Where this
is headed
European digital identity is changing fast — EUDI Wallets, the post-quantum transition, eIDAS 2.0. Our answer is an engine built to absorb change: integrate once, and new methods and algorithms arrive as configuration, not migrations.
Live today
Available to every tenant right now. The trajectory so far: qualified signing, then the engine itself, then the platform around it.
Qualified signatures via Smart-ID & Mobile-ID
eIDAS QES for Estonia, Latvia, and Lithuania. Signers click an email link, confirm a code on their phone — no accounts, no apps to install.
In-house signing engine
We wrote the sealing machinery ourselves — a small, portable engine tested byte-for-byte against the official validation software. No black box, no borrowed decades-old server stack.
Developer API & webhooks
REST API for creating documents, collecting signatures, validating containers, and applying e-seals — with webhooks for every lifecycle event and a machine-readable OpenAPI spec.
Organisation e-seal
Seal completed agreements with your company certificate — the digital equivalent of the company stamp, applied via dashboard or API.
Teams, workflows, branding
Sequential signing order, shared templates and contacts, branded signer pages, accountless public signing links, and OIDC single sign-on.
Crypto-agile engine core
Signature algorithms are switchable registry entries, not hardcoded assumptions. This is the foundation everything below builds on — swapping an algorithm is configuration, not a rewrite.
Working, behind a flag
Built and demonstrable today — honestly labelled as preview. These graduate when the surrounding EU infrastructure does, not when a marketing calendar says so.
EUDI Wallet identification
The signing switchboard already negotiates EU Digital Identity Wallets: wallet holders identify with selective disclosure, and the flow falls back to Smart-ID or Mobile-ID automatically. In preview until eIDAS 2.0 trust lists and wallet certification are live across member states.
Post-quantum signatures (ML-DSA)
The engine signs with ML-DSA — the NIST post-quantum standard, FIPS 204 — today, as a clearly-labelled demo profile: quantum-resistant content signature, classical qualified timestamp. The EU wants the post-quantum transition underway by end of 2026; our demo proves the swap already works end-to-end.
On our bench
Next up, in roughly this order. No external dependencies — these ship when we finish them.
Signer experience in ET / LV / LT
Signing pages and invitation emails in Estonian, Latvian, and Lithuanian — your signers read everything in their own language.
Long-term archival (XAdES-LTA)
Archival re-timestamping that refreshes a container's proofs before the algorithms inside them age out — so a signature sealed today still verifies decades from now, across the post-quantum transition.
Durable event delivery
Webhook retries with backoff, a replayable event log, and delivery dashboards — so your integration never misses a signature.
EUDI Wallet signing
Signing with the wallet itself — not just identifying — the day wallet-based qualified signature creation is certified. The switchboard offers it automatically; your integration doesn't change.
Waiting on the standards
Blocked on European standards bodies and trust service providers, not on us. We name the dependency instead of promising a date — and we build our half in advance, so landing these is a switch, not a project.
Qualified post-quantum signatures
Fully interoperable, legally qualified ML-DSA signatures. Our engine is ready; what's missing is external: qualified trust service providers must issue post-quantum certificates, and ETSI/IETF must standardize the signature identifiers. When they land, it's a one-line registry change on our side.
Hybrid signatures
Belt and suspenders for the migration years: one signature that is both classical (ECDSA) and post-quantum (ML-DSA), valid if either survives. Tracking the IETF composite signature drafts.
Quantum-safe storage
“Harvest now, decrypt later” targets stored documents, not just signatures. ML-KEM (FIPS 203) envelope encryption for every document at rest closes that exposure.
Quantum-safe trust proofs
Timestamps and revocation proofs are signed by EU trust services with classical keys today. As qualified TSAs and OCSP responders migrate to post-quantum algorithms, containers become quantum-safe end-to-end.
No vaporware: everything marked in preview runs in the product today, and everything on standards watch states exactly what must happen in Brussels or at the trust providers first.
Build on what's
already ahead.
Integrate once — the switchboard and the algorithm registry absorb what's coming.