or behavioral characteristics (fingerprint, facial recognition, handwriting pattern, voice). In electronic signature, biometric signature can capture the handwriting pattern on a touch screen (speed, pressure, angle) to create a direct link between the signatory and their consent. Under eIDAS, biometrics alone is insufficient to reach the advanced level (AES): it must be combined with strong authentication. Biometric data is considered sensitive under GDPR and its processing requires explicit consent.
Blockchain and electronic notarization
Blockchain notarization consists of anchoring the cryptographic fingerprint (SHA-256 hash) of a document in an immutable distributed ledger (Bitcoin, Ethereum, etc.) to prove its existence at a given point in time. Unlike RFC 3161 qualified timestamps, blockchain notarization is not recognized as legal proof under eIDAS: it constitutes admissible evidence before certain jurisdictions but does not replace an accredited QTSP. Its advantage is decentralization: the proof survives the disappearance of the service provider. In an enterprise context, blockchain is most relevant for archiving supplementary evidence (hash published on-chain) as a redundancy layer above standard electronic archiving with evidentiary value.

C

Electronic seal
Electronic seal is the equivalent of electronic signature for legal entities (companies, administrations). It guarantees the origin and integrity of a document issued on behalf of an organization without involving an identified human signatory. The eIDAS regulation recognizes simple, advanced, and qualified electronic seals in the same way as signatures.
SSL / TLS padlock
The SSL/TLS padlock is the visual indicator displayed by the browser (padlock icon in the address bar) confirming that an encrypted TLS connection is established between the browser and the server. It attests that the exchanged data (documents, OTP codes, credentials) cannot be intercepted in plain text. Certyneo enforces TLS 1.3 across all its endpoints, making the padlock visible on all signature pages.
Certificat de travail (employment certificate)
The work certificate is a document that the employer must compulsorily provide to the employee at the end of any employment contract (art. L1234-19 and D1234-6 of the Labour Code), regardless of the reason for termination. It mentions the entry and exit dates, the nature of positions held and corresponding periods. It is a "retrieval" document: it is held at the employee''s disposal, who comes to collect it. It can be signed and delivered electronically with full legal effect. See all end-of-contract documents →
Electronic certificate
An electronic certificate is a digital file issued by a certification authority (CA) that associates a public key with the verified identity of its holder — it is also called a digital signature certificate when used to sign. It is the digital identity document on which all digital signature rests.

What a certificate contains : the identity of the holder (Distinguished Name), their public key, the issuing CA, the validity period (typically 1 to 3 years), authorized uses (signature, seal, TLS) and the cryptographic fingerprint of the whole, signed by the CA.

The chain of trust : each certificate is signed by a CA, itself certified by a higher-level CA, up to the root certificate. Verifying a signature amounts to going up this chain — and checking that the certificate has not been revoked (CRL lists, OCSP protocol).

Simple or qualified certificate : a standard certificate is sufficient for advanced signature (AES) ; qualified signature (QES) requires a qualified certificate, issued by a qualified trust service provider after face-to-face identity verification or equivalent.

On Certyneo : you have no certificate to purchase or install — signature certificates are carried by the platform and applied on the server side at the time of PAdES sealing of the document. The digital signature certificate: complete guide →
Qualified certificate
A qualified certificate is an electronic certificate issued by a qualified trust service provider (QTSP) listed on the trust list of an EU Member State — the highest level of assurance recognized by the eIDAS regulation.

What it adds to a standard certificate : the holder''s identity is verified before issuance (physical face-to-face, video identification or equivalent electronic identity) ; the private key is protected in a certified device (QSCD, often backed by an HSM) ; and the QTSP is audited regularly by the national supervisory body (in France, ANSSI).

What is it for? It is the mandatory component of qualified signature (QES), the only one to benefit from automatic equivalence with handwritten signature throughout the EU (art. 25 eIDAS), with presumption of reliability in case of dispute. It is required for the most sensitive acts: attorney deeds, certain public procurement, business transfers.

On Certyneo : QES is offered on a per-transaction basis, without a dedicated subscription — the signatory''s identity verification and qualified certificate issuance are integrated into the signing process. Qualified signature (QES) at Certyneo →
Root certificate and trust chain
A root certificate is the apex of the PKI: self-signed by the root certification authority, it anchors the trust of the entire chain. When verifying an electronic signature, the verifier traverses the certificate chain (End Entity → Intermediate(s) → Root) and verifies that each link is valid, not revoked (OCSP / CRL) and compliant with its usage policy. Browsers and operating systems embed trusted root stores (Mozilla NSS, Microsoft Root Store, Apple Root Certificate Program). For eIDAS qualified signatures, the chain must trace back to a QTSP listed on the EU trust list. A certificate whose root is not in the verifier''s store will be rejected even if the cryptographic signature is technically correct.
Encryption
Encryption is the process of transforming a readable message into an unreadable format (ciphertext) using an algorithm and a secret key. It protects the confidentiality of data in transit and at rest, and is complementary to hashing used to guarantee integrity in signature. Certyneo uses TLS 1.3 to encrypt all communications between the browser and servers.
Encryption at rest
Encryption at rest refers to the protection of stored data through encryption, so that it is unreadable without the decryption key, even in case of unauthorized physical or logical access to the storage medium. Certyneo encrypts documents and their audit trails at rest (AES-256) on its infrastructure hosted in Germany, in compliance with GDPR requirements.
CLM (Contract Lifecycle Management)
CLM (Contract Lifecycle Management) refers to the set of processes and tools covering the complete lifecycle of a contract: drafting, negotiation, internal approval, electronic signature, storage and renewal. Single repository: a CLM solution centralizes all contracts in a single queryable repository, with expiration alerts, clause libraries, validation workflows and contract exposure reports, replacing scattered email threads and shared drives. Place of signature: electronic signature is one step in the CLM chain — once the contract is approved, it moves to signature and then to archiving with probative value. Integration with Certyneo: Certyneo covers the signature phase and integrates with a third-party CLM via REST API — it receives the finalized document, manages the signature circuit (sequential or parallel, at advanced (AES) or qualified (QES) level), and returns the signed PDF with a timestamped audit trail that the CLM archives as the definitive version. Why it matters: a signed contract but not tracked in a CLM still exposes the company to missed renewals and tacit renewal penalties, hence the increasingly joint purchase of signature and lifecycle management.
Co-signature and multiple signatures
Co-signature designates the collection of at least two signatures on the same document. Two modes are distinguished: sequential signature (signer B receives the invitation only after A has signed — useful for hierarchical contracts or notarial deeds) and parallel signature (all signers receive the invitation simultaneously — faster for symmetric documents). Co-signature raises the question of inter-round integrity: each PAdES added in the PDF must reference the previous revision via an incremental signature, ensuring that no party has modified the document between two appositions. Certyneo manages signer order, targeted reminders, per-signer expiration deadlines, and automatically detects inter-round modification attempts via SHA-256 hash verification at each step of the audit trail.
OTP (One-Time Password / OTP code)
An OTP (One-Time Password — sometimes called "OTP code" in French) is a temporary numerical code, usually 4 to 8 digits, randomly generated and valid for a single session or transaction. Once used or expired (typically 5 minutes), it becomes invalid — even if an attacker replayed it, it would be rejected.

Three main OTP variants :
• OTP SMS : code sent by text message to the signer''s phone number. Most common on the consumer side because no application is required. Known vulnerabilities: SIM swapping, SS7 interception — which is why OTP SMS is sufficient for advanced signature (AES) but is no longer accepted for QES (ANSSI and ENISA have recommended since 2020 switching to stronger factors).
• OTP e-mail : code sent by e-mail. Easier to implement, but inherits the weaknesses of the recipient''s e-mail account security. Acceptable for simple signature (SES).
• TOTP (Time-based OTP) : code generated locally by an application on the signer''s phone (Google Authenticator, Authy, 1Password). Synchronized via a shared secret key at registration. No network channel at the time of signature — resistant to interceptions. Standard RFC 6238.

OTP and electronic signature : in advanced electronic signature, sending an OTP via e-mail or SMS creates a verifiable link between the signed document and the identity of the signer via their communication channel (phone or e-mail). The OTP is recorded in the document''s audit trail (timestamp, IP, channel identifier) — evidence that can be raised in case of dispute.

Certyneo implementation : OTP SMS via Twilio Verify on AES envelopes — triggered just before signature, valid for 5 minutes, 3 attempts. TOTP available for administrator accounts as an alternative to SMS OTP. See also MFA and strong authentication. Learn more about signer authentication →
Compliance
Compliance refers to the adherence to laws, regulations and standards applicable to an organization. In the context of electronic signature, it notably refers to the eIDAS regulation, the GDPR, the Labor Code (for employment contracts), the ALUR law (real estate) and ethical rules specific to certain professions (CNB for lawyers, CSN for notaries). Non-compliance exposes the company to the nullity of its acts and administrative sanctions.
Electronic consent
Electronic consent is the manifestation of will of a person, expressed by digital means, to accept terms or to sign a document. To have probative force, this consent must be freely given, specific, informed and unambiguous, in accordance with the GDPR. In a signature workflow, clicking "Sign" constitutes the electronic consent of the signer.
Electronic contract
An electronic contract is any agreement of will formed by digital means, governed in France by articles 1366 to 1368 of the Civil Code and the LCEN. Unlike simple online ordering, an electronic contract involves a multi-step procedure: offer, pre-contractual information, explicit acceptance ("click to accept" or electronic signature), then evidentiary preservation for the legal duration. Evidentiary value is strengthened by adding: an advanced signature (AES) or qualified (QES), a qualified timestamp, capture of consent and the signer''s IP address. The eIDAS 2 regulation extends these requirements to cross-border contracts within the EU through the European Digital Identity Wallet.
CRL (Certificate Revocation List)
A CRL (certificate revocation list) is a list published periodically by a certification authority listing certificates revoked before their expiration date, usually due to key compromise or change of identity. When verifying a digital signature, the software consults the CRL (or uses OCSP) to ensure that the signer''s certificate was not revoked at the time of signature.
Asymmetric cryptography (public key / private key)
Asymmetric cryptography relies on a mathematically linked pair of keys: the private key (secret, preserved in an HSM or QSCD) and the public key (freely distributed in a certificate). To sign a document, the signer calculates the fingerprint of the document and encrypts it with their private key; anyone can verify the signature by decrypting this fingerprint with the public key and comparing it to the hash of the original document. The dominant algorithms are RSA (2048–4096 bit keys) and ECC (P-256, P-384 curves). RSA 2048 bits is recommended until 2030 by NIST; ECC P-256 offers equivalent security level with 10× shorter keys (performance gain on HSM). Resistance to quantum computers is assured by post-quantum algorithms CRYSTALS-Dilithium and CRYSTALS-Kyber, currently being standardized by NIST.

D

Signature delegation
Signature delegation is the mechanism by which an authorized signatory (delegating party) formally transfers his or her signing authority to a third party (delegatee) for a defined duration and scope. Under French law, signature delegation must be explicit, formalized in writing and precisely specify the acts covered (article 1994 Civil Code for agency, and statutory provisions for companies). On Certyneo, delegation is managed on the administration side: the delegating party configures a signature role for the delegatee; the audit trail records the actual identity of the signatory and the legal basis for his or her delegation.
Dematerialization
Dematerialization refers to the replacement of paper documents and processes with their digital equivalents. It encompasses digitization, native creation of electronic documents, and their signature via tools like Certyneo. It enables reducing delays, costs and environmental footprint of document processes. See the benefits of contract dematerialization →
Distinguished Name (DN)
The Distinguished Name (DN) is the unique identifier of a subject in an X.509 certificate. It is composed of hierarchical attributes: CN (Common Name, name of the holder), O (Organization), OU (Organizational Unit), C (Country, country in ISO code), etc. — for example CN=Jean Dupont, O=Certyneo, C=FR. The DN of the signer is readable in the signature properties of a PDF validated in Adobe Acrobat Reader.
DPA (Data Processing Agreement)
A DPA (Data Processing Agreement) is the contract required by Article 28 of the GDPR between a data controller (the client) and a processor (such as Certyneo). It specifies the purposes of processing, categories of data, security measures, conditions for further subprocessing, and obligations in case of breach. A DPA must be executed before any processing of personal data of signatories. Certyneo offers a standard DPA appended to its Terms and Conditions.

E

ECC (Elliptic Curve Cryptography)
Elliptic Curve Cryptography (ECC) is an approach to asymmetric cryptography based on the algebraic properties of elliptic curves. It offers security equivalent to RSA with significantly shorter keys (256-bit ECC ≈ 3072-bit RSA), reducing computational load. ECC is the preferred algorithm for TLS 1.3 (X25519 curve, P-256) and is increasingly used in certificates for digital signature.
eIDAS
eIDAS (Electronic IDentification, Authentication and trust Services) is European Regulation No. 910/2014 which establishes a common legal framework for electronic signatures, seals, time-stamping and other trust services in the EU. It defines three signature levels (simple, advanced, qualified) and creates the concept of qualified trust service providers. Learn more about eIDAS →
eIDAS 2.0
eIDAS 2.0 (EU Regulation 2024/1183, which entered into force in 2024) is the major revision of eIDAS that notably introduces the European Digital Identity Wallet (EUDIW). It aims to extend the recognition of digital identities to all public and private services in the EU, and strengthens requirements for qualified providers. Each Member State must offer at least one digital identity wallet to its citizens and residents by the end of 2026; its use remains voluntary.
Signature envelope
A signature envelope is the logical container grouping one or more documents to be signed, the list of signatories, the positioned signature fields, and the configuration of the workflow. On Certyneo, each envelope has its own lifecycle (draft, sent, pending, signed, refused, expired) and a time-stamped audit trail.
Bulk sending (bulk signing)
Bulk sending (or bulk signing) refers to the ability to send a document to many signatories simultaneously, or to send several distinct documents in a single operation. This functionality is essential for HR (employment contracts), insurance (amendments) or real estate (mandates). On Certyneo, the API allows orchestrating bulk sends via a single programmatic call, with each signatory receiving an individual link and their own audit trail.
ESIGN Act
The ESIGN Act (Electronic Signatures in Global and National Commerce Act, 2000) is the U.S. federal law that recognizes the legal validity of electronic signatures and online contracts in the United States. Complementary to the UETA (state model law), it establishes the principle that a signature cannot be rejected solely on the grounds that it is electronic. For transatlantic contracts, an eIDAS AES is generally recognized as ESIGN/UETA compliant, facilitating contractual exchanges between the EU and USA.
EUDI Wallet (European Digital Identity Wallet)
The European Digital Identity Wallet (EUDI Wallet) is the mobile application mandated by eIDAS 2.0. It allows EU citizens to store and share certified identity attributes (civil status, diplomas, driving licenses) and perform qualified signatures (QES) from their smartphone. The EUDI Wallet will progressively replace FranceConnect+ in France by 2026–2027.

F

Approval workflow
An approval workflow is a structured sequence of validation steps through which a document must pass before being signed. Typically: drafting → legal review → financial validation → signature. Under French business law, certain acts require formalized approval before signature (board meeting resolution, CFO sign-off). Technically, an approval workflow differs from co-signature: approvers validate the content without necessarily affixing their electronic signature (they click "Approved"), while final signers commit their responsibility. Certyneo supports both modes in the same envelope workflow, with distinct roles (Approver vs Signer) and webhooks triggered at each state transition.
Hash function
A hash function is a one-way mathematical function that transforms an input of any size into an output of fixed length called a digest (or hash). Any modification, even of a single bit, produces a radically different digest. Modern functions (SHA-256, SHA-3) are collision-resistant. In digital signature, the document is first hashed and then the digest is encrypted with the private key — which guarantees the integrity of the signed content.
FranceConnect
FranceConnect is France''s government digital identity service that allows citizens to authenticate to online public or private services using an existing identifier (Impots.gouv, Ameli, La Poste, MSA, Identité Numérique). A step above, FranceConnect+ is rated "substantial" under the eIDAS regulation and can be used to trigger an advanced signature (AES) or even qualified signature (QES). By the end of 2026, FranceConnect+ will be progressively replaced by the digital identity carried by the European Wallet (EUDIW) provided for by eIDAS 2.0.

G

Template (document template)
A template is a pre-configured standard document with dynamic fields (signatories, dates, amounts, signature locations) that serves as a starting point for recurring envelopes. On Certyneo, templates industrialize high-volume workflows (employment contracts, NDAs, purchase orders): you duplicate the template, fill in the case-specific variables, and send. Free contract templates available on /modeles-contrats are designed to be downloaded and then instantiated as templates in your account.
GDPR (General Data Protection Regulation)
The GDPR (General Data Protection Regulation, EU Regulation 2016/679) is the English version of the RGPD. This European regulation governs the collection, processing and retention of personal data within the EU. It applies to any organization processing data of European residents, regardless of its location. It notably requires the conclusion of a DPA with subprocessors, data minimization and respect for individuals'' rights (access, rectification, erasure).
Document generator and digital mail merge
A document generator combines a contract template with variable data (name, SIREN, amount, date, etc.) to automatically produce a PDF ready for signature. Common technologies are: Word/DOCX template engines (Carbone.io, Docxtemplater), LaTeX, HTML-to-PDF (Puppeteer/headless Chrome) and Adobe PDF Services API. The advantage of digital mail merge over paper mail merge is direct sending to the signature workflow without printing: the generated document is injected into the signature envelope via the REST API, signature fields are positioned by coordinates or HTML tags, and the cycle closes in seconds. The main risk is layout divergence between local DOCX rendering and server rendering — a suite of visual regression tests (PNG capture + diff) is recommended.

H

Hashing (hash)
Hashing is a cryptographic operation that transforms a document of any size into a digital fingerprint of fixed size, called a "hash". Any modification, however minor, to the document produces a completely different hash, thus guaranteeing the integrity of the file. Digital signature relies on the encryption of this hash with the signatory''s private key.
TLS handshake
The TLS handshake ("handshake") is the negotiation phase that takes place at the beginning of a TLS connection. The client and server agree on the cipher suite, exchange their certificates (optional mutual authentication), and establish session keys via an ephemeral key protocol (ECDHE). TLS 1.3 reduced the handshake to 1 round-trip (versus 2 in TLS 1.2), improving the performance of signing sessions on mobile.
Electronic timestamping
Electronic timestamping is a mechanism that links digital data to a precise moment in time, in a verifiable and unforgeable manner. A qualified timestamp, issued by a qualified provider under eIDAS, provides legal evidence of the existence of a document at a given date. It is essential for maintaining the probative value of documents over the long term.
Qualified timestamp (TSA)
A qualified timestamp is an electronic timestamp issued by a Time Stamping Authority (TSA) qualified under eIDAS. It produces legally recognized proof of a document''s existence at a specific date and time, linked to the document''s hash. Essential for PAdES B-T, B-LT, and B-LTA profiles to guarantee legal probative value over the long term.
HSM (Hardware Security Module)
An HSM (Hardware Security Module) is a tamper-proof hardware device dedicated to the secure generation, storage and use of cryptographic keys. The HSM performs cryptographic operations (signing, decryption, key generation) without ever exposing the private key — it remains inside the hardware perimeter, protected by physical countermeasures (intrusion sensors, automatic erasure on any opening attempt).

HSM Certifications: to be qualified under the eIDAS regulation, an HSM must meet strict standards — FIPS 140-2 level 3 or FIPS 140-3 level 3+ (NIST American standard), and/or Common Criteria EAL4+ (European standard). Common Criteria certified HSMs are eligible to host qualified signature (QES) keys and qualified timestamping keys. The European Trusted List references authorized HSMs for each qualified provider.

Cloud HSM vs Physical HSM: historically HSMs were dedicated appliances installed in private datacenters. Cloud providers now offer shared or dedicated HSMs as SaaS — AWS CloudHSM, Azure Dedicated HSM, Google Cloud HSM, but also national HSMs operated by European QTSPs. The eIDAS 2.0 regulation explicitly recognizes cloud HSMs for remote qualified signatures.

HSM and encryption ("HSM encryption"): beyond signatures, HSMs protect database encryption keys, disk encryption keys (BitLocker, FileVault, LUKS), internal PKI root keys, and application secrets. Key rotation, backup and revocation are managed via PKCS#11 or proprietary interfaces.

Certyneo implementation: the cryptographic keys for remote signing are hosted in Common Criteria EAL4+ HSMs operated by our qualified trust service provider (QTSP). No private key is ever accessible to Certyneo or its hosting provider — each signing operation goes through strong authentication of the signatory and an API call to the HSM, which returns the signature without exposing the key. See also QSCD and cloud signature.
HTTP/3
HTTP/3 is the third major version of the HTTP protocol, based on QUIC (UDP transport) rather than TCP. It reduces latency (eliminates head-of-line blocking), improves recovery after network interruption, and natively integrates TLS 1.3. Certyneo leverages HTTP/3 to accelerate document loading for signing and submission of consent forms, particularly on mobile in degraded network environments.

I

Digital identity
Digital identity is the set of data allowing identification of a natural or legal person in the digital space. It can be provided by a State (electronic identity card, FranceConnect) or by private operators (qualified providers). With eIDAS 2.0, each European citizen will have an official digital identity wallet (EUDIW).
IdP (Identity Provider)
An Identity Provider (IdP) is a service that manages digital identities and delivers authentication assertions to third-party applications (Service Providers). Dominant protocols are SAML 2.0 (enterprise, SSO Okta/Azure AD) and OIDC/OAuth 2.0 (web, FranceConnect). In the context of electronic signature, the IdP plays two roles: (1) authenticate the signer when accessing the signature portal (MFA via enterprise SSO); (2) provide verified identity attributes (name, email, employee number) that feed the signature certificate and audit trail. FranceConnect is the French public IdP enabling "substantial" trust level for advanced signatures intended for state services. Certyneo integrates with SAML and OIDC IdPs via the administration console.
Ink signature (digitized handwritten signature)
An ink signature (or digitized handwritten signature) is the digitization of a traditional handwritten signature as an image (JPG/PNG) affixed to a document. It constitutes the most basic level of simple electronic signature (SES) under eIDAS: without strong authentication or audit trail, its probative value is limited. It remains nonetheless used for documents with low legal stakes (internal signatures, annotations).
Integrity (of data)
Integrity is the property guaranteeing that data has not been altered or falsified after its creation, transmission, or storage. In digital signature, integrity is ensured by the hash function: any modification to the document means that the recalculated hash no longer matches the one encrypted in the signature, immediately invalidating verification. This is why a PDF signed with Certyneo is "sealed" — it cannot be modified without the signature breaking.
eIDAS interoperability
eIDAS interoperability refers to the mutual recognition of digital identities and electronic signatures between EU Member States, as required by the eIDAS regulation (articles 6 and 25). A qualified certificate issued by a trusted service provider (TSP) listed on the trust list of one Member State is automatically recognized as valid in all other Member States — without further action. This interoperability covers the AES and QES levels. The eIDAS 2.0 regulation (EU 2024/1183) extends this mechanism to the EUDI wallet (European Digital Identity Wallet), expected in 2026.

J

Signature token
A signature token is the cryptographic object produced at the moment of signing that groups together: the document''s hash, the timestamp, the signer''s identifier, and the cryptographic signature itself (encrypted with the private key via PKI). This token is embedded in the final PDF according to the PAdES format and allows any verifier — judge, expert, auditor — to reconstruct proof of signature without depending on the platform. The token is self-sufficient: even if Certyneo disappeared, the signature would remain verifiable with a standard PDF reader (Acrobat Reader, pdfsig).
Logging and preservation of signature logs
Logging in the context of electronic signature designates the immutable recording of all events in a document''s lifecycle: creation, sending, opening, OTP verified, signature affixed, signed document download, archiving. These logs constitute the technical layer of the audit trail and may be required in case of dispute. Legal requirements vary: GDPR imposes a limit on the retention period of personal data, while statutory limitation periods for contracts (5 years in commercial law, 10 years for civil acts) define the minimum log retention duration. Best practice: logs must be cryptographically signed (integrity token) to prove they have not been altered. Certyneo preserves the logs of each envelope for the applicable legal duration and includes them in the downloadable digital safe.
JWT (JSON Web Token)
A JWT (JSON Web Token, RFC 7519) is a compact and secure format for representing assertions between two parties. It consists of three parts encoded in Base64URL separated by periods: the header (algorithm), the payload (claims), and the signature. The Certyneo API uses signed JWTs (HS256 or RS256) for session management and authentication of API calls, ensuring that tokens have not been falsified. Access JWTs have a short lifespan, supplemented by long-lived refresh tokens.

K

KYC (Know Your Customer)
KYC (Know Your Customer) refers to the set of identity verification procedures that a company applies to its customers before entering into a business relationship. Historically imposed on banks by anti-money laundering directives, KYC has extended to electronic signature operations with high stakes: account opening, credit, insurance, notarial deeds. Three pillars: verification of identity documents (OCR and fraud detection on the security features of a card or passport), liveness control (proof that the person is real and present, not a photo or deepfake), and cross-checking information with reference databases. Link with signature level: the more sensitive the deed, the stronger the KYC — a simple signature may require none, while the eIDAS regulation requires face-to-face or equivalent remote identity verification (video KYC) before issuing a qualified signature (QES) certificate. KYC and AML/CFT: KYC is the entry stage of the relationship; ongoing transaction monitoring (AML/CFT) continues afterward. Why it matters: robust KYC is what allows a remote signature to have the same legal value as a signature witnessed in person, by linking the signing key to a verified human.

L

LCCJTI (Law on the legal framework for information technologies)
The LCCJTI is the Quebec law (R.S.Q., chapter C-1.1) establishing the legal framework for signature and electronic documents in Quebec. It explicitly recognizes electronic signature as equivalent to handwritten signature provided that the signatory''s identity is established reliably and the link between the signature and the document is ensured (section 39). The LCCJTI is complementary to the eIDAS regulation (applicable in Europe) and PIPEDA (applicable to personal information outside Quebec). It is the legal foundation for Certyneo signatures on Quebec contracts. Law 25 (2022) modernizes the accompanying personal information protection regime.
LCEN (Law 2004-575)
The LCEN (Law for Confidence in the Digital Economy of June 21, 2004, No. 2004-575) is the founding text of French digital law. It governs online commerce, the liability of hosting providers, digital advertising, and requires professional website publishers to display legal notices (company name, capital, RCS, address, publisher, hosting provider). Complementary to the European eIDAS regulation, it also transposed the first electronic signature directive into French law. The LCEN continues to apply alongside eIDAS, particularly regarding pre-contractual information obligations and the retention of electronic contracts over €120.
LegalTech
The term LegalTech (Legal Technology) refers to startups and software solutions that apply technology to the legal field to automate, accelerate, or make accessible services previously reserved for legal professionals. Electronic signature, contract dematerialization, AI-driven due diligence, and document management are part of it. Certyneo is part of the European LegalTech ecosystem by offering eIDAS-compliant signature that is simple to integrate.
LTV (Long-Term Validation)
Long-term validation (LTV, Long-Term Validation) is a feature of PDF signatures (PAdES B-LT/B-LTA) that embeds in the signed document all the data necessary for future signature verification: certificate chain, timestamps, OCSP responses or CRL. Thanks to LTV, a signed document remains verifiable years after signing, even if the certificates have expired. Certyneo integrates LTV to guarantee probative value for 10 years.

M

Electronic SEPA Mandate (direct debit mandate)
The electronic SEPA mandate (e-mandate) allows a creditor to collect authorization for automatic direct debiting from a debtor entirely online, in accordance with EU Regulation No. 260/2012 and EPC (European Payments Council) directives. The debtor enters their IBAN and BIC, then signs the mandate via simple electronic signature (SES); the debtor's bank can authenticate it via Open Banking (DSP2/PSD2). The signed mandate must be retained for 14 months after the last debit. A valid e-mandate contains: the SEPA creditor identifier (SCI), the unique mandate reference (UMR), and the signature date. SaaS platforms, software publishers and training organizations frequently use Certyneo to collect SEPA mandates during online subscription, integrating the signature via the REST API in the order funnel.
Handwritten (signature)
Handwritten signature is the graphical trace made by hand by a person at the bottom of a paper document, recognizable by its personal stroke. It remains the historical reference in French civil law (Article 1367 of the Civil Code). The eIDAS regulation establishes the principle of non-discrimination: an electronic signature, regardless of its level, cannot be rejected as evidence solely because it is electronic. A qualified signature (QES) has the same probative force as a handwritten signature throughout the EU. Advanced signatures (AES) often provide superior traceability (audit trail with timestamps) compared to their paper equivalent.
MFA (Multi-Factor Authentication)
MFA (Multi-Factor Authentication — sometimes abbreviated as 2FA for two-factor authentication when exactly two factors are combined) is a security mechanism that requires the presentation of at least two proofs of identity belonging to different categories:

• Knowledge factor ("what I know") : password, PIN code, answer to a secret question, passphrase.
• Possession factor ("what I have") : phone that receives an OTP via SMS or via a TOTP application (Google Authenticator, Authy, 1Password), YubiKey or other FIDO2 key, certificate on smart card.
• Inherence factor ("what I am") : fingerprint, facial recognition, voice, iris. Implemented via native APIs of modern operating systems (Face ID, Touch ID, Windows Hello, Android BiometricPrompt).

MFA vs 2FA : 2FA is a strict subset of MFA — exactly two factors. MFA can combine two, three or more factors. Mass-market practice often confuses the two terms; in B2B and legal cybersecurity, MFA is the generic term.

MFA and electronic signature : advanced electronic signature (AES) requires strong authentication of the signer, which translates in practice to MFA (typically e-mail + OTP SMS). Qualified signature (QES) requires reinforced MFA — identity verification with identity document + possession factor (smart card or QSCD). The eIDAS regulation does not explicitly name MFA but requires it through strong authentication requirements.

Certyneo implementation : MFA mandatory for all administrator access (TOTP via Google Authenticator or e-mail OTP at choice). For signers, the e-mail + SMS OTP combination is applied by default on AES-level envelopes. See also OTP and strong authentication.

N

Signature level (simple, advanced, qualified)
The eIDAS regulation distinguishes three levels of electronic signature: simple signature (SES), which requires minimum identification; advanced signature (AES), which requires a unique link to the signer and strong authentication; and qualified signature (QES), which relies on a qualified certificate and a secure creation device. QES has the same legal value as a handwritten signature throughout the EU. Understand signature levels →
Non-repudiation
Non-repudiation is the property of an electronic signature that makes it impossible for the signer to deny having performed the action (sign, send, accept). It is assured by the combination of cryptographic signature (irreplaceable technical link), timestamped audit trail, and strong authentication. A qualified signature (QES) offers the strongest non-repudiation recognized by European law.
ISO/IEC 27001 standard and ISMS certification
ISO/IEC 27001 is the international reference standard for Information Security Management Systems (ISMS). It defines the requirements for establishing, implementing, maintaining and continuously improving an ISMS, via 93 controls distributed across 4 domains (organizational, human, physical, technological). For an electronic signature service provider, ISO 27001 certification demonstrates a level of security maturity aligned with the obligations of eIDAS and GDPR. It is often required in public tenders and supplier security questionnaires from large enterprises. ISO 27017 standard (cloud security) and ISO 27018 (personal data protection in the cloud) complement ISO 27001 for SaaS services. Certyneo is hosted in ISO 27001 certified datacenters and maintains a documented ISMS covering the entire signature processing chain.

O

OCSP (Online Certificate Status Protocol)
OCSP (Online Certificate Status Protocol, RFC 6960) is a protocol for real-time verification of the revocation status of an electronic certificate, by querying an OCSP responder operated by the certification authority. Why revocation matters: a certificate can be valid by date but revoked in advance (key compromise, employee departure); a signature or TLS connection must therefore check the status, not just the expiration. OCSP vs CRL: OCSP is a lighter and more reactive alternative to a CRL — instead of downloading the entire revocation list, the client queries a single certificate and receives a concise signed response (valid / revoked / unknown). OCSP Stapling: to avoid a privacy leak and an extra round trip, the server retrieves its own OCSP response and "staples" it in the TLS handshake, so the browser never directly contacts the CA. In signed documents: OCSP responses are embedded in the PDF at the time of signature for long-term validation (LTV), so the signature remains verifiable years later even if the responder is offline.
Electronic onboarding (digital subscription)
Electronic onboarding is the process of subscription or account opening that is entirely dematerialized, combining KYC, identity verification and electronic signature of contractual documents (Terms of Use, SEPA mandate, account agreement) in a single web or mobile session. The banking, insurance and fintech sectors are the most advanced: the DSP2 directive requires strong authentication (SCA) when opening an account. An onboarding compliant with the eIDAS regulation requires that remote identity verification be at a "substantial" or "high" level of confidence for binding acts. Solutions combine: OCR of identity document, liveness check (video or selfie), AES or QES signature, and automatic filing of the complete KYC file in the digital safe.

P

PAdES (PDF Advanced Electronic Signature)
PAdES (PDF Advanced Electronic Signature, ETSI EN 319 142 standard) is the European standard for digital signatures embedded in PDF files. Adopted by the eIDAS regulation as the reference format for European documents, PAdES is today natively implemented by all PDF readers (Adobe Acrobat, Foxit, PDF.js, pdfsig). A PAdES signature is embedded IN the PDF: no detached file, no dependency on a third-party platform, offline verifiability.

The four PAdES profiles define an increasing level of guarantee:
• PAdES B-B (Baseline-B): basic signature with minimal ETSI attributes. Sufficient for common uses where immediate evidential value is enough.
• PAdES B-T (Baseline-T): adds a qualified RFC 3161 timestamp immediately after the signature, proving the date.
• PAdES B-LT (Baseline-Long Term): adds long-term validation with embedded certificate chain and revocation data. Verifiable even after the original certificate expires.
• PAdES B-LTA (Baseline-Long Term with Archive timestamp): adds periodic archive timestamps to maintain evidential value beyond 10 years, essential for documents requiring very long preservation (real estate, patents).

Certyneo implementation: all signed PDFs are produced in PAdES B-LT by default, the profile recommended for the majority of B2B uses. The B-LTA profile can be activated on the Business plan for contracts requiring preservation longer than 10 years. Verifiability guaranteed in Adobe Acrobat Reader without plug-in.

PAdES vs other formats: see XAdES (for XML), PAdES / XAdES / CAdES comparison.
Electronic parapheur (approval workflow)
The electronic parapheur is the digital equivalent of the physical parapheur used in government agencies and large companies: it centralizes documents awaiting visa or signature by a decision-maker. Historically reserved for the public sector (ADULLACT, Pastell by Libriciel), the electronic parapheur has expanded to enterprises with solutions integrated into ECM systems (Documentum, SharePoint, Alfresco). An electronic parapheur manages: the incoming mail list, signature delegations (see delegation), multi-level validation workflows (approval workflow), and the application of qualified electronic signature by the authorized signer. The main difference from a simple signature tool is the management of inboxes (pending, signed, rejected, archived documents) and passage audit for each document. Certyneo offers an integrated parapheur accessible via the dashboard or API.
PDF/A (long-term archiving)
PDF/A is a standardized ISO version of the PDF format (ISO 19005) specially designed for long-term archiving. It embeds all fonts, images and resources within the file, forbids encryption and content dependent on an external environment. This guarantees that the document remains readable in 30 years without software dependency. For electronic archiving with evidential value, combining PDF/A with PAdES B-LTA is the recommended practice.
PIPEDA (Personal Information Protection and Electronic Documents Act, Canada)
PIPEDA (Personal Information Protection and Electronic Documents Act, in French: Loi sur la protection des renseignements personnels et les documents électroniques) is the Canadian federal law on personal information protection in the private sector (S.C. 2000, c. 5). It governs the collection, use and disclosure of personal information in interprovincial and international commercial activities. It is the Canadian equivalent of the European GDPR, although less strict on some points (implicit consent sometimes permitted, lower financial penalties).

The 10 PIPEDA principles (from the Canadian Standards Association CAN/CSA-Q830):
1. Accountability — designate a personal information protection officer.
2. Identifying purposes — clearly state the purpose of collection.
3. Consent — obtain informed consent.
4. Limiting collection — collect only what is necessary.
5. Limiting use — use only for stated purposes.
6. Accuracy — keep data current.
7. Safeguards — appropriate technical and organizational protection.
8. Openness — public privacy policy.
9. Individual access — right to access and correct personal information.
10. Complaining procedure — complaint mechanism to the Privacy Commissioner of Canada.

PIPEDA and electronic signature: electronic signature involves processing personal data (name, email address, phone number, IP, session metadata, audit trail). PIPEDA requires:
• informed consent from the signatory before collection;
• secure retention (encryption at rest, restricted access);
• retention period proportionate to purpose (10 years for commercial contracts is generally accepted);
• right of access, correction and deletion on signatory''s request;
• mandatory notification in case of breach presenting real risk of serious harm (since 2018).

Quebec Law 25: the province of Quebec has its own law (Law 25 / Law modernizing personal information protection provisions, in force 2022-2024) which prevails over PIPEDA for intra-Quebec activities. Law 25 is stricter than PIPEDA — aligned with European GDPR on most points: mandatory explicit consent, designation of a personal information protection officer, impact assessments (DPIA), penalties up to 4% of worldwide revenue.

PIPEDA vs GDPR: the European Commission recognizes PIPEDA as providing an "adequate" level of protection under article 45 GDPR (Decision 2002/2/EC confirmed 2024). Transfers of personal data from the EU to Canada are therefore permitted without further formality. For Canadian organizations operating in the EU, GDPR remains applicable to the data of European residents (extraterritoriality, article 3).

Certyneo implementation: PIPEDA + Law 25 + GDPR compliance ensured by our data protection architecture — EU sovereign hosting (IONOS), TLS 1.3 encryption in transit + AES-256 at rest, access logging, right to complete erasure within 30 days, compliant sub-processors. Transfers to Canada (rare — only accounts hosted on request in Canada) are governed by GDPR-PIPEDA standard contractual clauses.
Audit trail
The audit trail is the timestamped log of all actions performed on a document: sending, opening, viewing, OTP entry, signing, rejection, expiration. It constitutes the primary proof of evidential value in case of dispute, by demonstrating that the signature process was carried out in accordance with the rules. On Certyneo, the audit trail is integrated into the final PDF and stored in our database for a period of 10 years. Understand the audit trail in detail →
PKI (Public Key Infrastructure)
A PKI (Public Key Infrastructure) is the set of hardware components, software, procedures and policies enabling the issuance, management and revocation of electronic certificates. It is based on asymmetric cryptography: a private key (secret) is used to sign, a public key (distributed in the certificate) allows anyone to verify the signature. Qualified providers operate PKIs compliant with ETSI standards.
Data portability (GDPR Art. 20)
Article 20 of the GDPR grants data subjects the right to obtain their personal data in a structured, commonly used and machine-readable format, and to transmit it to another data controller. For users of an electronic signature platform, this right covers: signed documents and their audit trails, account metadata, and activity logs. Portability requires the service provider to provide a standardized export (JSON, CSV, ZIP) within one month. Conversely, the right to erasure (Art. 17) may be limited by legal retention obligations (evidential archiving 5–10 years) — signed documents cannot be erased as long as the legal period has not elapsed. Certyneo implements full account export via the customer portal and supports migration of archives to a third-party safe.
Trust Service Provider (TSP)
A Trust Service Provider (TSP) is an entity that provides timestamping, certificate issuance, signature or archiving services under the eIDAS regulation. A qualified TSP is subject to regular audits and appears on the national trust list (in France: ANSSI list). Qualification guarantees the highest level of assurance recognized in the EU. See TSP obligations →

Q

QES (Qualified Electronic Signature)
The qualified electronic signature (QES, Qualified Electronic Signature) is the highest level defined by the eIDAS regulation. It is legally equivalent to a handwritten signature throughout the European Union. Its issuance requires: prior identity verification, a qualified certificate issued by a QTSP, and the use of a Qualified Signature Creation Device (QSCD). It is required for electronic notarial acts, certain public procurement and sensitive administrative procedures.
QSCD (Qualified Signature Creation Device)
A QSCD (Qualified Signature Creation Device) is a hardware or software device meeting the strict requirements of Annex II of eIDAS for the creation of qualified signatures (QES). It guarantees that the signature private key is generated within the device, never leaves it in clear, and can only be used by the legitimate holder. Certified HSMs and smart cards are common forms of QSCD. Cloud signature uses virtual QSCDs hosted in certified HSMs.
QTSP (Qualified Trust Service Provider)
A QTSP (Qualified Trust Service Provider) is a TSP that has been audited and registered on the trust list of an EU Member State under the eIDAS regulation. Qualification is the highest level of European recognition: it is mandatory to issue qualified certificates, qualified timestamps, or qualified signatures (QES). In France, ANSSI maintains the official list (docaposte, Universign/Oodrive, CertEurope…). Certyneo interfaces with multiple QTSPs to trigger QES when the qualified level is required (public procurement, notarial acts, certain social procedures).

R

Automatic reminder
Automatic reminder is the feature of an electronic signature platform that automatically sends reminders by email or SMS to signers who have not yet signed, according to a configurable frequency. It reduces signature abandonment and accelerates completion of workflows. On Certyneo, reminders are configurable per envelope (frequency, message content) and all actions are tracked in the audit trail.
GDPR
The GDPR (General Data Protection Regulation, EU Regulation 2016/679) regulates the collection, processing and storage of personal data in the EU. In the context of electronic signature, it notably requires minimizing the data collected from signers, defining a retention period and ensuring the right to erasure. Certyneo is GDPR compliant with hosting in the EU and an available processing register. See our security page →
ROI of electronic signature
The ROI (return on investment) of electronic signature is measured across four areas: (1) signature cycle reduction — from 5–10 days (mail/scan) to less than 1 hour on average, (2) direct savings — printing, postage, physical archiving (estimated at 15–30 € per envelope), (3) abandonment rate reduction — contracts awaiting paper signature have 3× higher abandonment rates, (4) compliance — GDPR fines for poor paper contract retention can exceed the annual cost of a SaaS tool. Going paperless typically breaks even within 3–6 months for SMEs processing more than 50 contracts per month.

S

SES (Simple Electronic Signature)
Simple Electronic Signature (SES, Simple Electronic Signature) is the basic level defined by the eIDAS regulation. It requires no specific technical requirement: a click "I accept", a signature image or email signature satisfies it. It is admissible as evidence in court (Article 25 of the eIDAS regulation), but its probative value is not presumed: the presumption of reliability is reserved for qualified signature (Article 1367 of the Civil Code and Decree No. 2017-1416). In case of dispute, it is for the person relying on it to demonstrate the reliability of the process. It is suitable for documents with low legal risk (quotations, internal reports, agreements in principle). For significant stakes, favour the AES or QES level.
Signatory
The signatory is the natural person who affixes their electronic signature to a document and commits legally to its content — to be distinguished from the sender, who prepares and sends the document, and from a legal entity, which "signs" via an electronic seal.

Who can be a signatory? Any legally competent natural person: an adult individual for their own commitments, or an authorized representative for a business — director, employee with a delegation of signature, or proxy. Verifying the signatory's authorization is an essential control point: a contract signed by an unauthorized person can be challenged.

Signatory, cosignatory, approver: the cosignatory is an additional signatory of the same document (co-signature), committed equally; the approver, on the other hand, validates the document in an approval workflow without affixing a legally binding signature. The order of signatories can be sequential (each signs in turn, with automatic reminders) or parallel (all at once) — this is the signature workflow.

How is the signatory's identity verified? According to the signature level: in simple signature (SES), via the unique email link; in advanced signature (advanced signature), via strong authentication — SMS OTP code; in qualified signature (QES), via identity document verification with a qualified trust service provider.

On Certyneo: the signatory receives a unique link by email, views the document, authenticates and signs from their mobile or computer, without creating an account. Each of their actions (opening, OTP, signature, refusal) is timestamped and recorded in the audit trail attached to the signed PDF — it is this that legally links the document to the signatory. Understand signature levels →
Advanced Signature (AES / eIDAS level 2)
Advanced Electronic Signature (Advanced Electronic Signature — AES) is the second of three levels of electronic signature defined by regulation eIDAS (EU) No. 910/2014, between simple signature (SES) and qualified signature (QES). It is the recommended level for the vast majority of contractual documents at stake.

The four requirements of Article 26 eIDAS:
• Unique link to the signatory: the signature can only be attributed to one person — ensured by the identification channel (named email, personal mobile).
• Signatory identification: the process makes it possible to find out who signed — declared identity information, email address, mobile number verified by OTP code.
• Exclusive control: signature creation data is under the control of the signatory alone — materialized by strong authentication at the time of signing.
• Integrity: any subsequent modification of the document is detectable — guaranteed by cryptographic sealing (hashing + PAdES).

AES vs SES vs QES: SES requires no enhanced verification (checkbox, drawn signature) — sufficient for everyday documents; AES adds strong authentication and proof of integrity — suited to employment contracts, mandates, leases, banking and insurance files; QES adds a qualified certificate issued after identity verification and a certified device (QSCD) — it is the legal equivalent of a handwritten signature throughout the EU, required for the most sensitive acts.

Legal value: Article 25 of eIDAS prohibits refusing legal effect to a signature solely on the ground that it is electronic, and Article 1367 of the Civil Code recognizes it provided that a reliable process identifies the signatory and guarantees the integrity of the deed. In case of dispute, the reliability of AES is demonstrated by the bundle of evidence: timestamped audit trail, recorded OTP codes, document fingerprint, time stamp. QES additionally benefits from a presumption of reliability (burden of proof reversed).

When is AES sufficient? Employment contracts and amendments, commercial contracts, quotations and purchase orders, mandates (sale, property management, SEPA), leases, KYC and credit files: AES is the market standard. Switch to QES for authentic deeds, certain public procurement, sale of business goodwill, or when a text requires it.

On Certyneo: AES is available on all paid plans — the signatory is authenticated by SMS OTP, the signed PDF is sealed in PAdES format with time stamp, and the complete audit trail is attached to the document. QES is available per signature, with no dedicated subscription. Understand the three eIDAS levels → · The eIDAS regulation in detail →
Biometric signature
Biometric signature is a form of electronic signature that captures, in addition to the image of the handwriting pattern, dynamic behavioral data: stylus pressure, speed, angle of inclination, acceleration. These parameters create a unique fingerprint that is difficult to forge. It provides more robust authentication than a simple signature image. Biometric data is considered sensitive under GDPR and requires explicit consent. Biometrics alone is insufficient to reach AES eIDAS level; it must be combined with strong authentication.
Cloud signature
Cloud signature is an electronic signature in which the signer''s private key is generated, stored and managed by a trusted service provider in the cloud, rather than on a local device (USB key, smart card). This approach simplifies user experience and enables qualified signature (QES) from a simple browser. Keys are protected in a certified HSM operated by a QTSP.
Electronic Signature
An electronic signature is a mechanism for affixing proof of identity and consent to a digital document, equivalent to a handwritten signature. Under the eIDAS regulation, it encompasses three levels of trust: simple (SES), advanced (AES) and qualified (QES). Unlike a digital signature, an electronic signature is a legal concept that can rely on different technologies. Discover our complete guide →
Mobile signature
Mobile signature refers to the ability to electronically sign a document from a smartphone or tablet, without a native application — via the web browser. The signer receives a link via email or SMS, views the document in their mobile browser, initials and signs with a tap gesture or by typing their full name (depending on required level), then validates via SMS OTP. On Certyneo, the signature interface is 100% responsive: identity verified, audit trail generated, and co-signed PDF delivered to the recipient in under 60 seconds on 4G mobile. No installation required for the signer.
Digital Signature
A digital signature is a technical implementation of electronic signature based on asymmetric cryptography. It consists of encrypting the hash of a document with the signatory''s private key, producing a fingerprint verifiable by anyone with the corresponding public key (contained in the certificate). It guarantees both the signatory''s identity and document integrity.
Smart contract and contract automation
A smart contract is a self-executing program deployed on a blockchain, whose terms are coded directly into the computer code and execute automatically when predefined conditions are met. Although popular in the Ethereum ecosystem (Solidity), smart contracts do not constitute an electronic contract in the sense of French civil law: their execution is automatic but their legal enforceability remains conditional on proof of a valid agreement of will. In B2B practice, the most robust combination is: qualified electronic signature of the master contract (certain legal proof) + smart contract for automatic execution of financial clauses (payments, penalties). The blockchain notarization of the hash of the signed contract constitutes a third complementary layer of proof.
Solde de tout compte (final settlement)
Final settlement is an inventory of sums paid to the employee upon termination of their employment contract (salary, compensation, paid leave, etc.). Governed by article L1234-20 of the Labor Code, it is drawn up in duplicate and its receipt can be signed by the employee. Once signed, the employee has a period of six months to contest it. Electronic signature secures its delivery and timestamps the date. End of contract documents →
Cipher suite
A cipher suite is a named combination of cryptographic algorithms (key exchange, authentication, symmetric encryption, MAC/HMAC) negotiated between the client and server during the TLS handshake. TLS 1.3 enforces modern suites like TLS_AES_256_GCM_SHA384, eliminating weak algorithms (RC4, 3DES, MD5). Certyneo only accepts TLS 1.3 cipher suites to maximize the security of signature sessions.

T

Trusted Third Party
A trusted third party is a neutral and independent actor whose mission is to secure an exchange between two parties: in electronic signature, they attest to signatories'' identity, seal the document, time-stamp actions and preserve evidence. Historically, notaries played this role for paper documents. In the digital realm, the trusted third party is formalized by the eIDAS regulation as trust service providers (TSP) and their qualified version (QTSP). Certyneo acts as a trusted third party by issuing advanced signatures (AES) and can delegate to a partner QTSP to issue qualified signatures (QES).
TLS (Transport Layer Security)
TLS (Transport Layer Security) is the cryptographic protocol that secures Internet communications, succeeding SSL. It ensures confidentiality (encryption), integrity and server authentication (via its certificate). TLS 1.3, the current version, mandates modern cipher suites and a single round-trip handshake. The padlock in the browser signals that a TLS connection is active. Certyneo enforces TLS 1.3 minimum across all endpoints.
Trusted List (EU trust list)
The Trusted List is the official list published by each EU Member State and supervised by the European Commission, listing qualified trust service providers (QTSP) and their services (qualified certificates, time-stamps, etc.). In France, the list is maintained by ANSSI. It is proof of a QTSP''s legitimacy under the eIDAS regulation. Only listed services benefit from the legal presumption of eIDAS compliance.
TSA (Timestamp Authority)
A TSA (Timestamp Authority) is an accredited trusted third party that issues timestamp tokens compliant with RFC 3161 (Internet X.509 PKI Time-Stamp Protocol). The process: the client calculates the fingerprint (hash) of the document and sends it to the TSA via HTTPS; the TSA cryptographically signs a token containing this hash + the certified UTC reception time. This token proves that the document existed in that exact state on that specific date, without the TSA ever having access to the document itself. A qualified TSA (QTSA) listed on the EU trust list produces a qualified eIDAS timestamp, the most evidential form. In PAdES-LT and PAdES-LTA, TSA tokens are embedded in the PDF, ensuring offline verifiability in 20 years even if the original TSA has disappeared.

U

UETA (Uniform Electronic Transactions Act)
UETA (Uniform Electronic Transactions Act, 1999) is the American model law that recognizes the probative value of electronic signatures in 47 of 50 states. Complemented by the ESIGN Act (2000) at the federal level, it provides that contracts and signatures "cannot be declared invalid solely because they are in electronic form". It is the American functional equivalent of the European eIDAS regulation, with a more liberal approach: UETA does not define levels (SES/AES/QES) and has no qualified equivalent. For transatlantic contracts, an eIDAS advanced signature (AES) is generally recognized as UETA/ESIGN compliant, whereas the reverse is not automatic.

V

Probative value (electronic signature)
Probative value is the capacity of an electronic document to be accepted as evidence before a court in the same way as a paper document. It is the pivotal legal concept that determines whether a contract signed electronically can be enforced against your client, employee or supplier in the event of a dispute.

Legal basis in France: the law of 13 March 2000 introduced into the Civil Code article 1366, which establishes a principle of equivalence between paper and electronic documents, provided that (1) the person from whom the document originates can be duly identified, and (2) the document is created and retained under conditions guaranteeing its integrity. Article 1367 specifies that electronic signatures complying with the European regulation eIDAS benefit from this equivalence.

The four cumulative conditions for an electronically signed document to have probative value:
• Identification of the signatory: has authentication enabled identification of a specifically named natural person? Mechanisms: SMS OTP for AES, video identification + KBIS for QES.
• Document integrity: has the content not been modified since signing? Guaranteed by the cryptographic hash embedded in the signature.
• Process reliability: does the signature provider apply best practices (encryption, key management via HSM, traceability)? A qualified provider (QTSP) listed on the European trust list provides the strongest guarantee.
• Traceability: is there a timestamped audit trail that is enforceable (who signed, when, from which IP, after which authentication)?

Legal presumption: under French law, the presumption of reliability is reserved for the qualified signature (QES): Article 1367, paragraph 2 of the French Civil Code and Decree No. 2017-1416. It reverses the burden of proof: whoever contests the signature must prove that it is not reliable. A simple or advanced (AES) signature remains admissible, but in the event of a dispute it is up to the party relying on it to demonstrate that the process is reliable (audit trail, authentication, integrity). A qualified signature additionally benefits from full equivalence with handwritten signature (Civil Code art. 1367 al. 2).

Duration of probative value: a signed document retains its probative value as long as archiving complies with conditions (integrity, durability, traceability). For contracts with retention > 5 years, the PAdES B-LTA profile with periodic archival timestamps allows extending probative value beyond the expiration of original certificates. See also non-repudiation and LTV.
Antivirus verification of uploaded documents
Before a document is integrated into a signature workflow, any responsible platform must submit it to antivirus (AV) analysis. Threats targeting PDFs include: embedded macros, malicious JavaScript (AcroForms), PDF parser exploits (CVE-2019-12657, etc.). Cloud scanning solutions (ClamAV open-source, OPSWAT MetaDefender, VirusTotal API) analyze the file in milliseconds. ISO 27001 and SOC 2 Type II compliance requirements impose AV analysis of all incoming documents. An infected document in a signature workflow is particularly risky because it is sent to all signers, amplifying the attack vector. AV verification must be done before database storage, not after. Certyneo analyzes each uploaded document via ClamAV (in-process daemon) and blocks suspicious files with an explicit error message, never propagating them to the workflow.
Identity verification (identity proofing)
Identity verification (identity proofing) is the process of verifying a person''s actual identity before issuing them credentials or authorizing them to sign. It ranges from simple email address collection (basic level) to biometric identity document verification via video (video KYC, qualified level). It is mandatory to issue a qualified certificate and trigger a qualified signature (QES).
Electronic Approval (Paraph)
Electronic approval (or electronic paraph) is an intermediate validation action affixed to a document by an approver before final signature. It indicates that a reader has reviewed the document and approves it without legally committing themselves through signature. On Certyneo, multi-actor workflows allow combining approval steps (internal validation) and signature steps (external legal commitment), guaranteeing complete traceability of the validation workflow.

W

Webhook
A webhook is an API mechanism that allows Certyneo to automatically send an HTTP notification to the client''s application when an event occurs (document signed, refused, expired, audit trail generated). Unlike polling, the webhook operates in push mode: the client does not need to query the API regularly. It enables integration of Certyneo into third-party systems (CRM, ERP, HRIS) to trigger business actions in real time upon completion of a signature workflow.
Signature workflow
The signature workflow is the organized process defining the order, conditions and actors involved in signing a document. It can be sequential (each signatory signs after the previous one), parallel (all sign at the same time) or mixed. On Certyneo, the workflow includes management of automatic reminders, expiration deadlines and multi-document envelopes.

X

XAdES (XML Advanced Electronic Signature)
XAdES (XML Advanced Electronic Signatures, ETSI EN 319 132 standard) is the European standard for digital signatures applied to XML documents. Adopted by the eIDAS regulation, XAdES is the reference format for signing structured XML files: electronic invoices (Factur-X, PEPPOL), EDI schedules, administrative declarations, market data, SEPA transcriptions.

Four XAdES profiles of increasing maturity, aligned with PAdES and CAdES:
• XAdES B-B: basic XML signature with minimal ETSI attributes. Use case: one-off signing of an XML sample without date constraint.
• XAdES B-T: adds a qualified timestamp RFC 3161. Standard for electronic invoices and EDI flows where issue date must be proven.
• XAdES B-LT: long-term validation with certificate chain and embedded revocation data. Remains verifiable after the original certificate expires.
• XAdES B-LTA: periodic archive timestamps to maintain evidential value over 10+ years. Essential for tax archives and regulated registers.

XAdES vs PAdES: choose XAdES to sign a native XML document (Factur-X invoice, PEPPOL schedule, EDI exchange). Choose PAdES to sign a PDF (contracts, quotes, HR documents). Both formats are legally equivalent — the difference is technical: the format suited to the document type.

XAdES variants: enveloping XAdES (the XML document is included in the signature structure), enveloped XAdES (the signature is added to the document), detached XAdES (signature stored in a separate file). Certyneo handles all three variants via REST API. See the PAdES / XAdES / CAdES comparison.
XAdES / PAdES / CAdES
XAdES, PAdES, and CAdES are the three standard digital signature formats defined by ETSI for the eIDAS regulation. XAdES (XML Advanced Electronic Signatures, EN 319 132) signs XML documents, PAdES (PDF, EN 319 142) embeds the signature token directly in the PDF — this is the format Certyneo uses to produce offline-verifiable files in Acrobat Reader. CAdES (CMS, EN 319 122) applies to arbitrary binary streams. Each format comes in profiles (B-B, B-T, B-LT, B-LTA) offering increasing guarantees: validity over time, qualified timestamp, long-term archival proof.

Y

YubiKey (hardware security key)
A YubiKey is a hardware security key (USB/NFC) designed by Yubico that stores non-extractable cryptographic secrets and supports FIDO2/WebAuthn, OpenPGP, and PIV protocols. As part of a qualified signature (QES), a YubiKey (or an equivalent device compliant with Annex II of eIDAS) can serve as a Qualified Signature Creation Device (QSCD): the private key associated with the qualified certificate never leaves the hardware, guaranteeing the highest level of assurance over the signer''s identity. On a Certyneo admin account, a YubiKey can also protect admin access via hardware MFA.

Z

Paperless
"Paperless" (or going paperless) is the process of completely replacing paper document flows with signed digital equivalents. Beyond operational gain (signature cycle divided by 5 to 20 on average), paperless reduces the carbon footprint related to printing, postage, and physical archiving. Electronic signature, combined with probative electronic archiving (minimum 10 years for commercial contracts), is the technical prerequisite for the transition. Dematerialization describes the movement; paperless is the end goal.
Zero Trust (zero-trust security)
The Zero Trust model (zero trust) is a security architecture based on the principle "Never trust, always verify" — unlike the classic perimeter model which trusts everything inside the corporate network. Its pillars are: continuous identity verification (MFA at each access), least privilege (access strictly limited to operational need), micro-segmentation (service isolation), traffic inspection (including internal), and real-time monitoring. In the context of electronic signature, Zero Trust applies at multiple levels: access to the HSM (no private key accessible without strong operator authentication), access to envelopes (identity-based control, not just link-based), and admin access (ephemeral sessions with automatic revocation). The NIST SP 800-207 framework and the ANSSI guide "Recommendations on Zero Trust" (2021) formalize the requirements in France.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.

Ready to put these concepts into practice?

Certyneo allows you to create signature envelopes compliant with eIDAS in just a few clicks, without installation.