Legal & Standards
Compliance Built In
rSign is designed from the ground up for full eIDAS compliance and long-term legal certainty.
Every signature module produces evidence that meets European and regional regulatory expectations
for banks and financial institutions.
Handwritten equivalence
EU + Adriatic recognition
Highest legal strength
Long-term validation ready
Legal foundation of every rSign signature
Two essential pillars that give banks confidence in every signed document.
eIDAS
The European legal framework that defines electronic identification and trust services.
Understand signature levels (SES / AES / QES), Article 25 legal effect, Qualified Certificates,
QSCD requirements and mutual recognition across Member States.
- Regulation (EU) No 910/2014 & eIDAS 2.0
- Qualified Electronic Signature requirements
- QTSP & QSCD roles
- How each rSign module complies
Signature Validation
Cryptographic and legal checks that confirm a signature is authentic, intact and still valid —
at the moment of signing and years later. Essential for audits, disputes and long retention periods
typical in banking.
- Certificate path & revocation checks
- Qualified timestamps
- PAdES / AdES long-term levels (LT / LTA)
- Audit-ready evidence packages
Why legal strength and validation matter
High-value products require evidence that stands up in court and before regulators.
Loans, mortgages & guarantees
Documents that must remain enforceable for 10–30 years need the highest legal certainty and long-term validation support.
Dispute resistance
A full QES + qualified timestamp + proper validation data dramatically reduces successful challenges of signature authenticity.
Regulatory & audit readiness
Supervisors and internal audit expect clear proof of origin, integrity and non-repudiation for electronically signed records.
Cross-border operations
eIDAS mutual recognition means a QES created in one Member State is recognised as a QES across the entire EU and many neighbouring markets.
How rSign modules meet legal requirements
All four modules are designed to produce signatures with strong evidentiary value under eIDAS.
PAES — On-site AES
Advanced Electronic Signature with biometric handwriting capture on signature pads.
High evidentiary value + qualified timestamp. Ideal when full QES is not required.
OQES — On-site QES
Face-to-face identification by bank clerk + one-time Qualified Digital Certificate from a QTSP.
Full Qualified Electronic Signature with Art. 25 equivalence — no hardware pads needed.
IQES — In-App QES
Already-authenticated banking-app users. Bank acts as Registration Authority;
QTSP issues a short-lived one-time QDC. Full QES without leaving the app.
RQES — Remote QES
Fully remote signing via trusted cloud identity providers or national eID schemes.
Full QES with remote QSCD operated under QTSP control.
What every bank should know
1. Only QES = handwritten
Under eIDAS Article 25(2), only a Qualified Electronic Signature has the equivalent legal effect of a handwritten signature.
2. Qualified Certificate is mandatory
A QES must be based on a qualified certificate issued by a supervised QTSP that appears on the EU Trusted List.
3. QSCD protects the private key
The signature must be created using a Qualified Signature Creation Device (local or remote) under the sole control of the signatory.
4. Validation data must survive time
Certificates expire and revocation services disappear. Long-term validation (LT / LTA) embeds the evidence needed for future verification.
Legal certainty, one API away
rSign delivers full eIDAS QES and validation-ready signatures for every banking scenario —
on-site, in-app or remote.