Skip to main content

SES / AES / QES signature levels

The European eIDAS regulation (No 910/2014) defines three electronic signature levels, with increasing legal value. TrueSign covers all three via Yousign, a qualified trust service provider — signatures are valid across all 27 EU countries.

The three levels

SES SimpleAES Advanced — TrueSign defaultQES Qualified
Signer authenticationEmail link (email OTP optional)SMS OTP — identity tied to the phone numberIdentity verification by a qualified provider
Typical useInternal documents, acknowledgements, simple NDAs95% of B2B contracts: sales, HR, amendmentsDocuments with reinforced formalism (notarial, consumer credit…)
eIDAS legal valueAdmissibleAdmissible, reliable signer identificationEquivalent to a handwritten signature
Signer experienceThe smoothestSMS code before signingPrior identification journey

Choosing a level

  • The level is configured per template (or at send time); authentication is set per signer.
  • AES is the default: the right balance of legal value and friction for everyday contracts. The signer's phone (international format) is then required.
  • Under AES, the interface only offers SMS OTP — and removes the per-signer override: the level constrains the authentication mode at the source, so an invalid level/authentication pair can never reach the provider.
  • With QES, the identification journey is fully handled by the qualified provider — TrueSign automatically omits incompatible authentication settings.
The level also depends on the provider

Yousign covers all three levels. weSign — the signature engine built into your org — produces SES exclusively: no PKI sealing, no qualified timestamp, no identity verification, no SMS OTP. A send requiring AES or QES on weSign is explicitly refused — never silently downgraded. See Signature providers.

Optional reinforcements

Stackable with the level, per signer:

  • Access code — a secret code shared out-of-band (phone) is required before accessing the document;
  • Identity verification (ID Check) — ID document + selfie before signing;
  • SMS delivery — the invitation goes out by SMS instead of email.

For a sensitive NDA: access code shared by phone + SMS OTP — double authentication before accessing the document.

The proof

Every signature produces a proof certificate, enforceable in a dispute. Its contents depend on the provider:

Yousign — authenticated identity, qualified timestamp, cryptographic sealing and document fingerprints.

weSign — the certificate is the proof, since there is no PKI sealing. It carries:

  • the document's SHA-256 fingerprint: change a single byte of the signed file and the fingerprint no longer matches;
  • for each signer — email, signing date and time, document read date and time, authentication mode, IP address;
  • the declared answers (the fields filled in), with their labels;
  • the fingerprint of the drawn signature mark, kept in your org.
Why a fingerprint rather than the signature image

A signature image proves nothing by itself — it can be copied. Its fingerprint, on the other hand, lets you verify that the mark stored in the org is indeed the one certified at signing time. That is stronger proof, not a compromise.

The certificate is downloadable with the signed document, including by a copied recipient. See also Logs & audit.