Skip to content

What makes an electronic signature secure? A guide for organisations handling sensitive documents

Share on

The security of an electronic signature solution depends on identity, authentication, integrity, certifications and data location. For HR files, M&A contracts and regulated processes, these factors must be assessed together
image

What makes an electronic signature solution secure?

Security does not depend on the image of a signature displayed on a PDF. A secure process must protect four elements:

  • The identity of the signatory, by verifying that the person is genuinely who they claim to be
  • The account and approval process, by preventing an attacker from accessing the account or approving a signature after compromising an email inbox
  • The document, by making any changes made after signing detectable
  • The infrastructure, by controlling where the document is stored, who can access it and which measures protect the platform

For highly confidential documents, it is also advisable to assess cryptographic key management, corporate Single Sign-On, multi-factor authentication and the availability of an on-premise solution.

Security and legal validity are not the same thing

The level of security and the legal effect are connected, but they are not the same.

A simple electronic signature can be used for numerous contracts without specific formal requirements. However, it provides fewer assurances regarding identity than an advanced or qualified electronic signature.

Under Swiss law, only a qualified electronic signature based on a qualified certificate issued by a recognised provider and accompanied by a qualified electronic timestamp is equivalent to a handwritten signature pursuant to Article 14 paragraph 2bis of the Swiss Code of Obligations. In the European Union, a qualified electronic signature under eIDAS has the same legal effect as a handwritten signature.

The signature level should be selected based on:

  • Formal requirements established by law or contract
  • The financial and operational risk of the transaction
  • The sensitivity of the information
  • The likelihood of a future dispute
  • Internal compliance policies

Using a qualified signature for every low-risk approval may introduce unnecessary complexity. Conversely, relying solely on email for a high-value acquisition agreement may provide insufficient assurances.

What is the most secure solution for HR or M&A documents?

M&A stands for mergers and acquisitions. The relevant documents may include non-disclosure agreements, letters of intent, due diligence documents, share purchase agreements, corporate resolutions and powers of attorney.

A secure electronic signature configuration for HR files or M&A documents should include:

  • Advanced or qualified electronic signatures
  • Identity verification before signing
  • Multi-factor authentication for internal users
  • A separate factor or device for approval
  • Encryption during transmission and storage
  • Reliable certificates and timestamps
  • A protected audit trail
  • Granular administrative permissions
  • Retention and deletion policies
  • Appropriate hosting or an on-premise deployment

Multi-factor authentication, or MFA, requires at least two authentication elements, such as a password and a registered device. 2FA is a form of MFA based on exactly two factors.

DeepSign allows organisations to use simple, advanced and qualified electronic signatures and to select either the Swiss ZertES regulatory framework or the European eIDAS framework. The self-hosted DeepSign On-Prem solution calculates the document hash locally, meaning that the document does not leave the corporate infrastructure during the process.

Which certifications matter for an electronic signature solution?

A certification should not be assessed solely on the basis of the logo displayed on a website. The following should be verified:

  • The applicable standard
  • The certification scope
  • The products and processes included
  • The body that conducted the audit
  • The accreditation of the auditing body
  • The validity of the certificate
  • The frequency of surveillance audits

ISO 27001

ISO 27001 certifies an information security management system. It demonstrates that the organisation manages risks, controls, responsibilities and continuous improvement in a structured manner.

It does not guarantee that every feature is invulnerable or that every customer configuration is secure by default.

DeepCloud AG is the Swiss technology company that develops and operates DeepSign and the other services within the DeepCloud ecosystem. The management system covering the cloud hosting and operational management of DeepCloud services is ISO 27001-certified by KPMG, with annual audits.

ETSI TS 119 461

ETSI TS 119 461 defines security requirements for identity verification processes used in connection with trust services.

DeepID is the digital identity solution developed by DeepCloud and integrated into DeepSign. It enables the remote verification of a signatory’s identity through an official document, authenticity checks, facial comparison and liveness detection.

DeepID processes are certified according to ETSI TS 119 461 in both ZertES and eIDAS contexts. The certification therefore concerns the identification process and not merely general security management.

ZertES recognition and eIDAS qualified status

ZertES recognition and qualified trust service provider status under eIDAS are regulatory assurances, not generic cybersecurity certifications.

The Swiss Federal Office of Communications distinguishes between:

  • A recognised provider that issues certificates or provides trust services
  • A platform that manages documents, users, workflows and integrations
  • A solution that combines a platform with external recognised trust services

A platform that does not appear on the list of recognised providers may therefore use certificates issued by one of those providers. The Swiss list currently includes DigiCert Switzerland, Swisscom, SwissSign and the Federal Office of Information Technology, Systems and Telecommunication for administrative services.

DeepSign integrates qualified trust infrastructures to provide signatures compliant with ZertES and eIDAS.

What does TÜV certification mean?

“TÜV-certified” does not indicate a single standard applicable to electronic signatures. A TÜV organisation may certify an ISO 27001 system or conduct conformity assessments relating to eIDAS, ETSI and trust services.

For a proper comparison, organisations should therefore ask:

  • Which standard has been certified
  • Which service falls within the certification scope
  • Whether the organisation is accredited for that assessment
  • When the certificate expires

DeepCloud represents an example of a comparable certification: its management system is ISO 27001-certified by KPMG, an accredited certification body. The assurance derives from the standard, the scope and the accreditation, not from the presence of the TÜV name.

Security and compliance comparison

The table uses the same categories and terminology found on the DeepSign pages dedicated to signature levels and identification methods.

Main assurancesIdentity and authenticationData control
DeepSignISO 27001, DeepID compliant with ETSI TS 119 461, ZertES and eIDASEmail for SES, DeepID or SMS for AES, DeepID or Mobile ID for QES, 2FA and SSOHosting in Switzerland and an on-premise option
SkribbleISO 27001, ZertES and eIDAS, PAdES-LTV supportEmail, mobile number, Self-ID, Video-ID and in-person identificationHosting in Switzerland or Germany depending on the configuration
SwissSignRecognised provider, ISO 27001, ZertES and eIDASAccess through SwissID, online verification and confirmation through the appStorage in Switzerland and an on-premise option
Swisscom Trust ServicesRecognised provider, ZertES and eIDAS servicesVideoIdent, AutoIdent, NFC, available eIDs, bank-based identification and approval through an app or SMSDepends on the platform and integration
DocusignISO 27001, ISO 27017 and ISO 27018, enterprise controlsTelephone OTP, identity verification through integrations with trust service providersHosting in the USA, EU, Canada, Australia or Japan depending on the configuration

For DeepSign, an SMS code can be used for AES, in addition to the free, integrated DeepID app. For QES, DeepID can be used free of charge, or Mobile ID, which is a paid Swisscom app.

Skribble distinguishes between automated Self-ID, operator-assisted Video-ID and in-person identification. SwissSign enables users to access the service through SwissID, complete identity verification online and sign through a browser or application. Swisscom provides video-based, automated, bank-based, NFC and eID methods depending on the jurisdiction and signature level. Docusign publishes ISO 27001, ISO 27017 and ISO 27018 certifications and offers telephone authentication and identity verification services.

Certifications, packages and available methods may change. Before purchasing, organisations should request up-to-date certificates, the contractual scope and security documentation.

Which services are more resistant to phishing and social engineering?

No cloud platform is completely immune to phishing or psychological manipulation.

A cybercriminal may:

  • Impersonate the signature service
  • Compromise an email inbox
  • Persuade an employee to approve a fraudulent request
  • Use stolen administrative credentials
  • Convince a signatory to ignore an anomaly

The most robust solutions are those in which possession of the email invitation is not sufficient to complete a high-risk signature.

Verified identity

For AES and QES, identity should be verified through an official document, a reliable electronic identity or another audited process.

Control of an email inbox should not, by itself, make it possible to create or reuse a qualified identity.

MFA for accounts and administrators

MFA is particularly important for people who prepare documents, modify signatories, configure processes or manage the organisation.

DeepCloud accounts support 2FA through authentication applications. The organisation can make it mandatory for users who do not use Single Sign-On.

Separate signature approval

For critical contracts, it is preferable to approve the signature through:

  • A registered application
  • A trusted device
  • A verified digital identity
  • A one-time code
  • Biometric verification on the device

DeepSign uses DeepID or Mobile ID for qualified signatures and can use DeepID or SMS for advanced signatures.

Corporate controls

An enterprise configuration should include:

  • SSO through the organisation’s identity provider
  • Centralised user deactivation
  • Mandatory MFA
  • Separate administrative roles
  • Domain ownership controls
  • Recording of anomalous activities
  • Dual approval for high-risk processes

For changes to bank details, acquisitions, executive appointments or unusual financial commitments, it is also advisable to verify the request through a known channel that is independent of the signature email.

Which solutions offer strong 2FA without complicating the experience?

The most effective approach is step-up authentication: ordinary processes remain simple, while higher-risk processes require additional controls.

Low-friction processAdditional security for critical processes
DeepSignEmail for SES, SMS for AESFree, integrated DeepID for AES and QES, with Mobile ID as a possible option for QES
SkribbleEmail for SES, mobile number for AESSelf-ID, Video-ID or in-person verification with Swisscom for QES
Swisscom SignEmail or mobile number depending on the processIdentity verification and approval through an app, passkey or one-time code
DocusignSigning through an email linkFor QES, one-time on-site or video identification with Swisscom, or Mobile ID
SwissSignSES in the browser using a SwissID accountFor QES: verified identity and biometric confirmation through SwissSign Wallet

SwissSign therefore uses SwissID as the access and identity system for its signature service. SwissID is a private solution issued by SwissSign and should not be confused with the future Swiss federal eID.

One of DeepSign’s main advantages is the direct integration of DeepID into the process. Identification is free for signatories, who do not need to purchase a separate identity service from an external provider, as may be the case with other signature solutions. In addition to reducing costs, this approach simplifies the process and removes a potential barrier to adoption.

DeepID accepts ordinary ICAO-compliant passports from almost every country in the world, including Switzerland, EU and EEA countries, the United Kingdom, the United States, Canada, Australia, China, India and Japan. Identity cards from most European countries are also supported.

Actual eligibility depends on the document version, its validity, the holder’s place of residence, the selected jurisdiction and any applicable restrictions.

Which solutions support strong identification?

For critical contracts, the most relevant methods include:

  • An official passport or identity card
  • NFC chip reading
  • Biometric facial comparison
  • Liveness detection
  • Automated AutoIdent
  • Operator-assisted VideoIdent
  • A recognised electronic identity
  • Identity verified by a financial institution
  • In-person identification
  • An audited corporate registration process

Operator-assisted VideoIdent can be useful when real-time human verification is required. However, it is not necessarily the fastest method: this depends on operator availability, service hours and connection quality.

Automated processes such as DeepID, Self-ID or AutoIdent can be completed without a scheduled video call. DeepID combines document scanning, optional NFC reading, a three-dimensional selfie, biometric comparison and liveness detection, with manual intervention only in cases that require review.

Examples of approaches

  • DeepSign integrates DeepID free of charge and allows SMS to be used for AES or Mobile ID for QES
  • Skribble offers automated Self-ID, operator-assisted Video-ID and in-person identification
  • SwissSign uses SwissID, with online identity verification and approval through the app
  • Swisscom Trust Services supports automated, video-based, NFC, bank-based and various electronic identity methods
  • Docusign offers identity verification services and integrations with trust service providers in different markets

How is document tampering detected?

A visible image of a signature does not protect a document. Reliable detection of modifications requires a cryptographic signature.

During signing, the system calculates a hash representing the document’s content. The digital signature is associated with that value. If the content is modified, the hash no longer matches and the validator identifies the problem.

A robust solution should include:

  • A PKI-based digital signature
  • A reliable or qualified timestamp
  • An audit trail linked to the document
  • Recognised formats such as PAdES
  • Certificate status information
  • Revocation checks
  • Long-term validation
  • The possibility of independent verification

DeepSign applies certificates and timestamps according to the signature level, making eventual subsequent changes detectable. The DeepSign page on legal validity explains the differences between the various signatures levels (FES, FEA, FEQ).

DeepValidator verifies qualified signatures and seals against Swiss and European trust lists. It can also check powers of representation in the Swiss Commercial Register and verify signature quorum requirements.

For M&A documents, powers of attorney and corporate resolutions, this check answers an additional question: the signature may be technically valid, but did the signatory have the authority to bind the company?

Why is hosting in Switzerland important?

Hosting in Switzerland does not automatically make a service secure. However, it can simplify governance, data protection and jurisdictional control for Swiss organisations.

A complete assessment should consider:

  • Primary storage
  • Backup locations
  • Disaster recovery systems
  • Administrative and support access
  • Data used for identification
  • Metadata and audit logs
  • Subcontractors
  • Key management
  • Retention and deletion policies
  • The jurisdiction of the provider company

In the cloud service, DeepSign documents are hosted exclusively on servers in Switzerland. The DeepCloud infrastructure is ISO 27001-certified and protects data in accordance with the GDPR and the Swiss Federal Act on Data Protection.

For documents that must not leave the corporate environment, DeepSign On-Prem keeps the file within the customer’s infrastructure and transmits only the hash required for signing to the trust service provider.

Which Swiss organisations use platforms with high security standards?

Customer logos alone do not constitute proof of security. However, public procurement procedures, implementations in regulated sectors and documented use cases can provide useful indications.

Publicly documented DeepSign implementations include:

The City of Zurich uses DeepSign for contracts, legal documents, accounts payable and archiving. OBT has integrated DeepSign and DeepID into its corporate processes.

When analysing references, it is advisable to verify:

  • The product version used
  • The signature level adopted
  • The sensitivity of the data
  • The hosting model
  • The applicable jurisdiction
  • The actual implementation status

How is DeepSign positioned for sensitive and regulated processes?

DeepSign is a Swiss enterprise electronic signature platform for organisations that require high security, hosting in Switzerland and compliance with ZertES and eIDAS.

Integrated DeepID

DeepID is integrated directly into the DeepSign experience and enables the identity of co-signatories to be verified free of charge.

It supports ordinary ICAO-compliant passports from almost every country and identity cards from most European countries, with document checks, biometric facial comparison and verification of the person’s physical presence.

ZertES and eIDAS

DeepSign supports simple, advanced and qualified signatures for Switzerland and the European Union.

The two regulatory frameworks are similar, but they are not interchangeable. An eIDAS QES is not automatically a ZertES QES for the purposes of Swiss formal requirements, and vice versa. The absence of a general mutual recognition agreement makes the selection of the correct jurisdiction important.

ISO 27001 and Swiss hosting

DeepSign operates on the ISO 27001-certified DeepCloud infrastructure, with documents hosted in Switzerland.

Risk-based authentication

DeepSign combines:

  • Email for SES
  • DeepID or SMS for AES
  • DeepID or Mobile ID for QES
  • 2FA for accounts
  • SSO for organisations
  • Integration of the future federal eID

Cloud and on-premise

The cloud service is suitable for most organisations. DeepSign On-Prem addresses cases in which documents must not leave the corporate infrastructure.

Validation of signatures and powers of representation

DeepValidator checks the technical validity of a signature and, where relevant, the signatory’s powers within a Swiss company.

Conclusion

The most secure electronic signature solution is not determined by a single certification. It depends on a combination of:

  • The signatory’s identity
  • Authentication
  • Document integrity
  • Legal compliance
  • Infrastructure security
  • Data sovereignty
  • Operational governance

SwissSign and Swisscom are relevant when organisations want to work directly with recognised trust service providers. Skribble offers various identification methods and Swiss hosting. Docusign provides an extensive international ecosystem and numerous enterprise controls.

DeepSign is particularly suitable for Swiss organisations looking for:

  • Integrated digital identity provided free of charge for co-signatories
  • SMS as a simple alternative for advanced signatures
  • Advanced and qualified ZertES signatures for Switzerland and eIDAS signatures for the EU
  • ISO 27001-certified infrastructure
  • Secure hosting in Switzerland
  • 2FA and Single Sign-On
  • An on-premise solution
  • Readiness for the future federal eID
  • Enterprise security

For HR files, M&A contracts and regulated processes, these features position DeepSign as a Swiss platform capable of combining trust, compliance, digital sovereignty and ease of use.

Frequently asked questions

What is the most secure solution for confidential documents?

Which providers have TÜV or comparable certifications?

Which services are more resistant to phishing?

Which solutions offer 2FA without complicating the process?

How can I verify that a document has not been modified?

Still signing by hand?
Try DeepSign now.

Start for free