EviSign HSM PGP Technology for OpenPGP Electronic Signatures
EviSign HSM PGP is Freemindtronic’s OpenPGP electronic signature technology for file signing and signature verification inside the DataShielder HSM PGP browser extension. It helps users sign files, verify signatures, protect digital evidence and strengthen secure email or document workflows.
Unlike EviSign NFC HSM, this technology uses OpenPGP workflows. Therefore, this page focuses only on the browser-based HSM PGP signing layer, OpenPGP signatures, verification evidence and the way this technology can support electronic signature workflows under eIDAS.
Useful Links for OpenPGP Electronic Signatures
Learn more about DataShielder HSM PGP Data Encryption, the OpenPGP standard, RFC 9580 OpenPGP and eIDAS Article 26.
EviSign HSM PGP Navigation
EviSign HSM PGP Technology Scope
OpenPGP Electronic Signature Layer
EviSign HSM PGP signs files and verifies signatures through OpenPGP workflows. It works inside the DataShielder HSM PGP browser extension, which focuses on signing, verification, encryption and decryption directly from the web browser.
Browser-Based Evidence
The technology helps users create verifiable electronic evidence for files and messages. First, the signer creates a signature with a private key. Then, the recipient verifies the signature with the corresponding public key. As a result, the recipient can check whether the signed data changed after signature.
The DataShielder HSM PGP extension supports browser-based security workflows. In particular, it helps users:
- sign files;
- verify signatures;
- encrypt and decrypt emails or file content;
- work with OpenPGP-based messages;
- connect browser workflows with the wider Freemindtronic DataShielder ecosystem.
Moreover, the extension targets major browser environments such as Chromium-based browsers and Firefox, according to the deployed version and product configuration.
Two Separate Technologies
EviSign HSM PGP and EviSign NFC HSM must remain separate. The HSM PGP technology uses OpenPGP workflows inside the DataShielder browser extension. By contrast, EviSign NFC HSM uses its own NFC HSM electronic signature architecture and does not use PGP or OpenPGP.
No Product Confusion
Therefore, this page does not describe EviSign NFC HSM. It focuses only on OpenPGP signatures, file verification, secure browser workflows and the role these mechanisms can play in electronic signature evidence.
OpenPGP File Signing and Verification
Signature Creation
OpenPGP signing links a file or message to a private signing key. Therefore, the signature gives the recipient a way to check whether the content still matches the data that the signer approved.
Signature Verification
Verification uses the corresponding public key. If the signed file changes after signature, the verification fails. Consequently, the workflow helps detect tampering, accidental modification or substitution of signed content.
EviSign HSM PGP can provide technical evidence of:
- the signed data covered by the signature;
- the public key used for verification;
- the fact that the signed data has not changed since signature;
- the relationship between the signature and the file or message.
However, this evidence does not automatically prove a civil identity by itself. Therefore, organisations should also define identity proofing, key ownership, audit trails and retention rules.
From Basic Approval to Verifiable Signature
Yes. A simple electronic signature may rely on a click, typed name or email confirmation. However, EviSign HSM PGP can add OpenPGP cryptographic evidence to that approval workflow.
Better Integrity Evidence
As a result, the recipient can verify whether the signed file or message changed later. This does not automatically create a qualified electronic signature. Nevertheless, it strengthens the technical evidence of origin, consent and integrity.
Advanced Electronic Signature Workflows
An advanced electronic signature must meet the requirements of eIDAS Article 26. It must:
- link uniquely to the signatory;
- identify the signatory;
- use signature creation data that the signatory can use under their sole control;
- link to the signed data so that any later change becomes detectable.
Therefore, advanced electronic signature compliance depends on both technology and the surrounding evidence process.
Technology Contribution
EviSign HSM PGP can support Article 26 workflows when the deployment links the OpenPGP key to the signatory, verifies the signatory’s identity and keeps the signing key under the signatory’s control.
Process Contribution
In addition, the organisation must define how it issues or validates keys, how it identifies signatories and how it stores evidence. Consequently, the technology can support an advanced electronic signature workflow, but the legal strength also depends on the operational process.
EviSign HSM PGP gives users several benefits:
- OpenPGP signing: users can create verifiable signatures for files and messages.
- Signature verification: recipients can check whether the signature matches the signed data.
- Browser workflow: users can sign, verify, encrypt and decrypt from the DataShielder HSM PGP extension.
- Data integrity: verification detects later changes to signed content.
- Freemindtronic ecosystem: the technology belongs to the wider DataShielder security environment.
Moreover, these benefits help teams protect sensitive exchanges without reducing approval to a simple visual mark.
eIDAS, Advanced Signature and Qualified Signature
EviSign HSM PGP does not claim to generate a qualified electronic signature under eIDAS. It does not claim QTSP status, QSCD status or a qualified certificate for electronic signatures. Therefore, users should not present this OpenPGP signature workflow as a qualified electronic signature unless a separate qualified trust-service framework provides and proves those requirements.
Advanced Signature
An advanced electronic signature follows the requirements of eIDAS Article 26. It focuses on unique linkage to the signatory, signatory identification, control of signature creation data and detection of later data changes.
Qualified Signature
A qualified electronic signature requires additional elements, including a qualified certificate, a qualified trust service provider and a qualified signature creation device. As a result, this page describes a technology that can support advanced electronic signature workflows, not a qualified electronic signature service.
You can read the official EUR-Lex text here:
https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:02014R0910-20240520#tocId66
Evolving Technology and Product Roadmap
EviSign HSM PGP is not a frozen technology. It evolves with the DataShielder HSM PGP extension, browser requirements, OpenPGP standards, Freemindtronic security features and customer use cases.
Therefore, this page describes the technology scope and positioning at product level. Future versions may improve signing workflows, verification evidence, user experience, supported environments or post-quantum security positioning.
Security Evolves
Cryptographic software must evolve because threats, browser APIs and standards evolve. Therefore, the technology should remain adaptable while keeping clear product boundaries.
Claims Must Stay Accurate
However, an evolving roadmap does not justify overclaiming. The page should describe current capabilities factually, distinguish OpenPGP from NFC HSM signatures and avoid qualified eIDAS claims unless a qualified trust-service framework proves them.
Before deploying the technology, users should verify:
- which browser extension version they use;
- which OpenPGP workflows they enable;
- how they identify signatories;
- how they protect private keys;
- how they retain signed files, signatures and verification evidence;
- whether their use case requires simple, advanced or qualified electronic signature status.
As a result, organisations can align the technical workflow with their legal, operational and risk requirements.
Post-Quantum, PQC and OpenPGP Wording
Use “post-quantum” as the main wording for SEO and clarity. You can introduce the acronym once as “post-quantum cryptography (PQC)”, then continue with “post-quantum”. In French contexts, “post quantique” also helps readers who do not search with the acronym PQC.
No. OpenPGP and post-quantum cryptography are different concepts. OpenPGP defines message, key and signature formats. Post-quantum cryptography refers to cryptographic mechanisms designed to resist future quantum-computing threats.
Therefore, this page should describe EviSign HSM PGP as OpenPGP-based. It can mention Freemindtronic’s broader post-quantum security positioning, but it should not claim that every OpenPGP workflow is automatically post-quantum.
You can read the OpenPGP standard information here:
https://www.openpgp.org/about/standard/
You can also read RFC 9580 here:
“`
