Electronic signature policy
Version 1.0 — 2026-09-27
This document describes how Certyneo produces, keeps and lets anyone verify the electronic signatures collected on its platform: the levels offered within the meaning of Regulation (EU) No 910/2014 (eIDAS), the technical mechanism behind each level, the certification authorities used and their limits. It is intended for signers, Certyneo customers and anyone who needs to verify a signed document.
1. Signature levels offered
The sender chooses the level of each envelope; every signer of the envelope signs at that level.
- Simple electronic signature (SES, Art. 3(10) eIDAS): the signer is identified by the personal link sent to their email address; every event is recorded in a timestamped log. Available from the free plan.
- Advanced electronic signature (AES, Art. 26 eIDAS): identification by a one-time code sent by SMS, and signature with a cryptographic key of the signer's own, certified in their name (section 2). Available from the Personal plan.
- Qualified electronic signature (QES, Art. 3(12) eIDAS): performed with a qualified trust service provider listed on the EU Trusted List, after that provider has verified the signer's identity. Charged per signature: €14.90 incl. VAT without a subscription, €9.90 incl. VAT with a subscription.
2. How the advanced signature works
The Certyneo advanced signature meets the four requirements of Article 26 of the eIDAS Regulation as follows.
- Key under the signer's sole control (Art. 26(c)): when signing, the signer's browser generates an ECDSA P-256 key pair marked non-extractable (WebCrypto API). The private key never leaves that tab: it is neither sent to Certyneo nor stored on the device, and it disappears at the end of the session. When signing in person, each signer gets their own key.
- Identification of the signer (Art. 26(a) and (b)): after an SMS code received less than 30 minutes earlier has been validated, the "Certyneo AES Signataires" authority certifies the public key in the signer's name and email address, on proof of possession of the private key. The X.509 certificate is valid for 24 hours and restricted to signing (digitalSignature, nonRepudiation).
- Link to the signed data (Art. 26(d)): the browser builds a manifest (format certyneo-aes-manifest/1) containing the envelope and signer identifiers, the SHA-256 fingerprint of each document as it was shown to the signer and of each value they entered (drawn signature, filled-in fields), and the signing time. It signs this manifest in CAdES format (detached CMS, with the contentType, signingTime, messageDigest and signingCertificateV2 attributes).
- Server-side check: Certyneo recomputes the manifest from the documents it holds and the values received, then verifies the signature. Any discrepancy — modified document, different value, certificate not issued by the authority or expired, clock more than 10 minutes off — causes the signature to be rejected. An RFC 3161 timestamp of the signature is then requested; when obtained, the signature becomes CAdES-T, otherwise it remains CAdES-BES and the proof certificate says so.
3. Signed document and evidence file
Once every signer has signed, Certyneo produces the final PDF: the document with the signatures and fields, to which are attached, for each signer of an advanced envelope, their manifest (.json) and their signature (.p7s, certificate and chain included). A PAdES electronic seal issued by Certyneo then covers everything: any later change to the file, attachments included, is detectable.
A proof certificate, delivered with the document, retraces the envelope: eIDAS level, sends, views, code validations (date and channel), key certifications, signatures, IP addresses and browsers, and, for each advanced signer, their certificate serial number and manifest fingerprint. Audit log entries are also batched and periodically anchored in OpenTimestamps.
4. Verifying a signed document
Three tools verify a document without uploading it: the online signature validator and the document verification page (the analysis runs in the browser), and the Certyneo Chrome extension. For each advanced signer they check the integrity of the manifest, the signature made with their personal key, the chain up to the Certyneo root — recognised by its fingerprint, not by its name — and the certificate's validity at signing time.
Verification is also possible offline, with tools independent of Certyneo. After extracting the attachments from the PDF: openssl cms -verify -binary -inform DER -in signature-avancee-1-x.p7s -content signature-avancee-1-x.json -CAfile certyneo-ca-cert.pem -purpose any. The root certificate is published at https://certyneo.com/api/ca-certificate.
5. Certification authorities
"Certyneo Signature Root CA" (RSA 4096-bit, valid until 20 May 2046) issues the document seal and the "Certyneo AES Signataires" intermediate authority (RSA 3072-bit, valid until 26 September 2036, with no subordinate authority), which issues the advanced signers' certificates. The authorities' private keys are encrypted and kept on Certyneo's servers in the European Union.
These authorities are listed neither on the EU Trusted List nor on Adobe's trust list (AATL): a PDF reader therefore shows the Certyneo seal with an "unknown" validity. This takes nothing away from integrity or evidence, but a body that requires a qualified signature (for example the French INPI one-stop shop) will reject a simple or advanced signature: choose the QES in that case.
Signers' certificates cannot be revoked: they expire after 24 hours and their private key only exists for the time of the signature. Should an authority be compromised, Certyneo stops using it, generates a new one and publishes its fingerprints on this page.
6. Legal value
An electronic signature cannot be denied legal effect or admissibility as evidence solely because it is electronic (Art. 25(1) eIDAS). Under French law, an electronic document has the same evidential weight as a paper one provided its author can be identified and its integrity guaranteed (Art. 1366 of the Civil Code), and an electronic signature consists of a reliable identification process guaranteeing its link with the act (Art. 1367).
Only a qualified signature has the legal effect of a handwritten signature (Art. 25(2) eIDAS) and enjoys a presumption of reliability (Decree No 2017-1416). For a simple or advanced signature, the party relying on it must establish that the process is reliable: that is the purpose of the evidence file described in section 3. Some acts relating to family and inheritance law remain subject to specific rules (Art. 1175 of the Civil Code).
7. Limits
- The advanced signer's key is a software key held by the browser, not a qualified signature creation device.
- Identification for the advanced signature relies on possession of the signer's email address and phone; it does not include an identity document check (offered with the qualified signature).
- The RFC 3161 timestamp is requested from external services and may not be obtained; its absence is stated in the proof certificate.
- Advanced envelopes signed before this mechanism went live only carry the Certyneo seal and the proof certificate, without a key of each signer's own.
8. Versions
Version 1.0 of 2026-09-27: first publication, with the advanced signature using the signer's personal key. Any change to these rules is published on this page with a new version number; the version applicable to a signature is the one in force on its date.
SHA-256 fingerprints of the authorities
- Certyneo Signature Root CA
- AF:87:93:3C:07:E6:20:CF:37:DF:B6:D7:5A:71:AC:73:18:D4:AC:72:BB:D3:44:47:39:75:67:8F:BF:5F:DB:65
- Certyneo AES Signataires
- D6:8F:AF:03:B3:AE:F6:45:65:3C:56:F7:E8:04:E6:65:31:73:2E:28:C4:0E:A7:A5:C4:7B:8D:F2:6C:54:11:F6