Skip to main content

We have a tailored site for international audiences

Om oss

Certifications and Compliance

To meet the very latest security and data protection requirements, all of our services are subject to strict rules and regularly checked by independent specialists.

ISO27001 logo

Signicat is ISO/IEC27001 certified.

# EN ISO 27001:2013

This international standard is designed to set requirements for the establishment, implementation, maintenance and continuous improvement of an information security management system.

An ISO / IEC 27001 certificate shows that the information security management system has been measured against a standard of best practice in the branch and found to be in compliance. Certification of an independent certification body shows that the necessary measures have been taken to protect sensitive information from unauthorized access and changes.

# Protect your values

The standard has a holistic approach to information security. Values that need protection can include everything from digital information, paper documentation and physical assets (computers and networks) to the knowledge of individual employees. Conditions you must consider include, among other things, the staff's skills development and technical protection against hacking.

ISO / IEC 27001 helps us protect information as follows:

  • Confidentiality ensures that information is only available to authorized parties
  • Integrity ensures that the information handling methods are accurate and complete
  • Accessibility ensures that authorized users have access to information and associated assets when needed

Signicat is ISO/IEC 27001 certified, certificate is available here.

# eIDAS (Electronic Identification and Trust Services)

Signicat is a Qualified Trust Service Provider issuing qualified time-stamps, certificate is available here.

The Signicat Time-Stamp policy and Practice statement is listed at the end of this page.

By being a Qualified Trust Service Provider, Signicat is listed on the EU trust list.

# AICPA SOC 2 (American Institute of Certified Public Accountants; Service Organization Control)

Signicat delivers a SOC 2 (type 1 for 2018) (type 2 for 2019) attestation report to its customer. The SOC 2 report addresses a service organization’s controls that relate to operations and compliance, as outlined by the AICPA’s Trust Services criteria in relation to availability, security, processing integrity, confidentiality and privacy. This report is intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to security, availability, and processing integrity of the systems the service organization uses to process users’ data and the confidentiality and privacy of the information processed by these systems.

# FTN (Finnish Trust Network)

Signicat is an approved identity broker for Finnish businesses, providing access to the Finnish Trust Network, by The Finnish Transport and Communications Agency (Traficom).
Signicat offers strong electronic identification services for the public. The principles for strong identification have been established in Finnish legislation: Laki vahvasta sähköisestä tunnistamisesta ja sähköisistä luottamuspalveluista 533/2016, section 2.2§: http://www.finlex.fi/fi/laki/ajantasa/2009/20090617.

# IDIN

Signicat is an approved broker of IDIN in Netherlands.

# GDPR as Data Processor on instruction by Data Controller (Signicat's Customer)

An audit report is provided to Signicat's customers of compliance to Signicat's Data Processor Agreement (DPA).

# Qualified Trust Service Provider Document Repository

# eIDAS QTSP Terms and Conditions

# eIDAS QTSP Policy and Practice Statement


QTSP logo

Signicat is a Qualified Trust Service Provider (QTSP)

# eIDAS (Electronic Identification and Trust Services)

Signicat is a Qualified Trust Service Provider issuing qualified time-stamps, certificate is available here.

The Signicat Time-Stamp policy and Practice statement is listed at the end of this page.

By being a Qualified Trust Service Provider, Signicat is listed on the EU trust list.

# OpenID Certified

Signicat is a certified OpenID Connect provider and has achieved OpenID Certification from the OpenID Foundation. OpenID Certification demonstrates that our implementation of OpenID Connect, a standard for user authentication and authorisation, meets the highest levels of security, interoperability, and usability.

Learn more

Signicat is eHerkenning certified.

# eHerkenning certified

The Ministry of Economic Affairs has certified us as an official eHerkenning broker. Other suppliers also recognise the power of our software, which means that our systems handle the majority of all login transactions.