Join over 20.000 users. Try it free for 10 days

Signature Validation and Preservation Policy

How it works and what guarantees we offer · wiwink

Version 1.0 · In force since 27 May 2026

When you sign a document with wiwink, the result is not just a signature image: it is a file with full legal validity, verifiable at any time and before any court. This page explains exactly what cryptographic and legal guarantees your signature has and how we preserve it.

1. What does validating a signature mean?

Validating an electronic signature means checking that:

  • The document has not been modified since it was signed (integrity).
  • The signature was made by the person who claims to have signed it (authenticity).
  • The signature was valid at the time it was made, even if the certificate used has since expired (long-term validity).

wiwink carries out this validation automatically, and the recipient of the document can do so too using any PDF reader compatible with the European PAdES standard, such as Adobe Acrobat Reader.

2. Technical standards we comply with

Standard Description
PAdES B-LT Signature level for PDF documents. Includes the seal certificate, the timestamp and the full chain of trust.
XAdES Signature level for XML documents. Same guarantees as PAdES in data exchange environments.
ETSI TS 103172 v2.2.2 European technical specification for PAdES signatures.
ETSI TS 103171 v2.1.1 European technical specification for XAdES signatures.
ETSI TS 119-511 Standard for long-term signature preservation.
RFC 3161 Time Stamp Protocol.

3. The timestamp (TSA): what it is and why it matters

An electronic signature without a timestamp has a problem: it does not prove the exact moment it was signed. This matters because digital certificates expire, and someone could argue that the signature was made after expiry.

The timestamp solves this once and for all. Here is how it works:

  • At the exact moment of signing, wiwink asks the Time Stamping Authority (TSA) service of the Spanish Royal Mint (FNMT-RCM) to certify that date and time.
  • FNMT-RCM is a qualified trust service provider, recognised in the European Trusted List (TSL).
  • Its clock is synchronised with the Royal Institute and Observatory of the Navy (ROA), Spain's national time standard, with an accuracy of ±50 milliseconds.
  • The timestamp is permanently embedded in the document: nobody can remove or alter it without invalidating the whole signature.
Result: even if the certificate we use expires in 2027, any document signed today with wiwink will remain valid and verifiable in 2035 or in 2050.

4. LTV: long-term validity

LTV (Long Term Validation) is the feature that keeps a signature valid even decades after the certificate used has expired or the certification authority has ceased operating.

How do we achieve it? At the time of signing, we embed the following inside the signed document itself:

  • The full chain of trusted certificates (from the wiwink seal up to the FNMT-RCM root).
  • The revocation status of each certificate at the time of signing (OCSP/CRL).
  • The qualified timestamp from the FNMT-RCM TSA.

With all of this inside the document, a future verifier does not need to connect to any external service to check its validity. All the evidence is self-contained in the PDF file.

5. How do we preserve your documents?

Secure storage

Signed documents are stored on Amazon Web Services (AWS), in the Europe (Ireland) region, with the following controls:

  • Encryption at rest and in transit at all times.
  • Daily backups with automatic versioning: if a file becomes corrupted, we can recover any previous version.
  • Redundant architecture: data is replicated across multiple availability zones.
  • AWS holds SOC 2, ISO 27001 and ENS High certifications.

How long do we keep the documents?

wiwink keeps signed documents and their audit evidence for as long as the service contract is in force and, after it ends, for the additional period set out in the terms of service or the one required by law.

In any case, the signature evidence (audit logs, cryptographic hash, timestamps) is kept for a minimum of 5 years from the date of signing, to guarantee the evidential value of the document.

Audit evidence

For each signing process, wiwink generates and keeps an audit record that includes:

  • Exact date and time the document was sent, opened and signed (in UTC).
  • IP address from which it was signed.
  • Delivery method used (email, SMS, WhatsApp, in person).
  • Cryptographic hash of the document before and after signing.
  • Signature status (completed, rejected, pending).
When you sign a document with wiwink, the result is not just a signature image: it is a file with full legal validity, verifiable at any time and before any court. This page explains exactly what cryptographic and legal guarantees your signature has and how we preserve it.

6. What happens if I download the document and lose it?

Once downloaded, the signed PDF document is completely self-contained: it holds within itself all the cryptographic evidence needed for its validation. It does not depend on wiwink's servers.

If you need to recover a document you no longer have, you can access it from your wiwink account while the service is active. If the service contract has ended, contact us at [email protected].

7. Independent verification

Any document signed with wiwink can be verified independently, without proprietary software, using:

  • Adobe Acrobat Reader (free): open the PDF and the signature's validity is checked automatically in the signatures panel.
  • VALIDe (official tool of the Spanish Government): https://valide.redsara.es
  • Any PAdES validator compatible with the European ETSI TS 103172 standard.

8. Our organisation seal certificate

wiwink signs all documents with a Qualified Organisation Seal Certificate issued by FNMT-RCM:

Holder WINK INSIGHTS S.L. ELECTRONIC CERTIFICATION
Tax ID (NIF) B87547642
Issuer AC Representación / CERES · FNMT-RCM
Type Qualified Organisation Seal Certificate (eIDAS Annex III)
Valid until 11 September 2027
Standard ETSI EN 319 411-2 · ETSI EN 319 412-3

This certificate appears on the Spanish Trusted List (TSL) and can be verified on VALIDe.

Last updated: 27 May 2026