Legal

Technical features of the advanced electronic signature (AES) solution

Last updated: 28 September 2026

This is a courtesy translation: in the event of any conflict, the Italian text prevails. Read the Italian version

This page describes the technical features of the advanced electronic signature (AES; under Italian law, Firma Elettronica Avanzata, FEA) solution made available by Grem S.r.l., with registered office at Via Matteo La Fragola, 4, Salerno (SA), VAT no. / tax code IT06136730659 (hereinafter "DOCUJET" or "we"), pursuant to Article 57 of the Italian Prime Ministerial Decree (DPCM) of 22 February 2013 ("Technical rules on electronic signatures"). Publishing the technical features is an obligation of the entity that provides an AES solution under the model referred to in Article 55(2)(a) of the same decree.

1. Subject matter and delivery model

DOCUJET makes it possible to sign electronic documents with electronic signatures of different levels under Regulation (EU) 910/2014 (eIDAS) and Italian Legislative Decree 82/2005 (Codice dell'Amministrazione Digitale, CAD): Simple Electronic Signature (SES) and Advanced Electronic Signature (AES), where the technical requirements are met. DOCUJET provides the AES under the autonomous model (Article 55(2)(a) of the DPCM of 22/2/2013): DOCUJET is both the entity that builds the solution and the one that makes it available to signers.

DOCUJET's AES meets the requirements of Article 26 eIDAS: it is uniquely linked to the signatory (point (a)), capable of identifying them (point (b)), created using data that the signatory can use under their sole control (point (c)) and linked to the signed data in such a way that any subsequent change is detectable (point (d)).

2. Identification of the signer

Identification takes place remotely, before signing, using methods proportionate to the level required.

2.1. Simple Electronic Signature (SES)

The signer is reached at a personal contact point (mobile number or email address) and confirms the signature by entering a single-use OTP code sent there. Possession of the contact point and entry of the code constitute the signing tool.

2.2. Advanced Electronic Signature (AES)

In addition to the OTP, an enhanced identity check (KYC) is carried out:

  • capture of the identity document (front and back) and of a selfie of the signer;
  • extraction of the data from the document (OCR) and comparison of the name with the one indicated in the document to be signed (name match);
  • biometric comparison between the face in the selfie and the photo on the document (face match) and a liveness check;
  • declaration of acceptance by the signer, who confirms their identity and the exclusive use of the contact point used for the OTP.

The images of the document and of the selfie are encrypted at rest with AES-256-GCM and the outcome of the check is recorded in a structured way.

3. Signing process and architecture

Each signature follows a technical sequence tracked end to end:

  • Full viewing of the document, verified on the server side (scrolling through all the pages);
  • acceptance of the versioned consents, for which the cryptographic hash (SHA-256) of the exact text accepted is kept, together with the date/time, IP address and user agent;
  • entry of the OTP and confirmation of the signature;
  • Qualified Electronic Seal (eIDAS Art. 35) applied by the qualified device of the trust service provider Namirial, to guarantee the integrity and origin of the document;
  • Qualified time stamp (eIDAS Arts. 41-42) for a legally certain date (data certa) that can be relied upon against third parties;
  • PAdES format, with long-term enrichment (PAdES B-LT): the certificates and revocation information are frozen in the PDF, so the signature can be validated independently over time;
  • anchoring of the hash on the Bitcoin blockchain (OpenTimestamps), as a public and independent proof of integrity;
  • immutable audit trail based on a chain of linked hashes, verifiable end to end, which records every relevant event of the signature.

4. Security

  • Data transmission protected in transit (TLS) and encryption at rest of identity artefacts (AES-256-GCM);
  • segregation of data by organisation (multi-tenant) and provider credentials stored in encrypted form;
  • anti-fraud checks on identity artefacts (perceptual hashes of the document and selfie).

5. Allocation of responsibilities

DOCUJET (provider of the solution) is responsible for:

  • building and maintaining the solution in compliance with Article 26 eIDAS and Article 57 of the DPCM of 22/2/2013;
  • identifying the signer using the methods described in section 2;
  • keeping the required documentation (section 6) and making the revocation procedure available (section 7).

The signer is responsible for:

  • providing truthful data and a contact point of which they have exclusive use;
  • safeguarding their contact point and the OTP code, and not sharing them with third parties;
  • checking the content of the document before signing it.

6. Retention

The signed document is retained and, if the service is enabled, placed in compliant long-term preservation (conservazione a norma under Italian law) with an accredited preservation provider, to guarantee that it remains unaltered and legible over time.

7. Withdrawal of consent to the use of the solution

The signer may at any time withdraw their consent to the use of the AES solution by writing to [email protected]. Withdrawal does not affect the validity of signatures already applied, whose documentation remains stored to meet legal obligations.

8. Legal references

  • Regulation (EU) 910/2014 (eIDAS), in particular Articles 25, 26, 35, 41 and 42;
  • Italian Legislative Decree 82/2005 (CAD), in particular Article 20;
  • Italian Prime Ministerial Decree (DPCM) of 22 February 2013 ("Technical rules on electronic signatures"), Articles 55-57.

9. Contact

For information on the AES solution or to withdraw your consent: [email protected]. For requests about the processing of personal data, please see the Privacy notice.