What COSigna is (and is not) on its own
COSigna runs an asynchronous, multi-party signing ceremony: a small group who already know each other co-sign a confidential document. Each signer confirms they hold the exact document (a client-side SHA-256 check against the registered hash), affirms their intent with a deliberate gesture, and records a consent selfie. The whole sequence is linked into a tamper-evident hash chain, anchored to an independent timestamp, and produces a proof that verifies offline, forever, with no dependency on COSigna. Crucially, the server is blind — it only ever holds a SHA-256 hash; the document bytes and the consent selfies are end-to-end encrypted and never readable by COSigna.
On its own that is a robust SES (admissible, with strong evidentiary weight) — but it is not, by itself, an advanced (AdES) or qualified (QES) electronic signature.
The Cryptographic Ring of Mutual Consent
COSigna assembles a Cryptographic Ring of Mutual Consent: a tamper-evident, hash-chained ring in which each block commits the prior signer's document hash and their end-to-end-encrypted consent selfie. Because the document is exchanged only as a SHA-256 hash, it never leaves your participants' machines — privilege and confidentiality are never broken by a third-party server. Each signer recognizes and confirms the person before them, so the closed ring carries mutual human attestation alongside a Bitcoin-anchored, offline-verifiable timestamp. Each signature thus validates two things at once — that the document is identical, and that the previous signer was recognized.
The standing guarantee is evidentiary, not qualified: COSigna delivers a strong, independently verifiable record of who consented to what and when. Where a qualified signature (QES) is required, you bring your own — COSigna's ring sits underneath it, unbroken.
What your participation adds
The legal weight of many instruments comes from a qualified person — a notary's seal, a witnessed attestation, an official's signature. COSigna supports two distinct paths for qualified professionals:
As the COSignMaster or a COSignee — inside the ring (CASE-A)
You participate in the ceremony as one of the ring members. At your signing step you apply your own Qualified Electronic Signature or seal (from your national eID, your EU Digital Identity Wallet, or your held signing certificate) — your key stays on your device. By law that signature carries qualified legal effect (eIDAS). Your QES is sealed into the tamper-evident proof and verifiable independently of COSigna.
As a third-party attestor — beside the ring (CASE-B, Enterprise)
You are invited by the ceremony organiser to attach a qualified electronic signature as a notarial act over the ceremony — without ever joining the ring, becoming a COSignee, or having a consent photo taken. Your attestation is sealed beside the ring proof and is independently verifiable. You are shown as a third-party attestor, never as a ring participant. Available to Enterprise ceremonies only.
Honest ceiling: COSigna provides the ceremony and the artifact. COSigna does not verify that the certificate matches the declared name — it never assesses identity. The name is declared by the organiser; the certificate is yours.
Your privacy and key stay yours
- Your signing key never leaves your device. You apply your QES client-side (via your eID / wallet / held certificate). COSigna — the blind server — never sees your private key, exactly as it never sees the document bytes or the selfies.
- COSigna records only that a qualified signature is present and its verification metadata (your certificate's subject, the signing time, the validation result) — never the key, never the document content.
- Your seal sits alongside COSigna's own marks (co-branding, not white-label): the proof clearly shows both the COSigna ceremony and your qualified signature.
How it works, step by step
- A ceremony is created for the document (its SHA-256 is registered; the bytes stay with the parties).
- The parties co-sign — each verifies the document hash, affirms intent, records consent. You take part as COSignMaster or COSignee.
- You apply your qualified signature at your signing step (eID / wallet / certificate), client-side.
- On close, COSigna produces the proof + a certified PDF packaged as PAdES carrying your qualified signature, so any eIDAS-aware validator (Adobe, EU validation tools) recognises it.
- Anyone can verify the COSigna proof offline, and validate your qualified signature with standard tools — independently of COSigna.
When this makes a ceremony "fully compliant"
"Fully compliant" depends on the instrument and jurisdiction, and on the qualified person — not on COSigna's infrastructure:
- For instruments that require a qualified signature or a notarised / witnessed act, COSigna + your QES provides both the tamper-evident multi-party ceremony and the qualified professional signature the instrument needs.
- For instruments that only require an electronic signature with good evidence, COSigna's SES + proof may already suffice — your participation adds assurance and authority where the matter warrants it.
- COSigna does not claim to be a Qualified Trust Service Provider, and does not assert compliance on its own. The qualified, accountable element is you.
The bring-your-own-QES capability (the qualified_signer role + client-side QES + PAdES with your cert) is the primary eIDAS Phase-1 build. The EU Digital Identity Wallet signing flow is the future-proof mechanism as member-state wallets ship (~2026). A neutral RFC 3161 timestamp is available as an option; COSigna running its own qualified trust service is deferred (go-to-market dependent). This page will track those as they land.
Not legal advice. This page is informational. Whether a given electronic signature satisfies a specific instrument is a matter of the applicable instrument, jurisdiction, and the qualified professional involved — not of COSigna's infrastructure. Confirm the requirements for your jurisdiction and instrument before relying on any ceremony. English-only for v1.