Skip to main content
NEW Didit KYC Identity Verification is live, verify signers with government ID & biometrics for eIDAS Advanced signatures Learn more

Security

Digital Signatures (PKI)

Cryptographic signatures that Adobe Reader can verify

Upload your organization's X.509 certificate to embed PKI digital signatures — AATL-compatible, tamper-evident and built for Long-Term Validation.

X.509 · AATL · LTV · certificate chain · tamper evidence

Enterprise-grade trust beyond a click-to-sign

PKI signatures embed cryptographic proof into the PDF so any compliant reader can verify identity and integrity independently.

X.509 certificates

Upload a .p12 or .pfx organizational certificate to sign with verified company identity.

AATL compatibility

Use Adobe Approved Trust List CAs so PDFs show Signed and Verified without warnings.

Long-Term Validation

Embed certificate chain and revocation data so signatures stay verifiable for decades.

How PKI signing works in WPsigner

Configure once, then every completed document can carry a cryptographic digital signature.

  1. 1

    Upload certificate

    Add your organization's .p12 or .pfx file in settings. The password is stored securely and never transmitted.

  2. 2

    Parties sign the document

    When all signers complete, WPsigner applies the PKI signature with certificate chain, timestamp and validation data.

  3. 3

    Verify in Adobe Reader

    Open the PDF to see a green checkmark — Signed and all signatures are valid — with no extra software.

  4. 4

    Detect tampering instantly

    Any change after signing triggers an Invalid Signature warning in PDF readers.

Organization identity and eIDAS AdES

Signed PDFs display your company name from the certificate — essential for B2B and regulated industries. Combined with Didit KYC, PKI signing supports eIDAS Advanced Electronic Signature (AdES) requirements.

  • Visual signature block with signer, time and certificate details
  • Full certificate chain embedded for independent verification
  • Organization identity on the PDF, not only the signer name
  • Tamper evidence after signing completes
  • AdES path with KYC identity verification
Explore compliance →

PKI capabilities included

  • X.509 .p12 / .pfx support
  • AATL-compatible verification in Adobe Reader
  • Long-Term Validation (LTV)
  • Visual digital signature indicator
  • Certificate chain verification
  • Organization identity display
  • Post-sign tamper evidence
  • eIDAS Advanced (AdES) with KYC

Built for high-trust documents

B2B contracts

Show organizational identity on every signed agreement.

Regulated industries

Meet stronger evidential standards with PKI plus audit trails.

Long-term archives

Keep signatures verifiable after certificates expire with LTV.

EU advanced signatures

Combine PKI with Didit KYC for AdES-level identity assurance.

Frequently asked questions

What is a PKI digital signature?

A PKI (Public Key Infrastructure) digital signature uses cryptographic certificates issued by a Certificate Authority to verify signer identity and ensure document integrity. Unlike a basic click-to-sign mark, PKI signatures embed cryptographic proof that any PDF reader can verify independently.

Do I need to buy a certificate?

Yes. You need an X.509 digital certificate (.p12 or .pfx) from a Certificate Authority. For Signed and Verified without warnings in Adobe Reader, use an AATL-listed CA such as GlobalSign, DigiCert or Sectigo. Certificates typically cost $200–500/year depending on provider and type.

What is Long-Term Validation (LTV)?

LTV embeds validation data (certificate chain, OCSP responses, CRL data) into the signed PDF. The signature can be verified even 10 or 20 years later if the certificate has expired or the CA no longer exists — critical for long retention requirements.

Is this the same as eIDAS Qualified Electronic Signature?

No. PKI signatures in WPsigner meet eIDAS Advanced Electronic Signature (AdES) level, especially with Didit KYC. Qualified Electronic Signatures (QES) require a QSCD and a certificate from a Qualified Trust Service Provider. AdES is sufficient for the vast majority of business contracts.

Is PKI included in WPsigner plans?

Yes. PKI digital signatures are included in every WPsigner plan. You only need to upload your own certificate.

What happens if someone edits the PDF after signing?

PDF readers show an Invalid Signature warning because the cryptographic hash no longer matches — making tampering immediately detectable.

Enterprise-grade digital signatures

PKI digital signatures are included in every WPsigner plan. Upload your certificate and start verifying in Adobe Reader.

Unlimited Usage · Self-Hosted

Stop paying per envelope

Choose an annual or lifetime license with unlimited documents and no per-envelope fees. Keep control of your data and signing workflows.