Aloaha Web Wallet · European Digital Identity Wallet ready
Cloud Signature Consortium v2Sign a PDF in your browser.
Drop a PDF below. Your signing certificate is minted per user on our server; the raw PDF stays on your device. The preview is rendered client-side by PDF.js — no browser plugin, no third-party PDF viewer. Only the SHA-256 hash of the document's signed byte-range and the resulting signature bytes are exchanged with our Cloud Signature Consortium (CSC) API v2 endpoint. This is the same architecture the European Digital Identity Wallet ecosystem uses for remote signature, minus the QSCD binding required for a Qualified Electronic Signature (QES).
This signature is currently produced by a software-backed cryptographic module (per-user ECDsa P-256 signing certificate keyed on the OIDC subject, private key wrapped with DPAPI at LocalMachine scope). The signer sees only their own credential; user A never sees user B's cert. The Aloaha remote-signing service is designed to accept an HSM substitution as a future upgrade path via the
Csc:CryptoModuleProvider configuration key; the CSC v2 API surface and audit trail remain unchanged. Today the shipped provider is software; the hsm-azurekv and hsm-pkcs11 values are reserved for future connectors and currently return crypto_module_not_configured.
1. Pick your PDF
Drop a PDF here
— or —
No file chosen.
2. Your signing certificate
3. Sign
Waiting for a PDF.
CSC v2 subset live at /csc/v2/… · PAdES assembly in your browser ·
Cookbooks ·
What the Web Wallet is ·
Sign in with EU Wallet ·
Privacy