GMO GLOBALSIGN LIMITED

Digital Electronic Signatures and eSeal's

GlobalSign's Digital Signing Service (DSS) provides you with compliant, identity-based digital Signatures and Seals for your employees and organisation. GlobalSign does all of the technical/compliance parts in our eIDAS-accredited infrastructure for your Digital Signatures and Seals. Use our REST API for signing workflow integration to easily implement Signatures and Seals.

Features

  • Build trusted Digital eSignatures into your existing document management services/workflows
  • Supports individual/department level identities for advanced eSignatures or eSeals
  • Easily add eSignatures to proprietary or well-known document signing services
  • Integrate our RestAPI, SDK or choose pre-installed zero-integration methods
  • Delivered from GlobalSign’s ETSI best-in-class audited robust infrastructure
  • GDPR compliant Global Data Centers (primary in London)
  • Includes choice of inclusive Trusted or Qualified Time Stamping
  • Includes all crypto components - you only need the API
  • Signatures & Seals comply with UK/EU elDAS regulations

Benefits

  • Meets all of your Digital Signature and seal compliance requirements
  • PKI-based eSignatures ensures highest standards of security, identity and integrity
  • Suitable for Directives related to VAT/eInvoicing/eArchiving etc.
  • Supports multiple Digital Signature identity profiles within the Organisation
  • Adopting Digital Signatures to shorten project timelines and save costs
  • Flexible and scalable options for eSignature/eSeal volume licensing and throughput
  • Highly-scalable backend environment - no additional configuration or integration needed
  • No integration required when using with DocuSign, Adobe Sign etc.
  • Globalsign is part of the Adobe approved trust list
  • Remote signing solution which requires no hardware or PKI expertise

Pricing

£713 a licence a year

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at mike.boyle@globalsign.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

9 6 1 9 8 8 1 3 1 5 3 0 8 7 4

Contact

GMO GLOBALSIGN LIMITED Mike Boyle
Telephone: 01622 766714
Email: mike.boyle@globalsign.com

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
DSS is an API service - provides the option to:
-Integrate into your own services
-Use readily integrated into GlobalSign's GMOSign eSignature service
-Help integrating DSS with your non-proprietary services
-Use readily integrated into DocuSign and Adobe Sign

Please contact GlobalSign for more details.
Cloud deployment model
  • Private cloud
  • Hybrid cloud
Service constraints
DSS is an API driven trusted eSignature service. It is however available via readily-integrated services.
System requirements
  • REST API when self integrated
  • Requires a form of digital signature signing workflow

User support

Email or online ticketing support
Email or online ticketing
Support response times
Please see our Standard Support SLA for more details.
Standard Support is provided Mon - Fri.
Out of hours and weekend support available at an additional cost via our Premium Support packages. Search' GlobalSign Premium Support in G-Cloud or contact GlobalSign for more details.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Web chat
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Via our main website www.globalsign.com or support website support.globalsign.com
Support Chat is available Mon-Fri 9-5pm for standard support users. Or Mon-Fri 24hrs for Gold or Platinum Premium Support customers.
Please see our Premium Support options or contact us for more options.
Web chat accessibility testing
All testing of our website and its available features are rigorously tested in accordance with international security standards and regularly tested.
Onsite support
No
Support levels
Please search G-Cloud for GlobalSign Premium Support Services or contact us for more details.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide an API guide and dedicated sales engineering support when implementing via API. For ready integrations we provide a simple to follow step process.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
This is not applicable, no information/documentation is shared, stored or process for this service.
End-of-contract process
N/A

Using the service

Web browser interface
No
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Identities, access credentials and services are managed through an online portal.
Accessibility standards
None or don’t know
Description of accessibility
Via a browser.
Accessibility testing
All testing of our website and its available features are rigorously tested in accordance with international security standards and regularly tested.
API
Yes
What users can and can't do using the API
API is a RESTful API
The service is bound and regulated to compliance standards for identities , e.g. eIDAS, AATL and other international regulations. Information provided will be subject to identity validation process.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
No

Scaling

Independence of resources
GlobalSign's Atlas CA infrastructure service that underpins this DSS service is robust and scalable for ultra high volume usage. All customer accounts are rate limited with the ability for customers to increase their rate limits where required. Please see DSS for Higher Throughput in the service pricing information.

Analytics

Service usage metrics
Yes
Metrics types
Reporting metrics such as usage are available via the online service portal.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • Other locations
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with CSA CCM v3.0
  • Physical access control, complying with SSAE-16 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Data sanitisation type
  • Explicit overwriting of storage before reallocation
  • Deleted data can’t be directly accessed
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
N/A
Data export formats
Other
Other data export formats
N/A
Data import formats
Other
Other data import formats
N/A

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Mutual TLS
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Mutual TLS
The infrastructure includes identity data stored on hardware security modules within our WebTrust, ETSI and Qualified Trust Service Provider accredited environment.

Availability and resilience

Guaranteed availability
99.95%
Please see GlobalSign's SLA for more details.
Approach to resilience
Available on request.
Outage reporting
Via a public dashboard and email and social media notifications.

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
In access management only authorised administrators have access to service accounts. Administrators undergo an identity verification process during the onboarding to the service.
Access to support channels is available to service administrators and named known contacts only.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
21 October 2019
What the ISO/IEC 27001 doesn’t cover
Services other than the ones provided from the certificate authority and TrustLogin function of GMO GlobalSign. Please note that GMO Sign and IoT services are out of the scope.
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
SecureTrust
PCI DSS accreditation date
24 September 2021
What the PCI DSS doesn’t cover
Services other than certificate ordering and processing.
Cyber essentials
No
Cyber essentials plus
No
Other security certifications
Yes
Any other security certifications
  • 2021-Globalsign-WebTrust-CA-Independent-Assurance-Report
  • 2021-Globalsign-WebTrust-SSL-Independent-Assurance-Report
  • 2021-Globalsign-WebTrust-EV-SSL-Independent-Assurance-Report
  • 2021-Globalsign-WebTrust-EV-CS-Independent-Assurance-Report
  • 2021-Globalsign-WebTrust-CS-Independent-Assurance-Report
  • GlobalSign_KK_BCMS
  • EYCP_GlobalSign_eIDAS_certificate_2021

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
WebTrust, ETSI and ISO Accreditations.
Information security policies and processes
GlobalSign provides and is bound to our certificate policy and certificate practice statement which underpins our services. GlobalSign is audited against its compliance and adherence to these policies.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
GlobalSign provides its services in accordance to international, regional and local legislation and industry regulation. We are audited against these standards.
Vulnerability management type
Undisclosed
Vulnerability management approach
GlobalSign provides its services in accordance to international, regional and local legislation and industry regulation. We are audited against these standards.
Protective monitoring type
Undisclosed
Protective monitoring approach
GlobalSign provides its services in accordance to international, regional and local legislation and industry regulation. We are audited against these standards.
Incident management type
Undisclosed
Incident management approach
GlobalSign provides its services in accordance to international, regional and local legislation and industry regulation. We are audited against these standards.

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Public sector networks

Connection to public sector networks
No

Social Value

Fighting climate change

Fighting climate change

Please contact us for details or visit www.globalsign.com
Covid-19 recovery

Covid-19 recovery

Please contact us for details or visit www.globalsign.com
Tackling economic inequality

Tackling economic inequality

Please contact us for details or visit www.globalsign.com
Equal opportunity

Equal opportunity

Please contact us for details or visit www.globalsign.com
Wellbeing

Wellbeing

Please contact us for details or visit www.globalsign.com

Pricing

Price
£713 a licence a year
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Test service is a replication of our production service but digital signatures or eSeals will not be trusted.

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at mike.boyle@globalsign.com. Tell them what format you need. It will help if you say what assistive technology you use.