eIDAS

eIDAS, stated precisely.

Most pages in this category blur the three eIDAS signature levels until "eIDAS compliant" sounds like "qualified". Here is exactly which one we provide, what it proves, and when you need something we do not sell.

Send a document free See pricing →

The three levels, and where we sit.

eIDAS defines three tiers. Vendors rarely say which one they sell, so this table does.

LevelMostlySignWhat it requires
Standard (SES)Yes — this is what we provide.Data in electronic form used to sign. Cannot be denied legal effect for being electronic (Article 25).
Advanced (AdES)No.Uniquely linked to and capable of identifying the signatory, under their sole control, with tamper detection.
Qualified (QES)No.An advanced signature made with a qualified signature creation device on a qualified certificate from a trust-service provider on an EU trusted list.

A standard electronic signature is what the vast majority of agreements — NDAs, contracts, offers, consents — actually call for. Where national law requires a qualified signature, you need a qualified trust service provider, and that is not us.

What our seal does prove.

Every completed document is sealed with a PAdES digital signature over its exact bytes and carries an RFC 3161 timestamp from an independent authority. Together those prove integrity and time: that this specific document existed, in this exact form, at that moment, and has not been altered since. Change one character and the seal breaks in any validator.

It is also standards-based rather than proprietary, so you can check it at the European Commission's own EU DSS validator with nothing of ours involved. We are deliberately not a "verify our document on our website" portal.

The honest caveat, which we would rather state than have you discover: our seal certificate is issued by Mostly Tiny and is not from a certificate authority on an EU trusted list or Adobe's AATL. A validator will confirm the document is intact and correctly sealed, and will flag the issuer as one it does not already know. That is the difference between proving the document has not changed and having a third party vouch for who we are. The full explanation is on our trust page.

What we do offer, for EU and UK customers.

Documents stored in the UK by default
Compute and storage run in europe-west2 (London). Your documents, audit trails and MostlySign records are processed there — not an add-on you have to request. Sign-in and your Mostly Tiny account are in the United States.
A DPA for Business customers
A GDPR Article 28 data processing agreement covering sub-processors, security, transfers, breach notice and deletion. Read it.
No certifications we do not hold
We do not hold SOC 2 or ISO 27001 and will not imply otherwise. What we offer is documents hosted in the UK (London), encryption in transit and at rest, and standards-based proof.

Standard signatures, honestly labelled.

Documents hosted in the UK, PAdES-sealed, timestamped — and clear about where the line is.

Send a document free