Skribble
Zusammenfassung aus Eigentümerschaft und CLOUD-Act-Risiko.
-
EU-souverän In EU-/EWR-/Schweizer Eigentum und betrieben, ohne erkennbares CLOUD-Act-Risiko.
-
EU-ansässig Dieser Eintrag EU-betrieben, mit höchstens geringfügigem oder vorübergehendem US-Bezug.
-
EU-gehostet EU-Hosting verfügbar, aber ein US-Mutterkonzern oder Hyperscaler-Unterauftragsverarbeiter erzeugt ein materielles Risiko.
-
US-verbunden Von einem US-Unternehmen betrieben, direkt der US-Jurisdiktion unterworfen.
Zurich-based Swiss e-signature platform with dual ZertES + eIDAS QES via Swisscom partnership; ISO 27001, 4,000+ DACH customers.
Skribble ist ein europäischer Dienst mit Hosting in der Schweiz und höchstens geringfügigem, vorübergehendem US-Bezug nach dem CLOUD Act. Gelistet unter E-Signatur.
Bewertungsnotizen
Skribble is a Zurich-based Swiss e-signature platform that uniquely covers both ZertES (the Swiss Federal Act on Electronic Signatures) AND eIDAS (the EU regulation) for Qualified Electronic Signatures. Skribble is not itself a Qualified Trust Service Provider: it brokers QES, and the eIDAS-qualified certificates, timestamps and remote QSCD management are issued by Swisscom IT Services Finance S.E., which is the entity actually carrying the qualified status on the Austrian trusted list (verified against that list at the 2026-08 re-verify; Skribble itself appears on no EU trusted list). ISO 9001 + ISO 27001 certified, GDPR + DSGVO compliant, serving 4,000+ companies in DACH (Germany / Austria / Switzerland). Signed documents stay on Swiss infrastructure (cloudscale.ch and VSHN, with IONOS in Germany for German customers), and Switzerland's adequacy decision keeps EU-CH transfers SCC-free, so there is no US-owned provider in the at-rest path. The score moved 5 to 3 at the 2026-08 re-verify because the published DPA names five US-incorporated sub-processors around that core: Cloudflare (network security and authentication, so plain-HTTP traffic passes through a US-owned network), plus SparkPost (email), Chargebee (billing), Userpilot (in-app messaging) and Clay Labs (data enrichment), with HubSpot, Stripe and Google Mail contracted through Irish entities of US parents. The rubric caps a listing at 3/5 once three or more US sub-processors are in the chain. The dual-bar ZertES + eIDAS coverage remains the directory's strongest cross-jurisdiction QES capability for buyers operating across CH and EU, and the at-rest picture is still cleaner than the AWS-hosted Namirial-group options.
Befund
- CLOUD Act
- CLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
-
Keines EU-Betreiber, kein US-Mutterkonzern, keine relevanten US-Unterauftragsverarbeiter.
-
Gering Dieser Eintrag Ein vorübergehender US-Unterauftragsverarbeiter (CDN, Karten); ruhende Daten bleiben in der EU.
-
Erheblich US-Mutterkonzern oder ein zentraler Unterauftragsverarbeiter ist ein US-Hyperscaler.
-
Direkt Der Betreiber selbst ist US-ansässig.
-
- Eigentümer
- Eigentümerschaft
Wo die letztliche Kontrolle über das Betreiberunternehmen liegt.
-
EU-Eigentum In der EU ansässig und EU-kontrolliert; keine nennenswerte US-Beteiligung.
-
Europäisch Dieser Eintrag Schweizer/EWR-Eigentum ohne nennenswerte US-Beteiligung, gilt als europäisch.
-
EU-Sitz, US-finanziert EU-Hauptsitz, aber von US-Risikokapital oder -Private-Equity kontrolliert.
-
EU-Tochter, US-Mutter Europäische Betriebsgesellschaft im Eigentum einer US-Muttergesellschaft.
-
US-Eigentum Das Betreiberunternehmen selbst hat seinen Hauptsitz in den USA.
-
- Unterauftragsverarbeiter
- 0 keine offengelegt
Geprüfte Signale
-
EU-/Angemessenheits-Hosting: Ja
-
EU-/Angemessenheits-Betreiber: Ja
-
Keine US-CLOUD-Act-Exposition: Nicht bewertet
-
Öffentlicher AVV: Ja
-
Unterauftragsverarbeiter offengelegt: Ja
-
Open-Source-Clients: Nein
-
Zertifizierung durch Dritte: Ja
Springen zu
Über Skribble
Skribble is a Zurich-headquartered Swiss e-signature platform that distinguishes itself in the QES market by uniquely covering both Swiss ZertES and EU eIDAS qualified-signature regulations under a single platform. Founded around 2018 with focus on the DACH region (Germany, Austria, Switzerland), the company has scaled to 4,000+ corporate customers and built its QES capabilities on a partnership with Swisscom, which issues the underlying qualified certificates under both ZertES (the Swiss Federal Act on Electronic Signatures) and eIDAS (the EU regulation). Skribble is not itself a Qualified Trust Service Provider and appears on no EU trusted list: it brokers those qualifications rather than holding them. Swisscom AG is the ZertES-side Swiss entity, while the eIDAS-qualified certificates, timestamping and remote signature-creation-device management sit with Swisscom IT Services Finance S.E., the entity actually carried on the Austrian trusted list. This dual-bar coverage matters because Switzerland and the EU are separate jurisdictions with no automatic mutual recognition of qualified signatures; a Swiss-only or EU-only QTSP can leave one half of a DACH transaction legally exposed, while Skribble's Swisscom-anchored stack delivers QES that is fully binding under both regimes.
Compliance posture is procurement-grade: ISO 9001 + ISO 27001 certified at the company level, GDPR + DSGVO compliant, Swiss federal legal-validity coverage under ZertES via Swisscom-issued certificates. The platform handles identity verification (video-ident, qualified e-ID, GwG / FATF-aligned KYC for higher signature tiers), signing workflows (Simple, Advanced, Qualified electronic signatures), and audit-trail packaging. Switzerland holds an EU adequacy decision under Art. 45 GDPR so cross-border EU↔CH transfers require no SCCs. Contracting is better than the Swiss address suggests: buyers seated in Germany or in any other country outside Switzerland contract with Skribble Deutschland GmbH (An der Raumfabrik 29, Karlsruhe), so an EU customer's counterparty is an EU-incorporated entity. Signed documents stay on Swiss infrastructure (cloudscale.ch and VSHN, with IONOS in Germany for German customers), but the published DPA names five US-incorporated processors around that core, Cloudflare among them for network security and authentication, which is why CLOUD Act exposure is recorded as Gering rather than none.
Pricing is published per user per month, excluding VAT: a free Starter tier on pay-per-use at €1 per simple electronic signature, Team at 23 € per user per month on annual billing, Pro at €36 on the same basis, and Scale on request. Best fit: DACH companies with material cross-border CH↔EU contracting flows (Swiss banks contracting EU customers, EU insurers signing Swiss policy-holders, Swiss-EU joint ventures, dual-jurisdiction employment contracts), companies in regulated industries needing QES under either ZertES or eIDAS, and any organisation that values having Swisscom-issued qualified certificates as the trust anchor. Procurement-grade EU-only buyers operating purely inside the EU may prefer Youtrust (France, ANSSI-supervised, formerly Yousign and a QTSP in its own right) or the Signaturit / Namirial group (though the latter is US-private-equity-owned since 2025 and hosted at rest on AWS, so cloud_act_exposure: material), but for any DACH workflow Skribble's dual-regime QES is structurally differentiated.
Unterauftragsverarbeiter-Karte · keine offengelegt
Rahmenwerke & Zertifizierungen
Funktionsmatrix
Tabelle 1Funktionen von Skribble
Integration & Zugriff
Compliance & Governance
Preise & Tarife
Öffentliche Dokumente
Alternativen in dieser Kategorie
-
Österreich · 10 $/Mt.US-verbundenCLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
-
Keines EU-Betreiber, kein US-Mutterkonzern, keine relevanten US-Unterauftragsverarbeiter.
-
Gering Ein vorübergehender US-Unterauftragsverarbeiter (CDN, Karten); ruhende Daten bleiben in der EU.
-
Erheblich US-Mutterkonzern oder ein zentraler Unterauftragsverarbeiter ist ein US-Hyperscaler.
-
Direkt Dieser Eintrag Der Betreiber selbst ist US-ansässig.
Öffentl. AVV: Ja Subprozessoren: Ja Open Source: Nein -
-
SpanienEU-gehostetCLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
-
Keines EU-Betreiber, kein US-Mutterkonzern, keine relevanten US-Unterauftragsverarbeiter.
-
Gering Ein vorübergehender US-Unterauftragsverarbeiter (CDN, Karten); ruhende Daten bleiben in der EU.
-
Erheblich Dieser Eintrag US-Mutterkonzern oder ein zentraler Unterauftragsverarbeiter ist ein US-Hyperscaler.
-
Direkt Der Betreiber selbst ist US-ansässig.
Öffentl. AVV: Ja Subprozessoren: Ja Open Source: Nein -
-
NorwegenEU-gehostetCLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
-
Keines EU-Betreiber, kein US-Mutterkonzern, keine relevanten US-Unterauftragsverarbeiter.
-
Gering Ein vorübergehender US-Unterauftragsverarbeiter (CDN, Karten); ruhende Daten bleiben in der EU.
-
Erheblich Dieser Eintrag US-Mutterkonzern oder ein zentraler Unterauftragsverarbeiter ist ein US-Hyperscaler.
-
Direkt Der Betreiber selbst ist US-ansässig.
Öffentl. AVV: Ja Subprozessoren: Ja Open Source: Nein -
| Produkt | Souveränität | CLOUD Act | Signale | Ab |
|---|---|---|---|---|
|
|
US-verbunden | CLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
|
Öffentl. AVV: Ja
Subprozessoren: Ja
Open Source: Nein
|
10 $/Mt. |
|
|
EU-gehostet | CLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
|
Öffentl. AVV: Ja
Subprozessoren: Ja
Open Source: Nein
|
— |
|
|
EU-gehostet | CLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
|
Öffentl. AVV: Ja
Subprozessoren: Ja
Open Source: Nein
|
— |