eIDAS and Pensti
eIDAS is the EU regulation on electronic identification and trust services, including electronic signatures, seals and timestamps (Regulation (EU) No 910/2014, as amended by (EU) 2024/1183). This is exactly where Pensti stands.
Pensti provides simple electronic signatures (SES) under eIDAS Article 3(10), with extensive evidence for every signature. Pensti does not currently provide advanced (AdES) or qualified (QES) electronic signatures.
The three levels of electronic signatures
eIDAS distinguishes three levels. All three have legal effect; they differ in the strength of the evidence and in which formal requirements they meet.
| Level | Requirements | Legal effect | Pensti today |
|---|---|---|---|
| Simple (SES)Art. 3(10) | Data in electronic form attached to or logically associated with other electronic data and used by the signatory to sign. | Cannot be denied legal effect or admissibility as evidence solely because it is electronic or not qualified (Art. 25(1)). Its evidential weight is assessed case by case. | Yes – with detailed evidence |
| Advanced (AdES)Art. 3(11) and Art. 26 | Uniquely linked to and capable of identifying the signatory, created with data under the signatory's sole control, and linked to the document so that any subsequent change is detectable. | Same as a simple signature, but with stronger evidence of who signed. | No – planned with MitID/eID |
| Qualified (QES)Art. 3(12) | An advanced signature created by a qualified signature creation device and based on a qualified certificate from a qualified trust service provider on the EU trusted list. | Has the equivalent legal effect of a handwritten signature (Art. 25(2)) and is recognised in all EU member states (Art. 25(3)). | No – requires integration with a qualified provider |
When is a simple signature enough?
Under Danish law, contracts are generally not subject to formal requirements, so most business agreements – service agreements, NDAs, quotes and order confirmations – can be concluded with a simple electronic signature. What matters in a dispute is whether you can prove who signed what and when, and that is what Pensti documents. Some document types have formal requirements or require a specific signature solution, such as documents for land registration or wills. If in doubt, check with your legal adviser.
Pensti measured against Article 26
The requirements for an advanced signature are a useful yardstick for the strength of the evidence. Pensti fully meets requirement (d) and documents (a)–(c) with the mechanisms described here – but without reliable identification of the signatory, the signature is not an AdES.
Uniquely linked to the signatory
Each recipient gets their own personal signing link, sent to their email address. The signature is recorded with the recipient's ID, email, IP address, device, browser time zone and a session ID.
Capable of identifying the signatory
The first visit through the link is recorded as confirmation that the recipient controls the email address.
Limitation: Access to an email address does not identify a person with the same assurance as MitID or another eID. That is why the signature is simple, not advanced.
Under the signatory's sole control
The link is based on a random single-use key sent only to the recipient. It is replaced when a reminder is sent and invalidated once the recipient has signed.
Limitation: Control depends on the recipient's email account being secure.
Subsequent changes are detectable
The document's SHA-256 fingerprint is frozen at send and checked again before every signature. The final PDF is sealed with PAdES, the audit trail is hash-chained and append-only, and RFC 3161 timestamps bind the trail and the PDF to a point in time. Anyone can check a file on the public verification page.
Consent and intent
An electronic signature must be used by the signatory to sign (Art. 3(10)). Pensti therefore records every step with server time: that the document was displayed, the exact consent text the recipient accepted, every completed field and the explicit click on “Accept and sign”. A signature without that click is rejected.
Timestamps (Art. 41–42)
Pensti requests RFC 3161 timestamps from a timestamp authority after every signature and for the final PDF. An electronic timestamp cannot be denied legal effect solely because it is electronic (Art. 41(1)). Only a qualified electronic timestamp from a qualified provider (Art. 42) enjoys a presumption of the accuracy of the date, time and integrity of the data (Art. 41(2)). By default Pensti uses a public, non-qualified timestamp authority. Qualified timestamps require configuring a qualified service from the EU trusted list.
Electronic seal
The final PDF is digitally sealed (PAdES), so PDF readers show if the file is changed. The seal currently uses Pensti's own sealing certificate and is not a qualified electronic seal.
Planned
The following is not available today.
- Signer identification with MitID and other eIDs – aiming for advanced signatures (AdES).
- Integration with a qualified trust service provider – for qualified signatures (QES), qualified seals and qualified timestamps.
- Support for the EU Digital Identity Wallet (EUDI Wallet) under eIDAS 2.0 once available.
Sources
This page describes Pensti's features and is not legal advice. If an agreement requires a specific form of signature, check with your legal adviser.