Knowledge
What is eIDAS — and what does AdES mean?
Our pages say every release is signed “to the eIDAS AdES bar”. That sounds technical — but it's simple: eIDAS is the EU framework that makes electronic signatures trustworthy, and AdES is the level easo signs at.
eIDAS in one sentence
eIDAS (Regulation (EU) No 910/2014, amended by eIDAS 2.0) is the EU framework for electronic signatures and trust services. It defines when an electronic signature is reliable — and for that it distinguishes three levels, from simple to qualified.
The three levels — and where easo sits
Not every electronic signature carries the same weight. eIDAS grades them by evidentiary strength.
-
Simple signature (SES)
An “I agree” click or a scanned signature. Fast, but low evidentiary weight — hard to prove who really signed, or whether anything changed afterwards.
-
Advanced signature (AdES) — where easo signs
Uniquely linked to one person, created under their sole control, and bound to the document so that any later change is detectable. The practical standard for internal QMS approvals.
-
Qualified signature (QES)
Like AdES, plus certification by a qualified trust service provider. Usually overkill for internal QMS approvals.
How easo signs to the AdES level
The four properties that make a signature “advanced” are not an add-on in easo — they are built into every release.
-
Uniquely linked to one person
Every release carries the key of exactly the person who approved it — not an anonymous account and not “the system”.
-
Under sole control
The private key lives on that person's device, not with us. easo cannot sign in your name — that is deliberate by design.
-
Tamper-evident
The signature is bound to the content via a checksum. If the text changes after release, verification fails — provable, not a promise.
-
Verifiable even without easo
The verification steps are printed on every exported PDF. You or an auditor can verify a release independently of our software.
The QMS question it answers
The signature is not an end in itself — it answers exactly the questions that matter in an audit.
-
“Who approved this?”
The signature names the responsible person unambiguously — not “the system”, not a shared account.
-
“Is the document unchanged since release?”
Because the signature is bound to the content, any later change becomes detectable.
-
“Does it hold outside easo?”
Yes — the signature is verifiable with standard means, independent of our software.
Honest: AdES, not QES
easo signs to the AdES level — the practical standard for internal QMS approvals: unique, under your control, tamper-evident. The highest level (QES) requires a certified trust service provider and is usually overkill for internal approvals. We never claim a level we don't technically meet.
Stay in the loop
easo is available for macOS — the Windows version is coming soon. Leave us a note and we'll reach out the moment it lands.