> ## Documentation Index
> Fetch the complete documentation index at: https://docs.firma.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Legal Validity & eIDAS Compliance

> Where Firma's electronic signatures stand under eIDAS, ESIGN/UETA, and country-specific rules in Italy, Spain, France, and Germany — and what Firma does not provide.

<Note>
  This page explains the legal frameworks that apply to electronic signatures. It isn't legal advice. Whether a given document can be signed electronically — and which signature tier it needs — depends on the laws of the relevant jurisdiction and the specific document. Consult qualified local counsel for your use case.
</Note>

**Quick answer:** Firma provides an **Advanced Electronic Signature (AES)** under eIDAS, with a full audit trail and a tamper-evident digital seal on every completed document. This is legally sufficient for the large majority of contracts, NDAs, HR documents, and commercial agreements across the EU and US. Firma is **not** a Qualified Trust Service Provider (QTSP) and does not issue **Qualified Electronic Signatures (QES)**. A small set of document types — real estate transfers, some employment terminations, notarized acts — require QES or a notary regardless of which e-signature provider you use.

## The three tiers of electronic signature under eIDAS

eIDAS (EU Regulation 910/2014) doesn't certify individual products as "compliant" or "non-compliant." Instead, Article 25 sets out three tiers of electronic signature, each with a different legal effect. Industry shorthand for the baseline tier is "Simple Electronic Signature" (SES) — the Regulation itself doesn't use that label, but defines the tier in Article 3(10).

| Tier                                 | eIDAS basis         | What it takes                                                                                                                                                                 | Legal effect                                                                                                                                                      |
| ------------------------------------ | ------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Simple Electronic Signature (SES)    | Art. 3(10)          | Any data in electronic form attached to other data and used to sign — a typed name, a scanned signature image, a click-to-agree                                               | Can't be denied legal effect or admissibility solely because it's electronic (Art. 25(1)), but no automatic presumption of equivalence to a handwritten signature |
| Advanced Electronic Signature (AES)  | Art. 3(11), Art. 26 | Must be uniquely linked to the signer, capable of identifying them, created under their sole control, and linked to the signed data so any later change is detectable         | Same admissibility floor as SES, but the identity link and tamper-detection make it materially harder to dispute in practice                                      |
| Qualified Electronic Signature (QES) | Art. 3(12)          | An AES created on a Qualified Signature Creation Device (QSCD), using a Qualified Certificate issued by a Qualified Trust Service Provider (QTSP) after identity verification | Art. 25(2): legally equivalent to a handwritten signature. Art. 25(3): automatically recognized in every EU/EEA member state                                      |

Only QES carries the automatic "equivalent to handwritten" presumption and automatic cross-border recognition. AES and SES are still legally valid and admissible everywhere in the EU — they just don't carry that automatic presumption, so their evidentiary weight is argued on the facts if a signature is ever challenged.

## What Firma provides

Firma's signing process is designed to meet the **Advanced Electronic Signature** bar:

* **Signer identity capture** — every signer's name and email are recorded and linked to their signature, with optional one-time-passcode (OTP) verification as an additional identity factor.
* **Full audit trail** — every document view, field interaction, signature, and decline is logged with a timestamp, actor identity, and IP address. See the [Audit Trail guide](/guides/audit-trail) for the full event schema.
* **Tamper-evident digital seal** — on completion, Firma applies a PAdES digital seal (the ETSI standard signature format for PDFs) to the final document. The seal embeds the signing certificate, a trusted timestamp, and revocation information directly in the file, so it can be verified independently of Firma's own servers.
* **Certificate of completion** — a summary of the signing process is embedded in the final PDF alongside the seal.
* **EU-hosted infrastructure** — Firma's database and document-processing services run in EU data centers (Supabase and AWS Lambda both in `eu-west-3`).

Together, this gives you a signature that's uniquely linked to the signer, backed by an identity check, and provably unaltered since signing — the criteria that define an AES under Article 26.

## What Firma does not provide

To be direct about the boundary:

* **Firma is not a Qualified Trust Service Provider (QTSP).** It isn't on the EU Trusted List, and it doesn't issue Qualified Certificates.
* **Firma does not produce Qualified Electronic Signatures (QES) or Qualified Electronic Seals.** The digital seal on your completed documents is an AES-level seal, not a QES — it does not carry the Article 25(2) presumption of equivalence to a handwritten signature or the Article 25(3) automatic cross-border recognition that QES gets.
* **SOC 2 and ISO 27001 aligned.** Firma's security practices are designed around the SOC 2 Trust Services Criteria and ISO 27001 controls. See [Security & Compliance](/guides/security) for details.
* **No Adobe Approved Trust List (AATL) membership** — see [below](#why-theres-no-green-checkmark-in-adobe-acrobat) for what that means in practice.

If your use case specifically requires QES — a qualified certificate-based signature, typically obtained via a licensed QTSP with in-person or video identity verification — Firma is not the right tool for that document on its own.

## Electronic signatures in the United States: ESIGN and UETA

The US doesn't use eIDAS's tiered model. The federal ESIGN Act and the state-level Uniform Electronic Transactions Act (UETA, adopted by nearly every state — New York uses its own similar Electronic Signatures and Records Act instead) both work on the same principle: a signature or record can't be denied legal effect solely because it's in electronic form, provided the process shows:

* **Intent to sign** — the signer took an affirmative action to sign.
* **Consent to do business electronically** — particularly important for consumer transactions, where ESIGN requires specific disclosures about the right to receive a paper copy and withdraw consent.
* **Attribution** — the signature can be tied to the person who signed.
* **Record retention** — the signed record can be accurately reproduced later.

Because ESIGN and UETA aren't tied to a specific signature technology, Firma's AES-level process — identity capture, explicit signing action, tamper-evident seal, full audit trail — is well-positioned to satisfy all four elements for most business, consumer, and healthcare contracts under US law.

A narrow set of document types is excluded from ESIGN/UETA entirely and generally still requires a wet-ink signature: wills and testamentary trusts, certain family-law documents (divorce, adoption), court orders, notices of utility cancellation, notices of foreclosure or eviction, product recall notices, and documents required to accompany the transport of hazardous materials.

## Country-specific notes

These are the questions we hear most often from signers and senders in specific EU countries. They're general context, not a substitute for local legal advice.

### Italy

Italian users often ask whether Firma qualifies as *firma elettronica avanzata* (FEA) under Italian domestic law. eIDAS AES and Italy's domestic FEA concept are related but not identical — Italy's implementing rules (under the *Codice dell'Amministrazione Digitale* and AgID technical guidelines) impose additional technical requirements on FEA solutions for certain regulated use cases within Italy. Firma's signature meets the EU-wide eIDAS AES bar described above; we don't claim compliance with Italy's domestic FEA technical specification. Where Italian law requires *firma elettronica qualificata* (Italy's term for QES) or notarization — real estate transfers, for example — consult Italian counsel.

### Spain

Under Spain's Civil Code freedom-of-form principle and Ley 6/2020 (Spain's domestic implementation of eIDAS), an AES like Firma's is generally sufficient for private contracts and is admissible as evidence. Certain acts require a notarial deed (*escritura pública*) regardless of signature technology — real estate transfers, mortgages, and specific corporate resolutions are common examples. Those require an in-person notary, not any tier of electronic signature.

### France

French Civil Code Article 1367 (formerly 1316-4) ties an electronic signature's legal weight directly to the eIDAS tiers, and French courts have historically scrutinized whether the AES criteria — identity verification and tamper-detection — are actually met, more closely than in some other member states. That's one reason a complete audit trail and an identity-verification step (Firma supports OTP as an additional factor) matter specifically in France: if a signature is ever challenged, you want documented proof that the AES criteria were met, not just the label. Certain French acts still require a notarial deed (*acte authentique*) — real estate transfers and matrimonial agreements among them — regardless of signature tier.

### Germany

German civil law imposes strict statutory written-form (*Schriftform*) requirements on certain contract types. Where the law requires *Schriftform* under § 126 BGB, only a **Qualified Electronic Signature** — not an AES — can substitute for it electronically, under § 126a BGB. Firma's AES-level signature is not sufficient for those documents. Some statutory form requirements go further and exclude electronic form entirely, requiring a wet-ink signature regardless of tier — termination of an employment contract under § 623 BGB is a well-known example. For contracts not subject to a statutory form requirement — the majority of commercial agreements, NDAs, and consumer contracts, under German law's general freedom-of-form principle — AES is legally sufficient. If you're unsure whether your document falls under a *Schriftform* requirement, check with German counsel before relying on Firma alone.

## Why there's no green checkmark in Adobe Acrobat

Adobe Acrobat and Reader show a green checkmark automatically only for signatures whose certificate chains to a root on the **Adobe Approved Trust List (AATL)** — a curated list of certificate authorities that ship pre-trusted inside Adobe's software. Acrobat can also be configured to trust certificates chaining to the EU Trusted List (EUTL), the list of EU-recognized QTSPs.

Firma is neither an AATL member nor a QTSP on the EUTL, so the certificate behind Firma's digital seal doesn't chain to either list. Acrobat will typically show the seal as present, but without the automatic green checkmark — you may see a neutral or unverified trust indicator instead, even though the seal itself is fully valid.

This is a limitation of Acrobat's default trust store, not a defect in the signature. The seal is still cryptographically verifiable independent of Adobe:

* Recipients can check the signature panel in Acrobat/Reader to inspect the certificate directly.
* Anyone can independently verify a signed document's seal at [app.firma.dev/validate-signature](https://app.firma.dev/validate-signature) — Firma's public signature validator — without relying on any PDF viewer's trust store at all.

## What holds up as evidence

If a signature is ever disputed, what typically matters — under Article 25(1) eIDAS, ESIGN, or UETA alike — isn't a technology label by itself, but whether you can show who signed, when, with clear intent, and that the record hasn't changed since. Firma's combination of identity capture, a complete [audit trail](/guides/audit-trail), a tamper-evident PAdES seal, and an embedded certificate of completion is designed to answer exactly that, for both AES-sufficient use cases in the EU and ESIGN/UETA use cases in the US.

That said, no vendor can guarantee an outcome in litigation — sufficiency of evidence is ultimately decided by the relevant court or authority on the facts of the case. For high-value transactions, or any document that might fall under a QES, notarization, or statutory written-form requirement in your jurisdiction, confirm the requirement with local counsel before relying on Firma alone.

## Related guides

* [Audit Trail](/guides/audit-trail) — the full event schema behind every signing request
* [Webhooks](/guides/webhooks) — get notified in real time when a certificate is generated or a signature completes
