The TrustedX download area contains documentation, videos and the posibility to request a 30 days TrustedX trial download. The contents of that area is subject to previous registration.
TrustedX e-Signature Platform
More information:
Product Sheet
Web services platform for managing digital signature processes:
- Client-side or server-side signatures
- Batch signatures and verification
- Trust management for CAs, both public and corporate
- Optional signature archiving service that guarantees non-repudiation over time
- Signature mechanisms are isolated from the applications to provide the centralized management
- Extendable and centralized logging that can be easily integrated with SIEM tools
- Common Criteria EAL4+ certified to assure maximum security
- Electronic signature on server
TrustedX acts as a centralized repository of keys and digital certificates so that corporate users and/or applications can use them remotely without having to store them locally. This approach provides greater control over the use of keys in an audited manner and simplifies deploying, maintaining and using the PKI through centralized management. The authentication and access control offers a range of mechanisms and trust levels, and the system can be easily integrated with other repositories for managing digital identities. - Semantic interpretation of electronic signatures
TrustedX is the most complete digital signature platform of its kind. Multiple CAs can be managed, all electronic signature formats are supported and all complexity related to managing trust is removed from the applications. The incorporated semantic services support obtaining all signer/signature data along with a trust level indicated using discrete values (4 levels) and labels (i.e., Government, Corporate, Finance, etc.). - Cost saving and flexible integration
The product can be quickly deployed thanks to its standardization and multiple integration options. It can be used (i) from user applications through plug-ins, (ii) as a Web service and (iii) by means of watch folders. The product incorporates an integration gateway that uses pipelines for the straightforward integration of data and common-task processing. - Centralized management, auditing and non-repudiation
TrustedX provides the centralized management of all digital signature policies, the preservation of electronic signatures, and logging and auditing. This allows the corporate control of the use of the cryptography, the effective management of recognized CAs/VAs and the transparent maintaining of electronic signatures when required owing to the expiration of certificates and the renewal of cryptographic material.
TrustedX incorporates functions that provide a set of security and trust mechanisms as services. These services can be used in different formats as they support different integration strategies:
- Java or .NET APIs: Allows easily integrating electronic signature services in native Java applications and .NET (**).
- SOAP/WS: Using the OASIS DSS standard as an access protocol for Web services.
- REST/WS, SOAP/WS: Using TrustedX's integration gateway, which supports configuring traffic and data processing with an XML pipeline language.
The platform includes a Java Applet for signature integration scenarios with user cards in Web environments.
Platform functions are grouped into the following services:
- Authentication and authorization. Manages the authentication policies and access control to platform resources/services. Password and digital-certificate based internal authentication mechanisms are supported, as are third-party authentication services based on RADIUS (TMS), SAML and LDAP/AD.
- Object and entity management. Manages platform entities and objects. External repositories, such as user LDAP/AD, databases, files and HSMs, can be added for protecting private keys.
- Auditing and accounting. Uniformly and securely centralizes e-signature log data. The log system supports incorporating specific entries, which facilitates management with third-party tools.
- Electronic signature generation and verification. Generates and verifies electronic signatures in most standard e-document formats, including email and Web messaging. Supported formats include multiple electronic signatures, signatures with time-stamps and long-term electronic signatures.
- Non-repudiation. Allows extending an electronic signature's validity over time by preserving its cryptographic reliability and incorporating the certification chain, information on digital certificate status at the time of signing and a time-stamp.
The following services can also be added:
- Virtual SmartCard. Key and certificate centralized manager that is coordinated with user desktop Microsoft CAPI and PKCS #11 Plug-ins .
- Watched Folders. Folder Manager that allows several processes to apply disadvantaged signature on file. Suitable for batch signatures.
- Signature Workflows. Oriented to the integration of the signature in the document management system, for the implementation of the signature workflows. Support for Alfresco Share and Microsoft SharePoint.
- Electronic Signature Custody. Preserves the non-repudiability of the electronic signatures, by transparently interacting with the non-repudiation service and managing signature and e-document metadata.
(**) Please, check for availavility.
The following figure illustrates the possible TrustedX architectures. The TrustedX functions can be used as a (i) trusted Web service, (ii) a trusted gateway between applications (iii) or a combination of (i) and (ii) (not shown in the figure).

(*) TrustedX 3.0 with a CC-EAL4+ (ALC_FLR.2) http://www.oc.ccn.cni.es/certificacion_en.html guarantee level in compliance with the USA Government "US Government Family of Protection Profiles. Public Key-Enabled Applications For Basic Robustness Environments", USMC (United States Marine Corps).
