SES / AES / QES signature levels
The European eIDAS regulation (No 910/2014) defines three electronic signature levels, with increasing legal value. TrueSign covers all three via Yousign, a qualified trust service provider — signatures are valid across all 27 EU countries.
The three levels
| SES Simple | AES Advanced — TrueSign default | QES Qualified | |
|---|---|---|---|
| Signer authentication | Email link (email OTP optional) | SMS OTP — identity tied to the phone number | Identity verification by a qualified provider |
| Typical use | Internal documents, acknowledgements, simple NDAs | 95% of B2B contracts: sales, HR, amendments | Documents with reinforced formalism (notarial, consumer credit…) |
| eIDAS legal value | Admissible | Admissible, reliable signer identification | Equivalent to a handwritten signature |
| Signer experience | The smoothest | SMS code before signing | Prior identification journey |
Choosing a level
- The level is configured per template (or at send time); authentication is set per signer.
- AES is the default: the right balance of legal value and friction for everyday contracts. The signer's phone (international format) is then required.
- Under AES, the interface only offers SMS OTP — and removes the per-signer override: the level constrains the authentication mode at the source, so an invalid level/authentication pair can never reach the provider.
- With QES, the identification journey is fully handled by the qualified provider — TrueSign automatically omits incompatible authentication settings.
Yousign covers all three levels. weSign — the signature engine built into your org — produces SES exclusively: no PKI sealing, no qualified timestamp, no identity verification, no SMS OTP. A send requiring AES or QES on weSign is explicitly refused — never silently downgraded. See Signature providers.
Optional reinforcements
Stackable with the level, per signer:
- Access code — a secret code shared out-of-band (phone) is required before accessing the document;
- Identity verification (ID Check) — ID document + selfie before signing;
- SMS delivery — the invitation goes out by SMS instead of email.
For a sensitive NDA: access code shared by phone + SMS OTP — double authentication before accessing the document.
The proof
Every signature produces a proof certificate, enforceable in a dispute. Its contents depend on the provider:
Yousign — authenticated identity, qualified timestamp, cryptographic sealing and document fingerprints.
weSign — the certificate is the proof, since there is no PKI sealing. It carries:
- the document's SHA-256 fingerprint: change a single byte of the signed file and the fingerprint no longer matches;
- for each signer — email, signing date and time, document read date and time, authentication mode, IP address;
- the declared answers (the fields filled in), with their labels;
- the fingerprint of the drawn signature mark, kept in your org.
A signature image proves nothing by itself — it can be copied. Its fingerprint, on the other hand, lets you verify that the mark stored in the org is indeed the one certified at signing time. That is stronger proof, not a compromise.
The certificate is downloadable with the signed document, including by a copied recipient. See also Logs & audit.