Encryption in transit and at rest, EU-only hosting and strict data separation.
All exchanges between your browser and our servers are encrypted with TLS 1.3 using modern cipher suites (ECDHE-ECDSA-AES256-GCM-SHA384). Older TLS versions (1.0, 1.1, 1.2) are disabled.
Uploaded documents and identity data are encrypted at rest with AES-256. Encryption keys are stored in a separate KMS service, never co-located with the data.
All signing operations and data storage happen on EU-hosted servers (Paris and Dublin regions). No data is transmitted outside the EU as part of operational service.
Identity data (IDs, photos), documents to sign, payment information and technical logs are stored in separate databases with distinct access controls per category.
Processing register maintained, GDPR-compliant subprocessors, access/rectification/erasure rights honored within 30 days, DPO reachable. See our privacy policy.
The signed document is automatically deleted from our systems 30 days after delivery (unless explicitly extended). Identity documents are kept for the eIDAS minimum of 10 years, then deleted.
Certif Europe stores no banking data. All payments are handled by our licensed payment provider, certified PCI DSS Level 1 (the highest banking compliance level). Card data is entered directly in our payment provider’s secure environment and never transits our servers.
We apply automated checks on every order:
Our partner Qualified Trust Service Provider undergoes annual audits by an accredited compliance body (CAB), in accordance with Article 17 of the eIDAS Regulation. Audit reports are submitted to the national supervisory body (ANSSI in France).
Certifications applicable to our partner QTSP typically include:
The Certif Europe infrastructure is designed for 99.9% availability. In case of incident:
If you discover a vulnerability or potential security flaw, write immediately to security@certifeurope.com. We acknowledge receipt within one business day and investigate within 48 hours. Per our responsible disclosure policy, good-faith security researchers are protected from any legal action.
We document our full stack for institutional buyers.
Request documentationLeave your email, we reply within a few hours. Or email us directly at support@certifeurope.com.