...
mindit.io logo

helping enterprises become AI-native organizations

Modernizing a Qualified Electronic Signature Platform

About the client

Swisscom Trust Services is one of Europe’s leading qualified trust service providers, operating regulated signing infrastructure under eIDAS and ZertES. Its on-demand QES platform spans several cooperating services, from the signing gateway and hardware security modules through orchestration, timestamping, authentication, and provisioning. Because signatures carry legal weight, every component is security-critical: signing keys must stay under the sole control of the signer, certificates must be qualified, and every step must leave a tamper-evident audit trail.

/Key Results

    A new hardware-backed signing capability delivered: mindit.io helped establish a robust signing service with live certificate issuance validated in a realistic pre-production setup.

    Improved platform performance and scalability: architecture and workload handling were optimized to support more efficient signing ceremonies under load without exposing internal benchmarks.

    Timestamping tier prepared for higher demand: configuration, connection handling, and load behavior were strengthened to improve reliability at scale.

    Greater resilience under concurrency: load balancing, admission control, and parallel processing patterns were introduced to reduce operational risk and stabilize behavior during peak usage.

    Security hardened end-to-end: mutual TLS trust-store configuration, response validation aligned with OWASP and zero-trust principles, and a documented security-remediation program strengthened the overall platform posture.

    A repeatable end-to-end test and observability practice established: automated regression practices and log-driven analysis improved confidence in releases and made platform behavior more transparent for engineering teams.

/The Challenge

Swisscom Trust Services is one of Europe’s leading qualified trust service providers, operating regulated signing infrastructure under eIDAS and ZertES. Its on-demand QES platform spans several cooperating services, from the signing gateway and hardware security modules through orchestration, timestamping, authentication, and provisioning. Because signatures carry legal weight, every component is security-critical: signing keys must stay under the sole control of the signer, certificates must be qualified, and every step must leave a tamper-evident audit trail.

/Project Goals

    Deliver a new hardware-backed signing service that works reliably with the orchestrator and supports remote signing end to end.

    Increase signing and timestamping throughput and make the platform resilient under concurrency.

    Harden the security posture end-to-end: mutual TLS, response validation, remediation of identified findings.

    Enforce sole control, single-use authorization, strict signed-attribute binding, and correct signature jurisdiction.

    Make the platform observable and continuously testable: an audit trail, log-driven performance analysis, and an automated end-to-end regression suite.

/mindit.io’s Solution

mindit.io worked as an embedded engineering partner across the platform, organized into complementary workstreams:

A greenfield signing service. A new hardware-backed service was built from the ground up with a clear architecture and practical automated checks. Each major capability was planned and reviewed before implementation, helping the signing service work reliably with the orchestrator and support remote signing end to end.

Live certificate issuance, not stubs. The certificate-issuance path was hardened against the certificate authority: message authentication, transaction/nonce echo checks, bounded reads, and key-identity matching on the issued certificate.

Performance and resilience engineering. Signing was parallelized to improve platform responsiveness; the gateway gained multi-instance load balancing, admission control, and parallel timestamping; and the timestamping tier was strengthened for higher demand. Failure modes surfaced under load, including connection resets, hardware-partition loss on restart, and revoked-certificate handling, were diagnosed from logs and fixed.

Security hardening. Mutual TLS trust stores were configured across services, response validation was designed against OWASP and zero-trust principles, and identified findings were driven to closure through a documented remediation program.

Compliance at the hardware and jurisdiction boundary. The least-documented behavior — sole-control signing policies, signature padding, and timestamp jurisdiction — was validated directly against the hardware, and the findings captured as durable knowledge for the team.

An end-to-end test and observability practice. Automated regression runs, a repeatable local stack, and log-driven analysis strengthened release confidence and turned platform behavior into actionable performance improvements.

/Results

● A production-shaped new service, fast. Live certificate issuance, a sole-control key lifecycle, and a full audit and error contract, delivered as a coherent, test-covered codebase.
● Performance headroom. Parallel signing shortened concurrent signing ceremonies and the timestamping tier was strengthened for higher demand, giving the platform room to scale without a hardware-side redesign.
● Resilience where it was fragile. Connection resets, capacity limits, and hardware-session loss on restart were eliminated or contained through load balancing, admission control, and targeted fixes.
● A stronger, evidenced security posture. Mutual TLS, response validation, and a closed-out remediation program moved security from ad hoc to documented and defensible.
● Compliance you can audit. Correct sole control, qualified certificates, timestamp jurisdiction, and a tamper-evident audit trail, validated against real hardware and a growing end-to-end suite.
● Change with confidence. An automated regression and observability practice replaced manual spot-checks, so the team could move quickly without risking legally binding output.

/Customer Testimonial

“The signing platform is the part of our business with the least room for error: sole control, qualified certificates, and a hardware boundary that doesn’t forgive mistakes. mindit.io strengthened it end to end: a clean new signing service, real performance headroom under load, and a security and testing practice we can stand behind. The pace never came at the cost of rigor.”

– Peter Amrhyn, CEO @ Swisscom Trust Services AG

/Strategic Takeaways

● Rigor and speed are not a trade-off. Plan-first delivery, enforced architecture, and pinned contracts kept quality high while moving quickly across many services.
● Guardrails-as-code and automated end-to-end tests outlast any single phase. Quality becomes a property of the build and the pipeline, not of who is on the team this week.
● The hard problems live at the hardware, jurisdiction, and load boundaries. The highest-value work was hardware behavior, compliance contracts, and behavior under concurrency, exactly where careful, verified iteration pays off.
● Legacy platforms can be modernized in place. Security, performance, and resilience were improved without a disruptive rewrite of the whole platform.

/What’s Next?

The platform is ready for its next hardening stage: widening the supported signature schemes, aligning certificate key strength with the current regulatory standard, closing the remaining hardware-attestation gap, and growing end-to-end test coverage. The same delivery model — plan first, verify against real hardware, test continuously — is directly reusable across mindit.io’s regulated-systems work.
Interested in modernizing regulated, security-critical systems without trading away rigor?

Talk to our expert

Executive Summary

Swisscom Trust Services set out to modernize its on-demand Qualified Electronic Signature (QES) platform — the regulated infrastructure that lets users apply legally binding signatures after a mobile authentication step. mindit.io worked across the whole platform, from the signing gateway and a new hardware-backed signing service to the orchestrator, timestamping, authentication front-end, and provisioning layer. In a single delivery phase, the team hardened security, improved signing performance under load, delivered a new signing service from scratch, and established an automated end-to-end test and observability practice, all while keeping the platform compliant with eIDAS (EU) and ZertES (Switzerland).

/ turn your vision into reality

The best way to start a long-term collaboration is with a Pilot project. Let’s talk.

Seraphinite AcceleratorOptimized by Seraphinite Accelerator
Turns on site high speed to be attractive for people and search engines.