Companies
Close deals the same day, across borders, without a courier.
Supplier contracts · NDAs · board resolutions
Signature space, hashing, certificates, timestamps, long-term validity, encrypted archiving — all of it ours. The only signature that stands equal to ink in all 27 EU member states, and you never touch a single byte of cryptography.
Your document
Signature field
Dr. A. Meyer · verified by ZealiD
weSign did this
Anyone can verify
Signature valid
Qualified certificate · ZealiD AB
9f2b8c41d7e05a63bb14f8907c2d3e5a6f81b0c94d27ae3f5b6c8d1029e4af73
How it works
A qualified signature is dozens of moving parts — certificate chains, byte ranges, revocation data, timestamps, trust lists. We carry all of it. And your part in it never grows beyond one upload and two taps on your phone.
Drop in the final PDF. No placeholder fields, no certificates, no crypto library on your side.
1 request
We ask ZealiD to release your qualified certificate chain and hand you back a QR code. Nothing has touched the document yet.
QR 1 of 2
You scan that code and approve inside the ZealiD app. The approval goes straight to ZealiD — we are never in the middle of it.
your phone
ZealiD checks your approval and releases your qualified certificate chain to us. Your signing key stays inside their certified hardware.
x5c chain
We open the signature dictionary inside the PDF and reserve the exact byte range the signature will occupy.
/ByteRange
The reserved ranges are digested into a single SHA-256 hash — 64 characters that reveal nothing about the file.
SHA-256
A second QR code, this time for the signature itself. It is bound to that one hash and to nothing else.
QR 2 of 2
You scan and approve again, and again the tap lands on ZealiD's platform. This is the moment the law treats as your own hand on the page.
your phone
ZealiD signs the hash with your qualified certificate on certified hardware and hands the signature back. The document itself never leaves our side.
QSCD
The signature, certificate chain, revocation data and a qualified timestamp are embedded back into the PDF.
PAdES-B-LTA
You get a file that validates in Adobe Reader, in court, and in ten years — plus an encrypted copy in your vault.
LTV ready
Security architecture
ZealiD verifies people and issues qualified certificates. Your identity lives with them, your document lives with us, and the only thing that travels between the two is a number.
9f2b8c41d7e05a63bb14f8907c2d3e5a6f81b0c94d27ae3f5b6c8d1029e4af73
A hash is a one-way fingerprint. It proves the file has not changed by a single byte, and it reveals nothing about what the file says. ZealiD signs that number — not your contract.
Who you are is already theirs to hold. ZealiD verified your passport and liveness to issue the certificate, and that evidence stays on their side under eIDAS — weSign never asks for it and never stores it.
XChaCha20-Poly1305
Every document, sealed result and object key is encrypted on its own with a unique nonce and an authentication tag. Corruption and tampering are detected on read, not on trust.
TLS 1.3, EU endpoints
Requests terminate inside the EU. The payload that reaches the Trust Service Provider is a digest and a signing intent — nothing that can be reconstructed into a document.
HSM-wrapped envelopes
Object keys are wrapped by a root key that never leaves hardware. No engineer, and no support session, can decrypt a customer document.
EU only, always
Storage, processing, backups and logs stay within the European Union. Nothing is replicated to a region outside the EEA, under any circumstance.
Two surfaces
The same qualified signature, whether a person clicks it or a service requests it. Nothing about the legal outcome changes.
lease-agreement-2026.pdf
A. Meyer
patient-consent-4471.pdf
Klinik Nord
power-of-attorney.pdf
J. Kowalski
supplier-nda-q3.pdf
Contoso GmbH
board-resolution-12.pdf
Draft
Folders, search and retention rules across every signed document
One identity check per signer — reused for every signature after
Append-only audit trail, exportable as evidence
Who signs with weSign
If a document carries consequences, it deserves the highest signature level European law defines.
Close deals the same day, across borders, without a courier.
Supplier contracts · NDAs · board resolutions
Meet eIDAS obligations with the signature level regulation asks for.
Permits · procurement · citizen decisions
Consent that holds up, with patient data encrypted per record.
Patient consent · referrals · prescriptions
Evidence-grade signatures with a timestamped, exportable trail.
Powers of attorney · settlements · filings
A tenant signs from a phone in minutes — no printer, no scanner.
Leases · handover protocols · terminations
Signatures that stay verifiable for as long as you must keep them.
Annual reports · filings · audit sign-offs
Compliance
Every claim on this page maps to a European standard, an audited Trust Service Provider, or a published specification you can read yourself.
(EU) 910/2014
A qualified electronic signature has the equivalent legal effect of a handwritten signature.
ETSI EN 319 142-1
Signature, certificate chain, revocation data and archive timestamp embedded in the PDF itself.
ETSI EN 319 422
Proof of when the signature existed, issued by a qualified time-stamping authority.
EN 419241-2
The signing key lives on a qualified signature creation device under the signer's sole control.
ISO/IEC 27001
Documented ISMS covering key custody, access control and incident response.
GDPR
The Trust Service Provider receives a digest. Identity data stays with them; we never collect a second copy.
Straight answers
The questions legal and engineering teams ask before they sign anything themselves.
Yes. Article 25(2) of the eIDAS Regulation states that a qualified electronic signature has the equivalent legal effect of a handwritten signature, and every EU member state must recognise one issued in any other. That equivalence only applies to the qualified level — the one weSign issues.
Nothing. A PAdES-LTA file is self-contained: the signature, the full certificate chain, the revocation evidence and an archive timestamp are embedded inside the PDF. It validates in Adobe Reader or any conformant validator with no call to our servers. You can export everything at any time.
No. ZealiD verifies identity remotely — a passport or national ID plus a liveness check, once. The qualified certificate is then issued and the signing key stays on a QSCD under the signer's sole control. Every later signature is a confirmation on their phone.
Yes. The API returns the sealed PDF in the response; storing it with us is optional. If you do use the vault, each document is encrypted as its own object with XChaCha20-Poly1305 and stays inside the EU.
None. You do not create signature fields, reserve byte ranges, compute digests, handle certificates or manage keys. You upload a finished PDF and receive a signed one — that is the entire integration surface.
Verify a signer once, upload a PDF, and get back a document that holds anywhere in the Union. The sandbox needs no card and no real identity.