Aller au contenu
CLOUD Act signalé sur chaque fiche
EU VETTED

Skribble

VéRIFIé
Signature électronique · Suisse
Fondé en 2018 · skribble.com ↗

Zurich-based Swiss e-signature platform with dual ZertES + eIDAS QES via Swisscom partnership; ISO 27001, 4,000+ DACH customers.

En bref

Skribble, dans la catégorie Signature électronique, est un service européen hébergé en Suisse, avec tout au plus une exposition américaine mineure et transitoire au titre du CLOUD Act.

Notes d’évaluation

Skribble is a Zurich-based Swiss e-signature platform that uniquely covers both ZertES (the Swiss Federal Act on Electronic Signatures) AND eIDAS (the EU regulation) for Qualified Electronic Signatures. Skribble is not itself a Qualified Trust Service Provider: it brokers QES, and the eIDAS-qualified certificates, timestamps and remote QSCD management are issued by Swisscom IT Services Finance S.E., which is the entity actually carrying the qualified status on the Austrian trusted list (verified against that list at the 2026-08 re-verify; Skribble itself appears on no EU trusted list). ISO 9001 + ISO 27001 certified, GDPR + DSGVO compliant, serving 4,000+ companies in DACH (Germany / Austria / Switzerland). Signed documents stay on Swiss infrastructure (cloudscale.ch and VSHN, with IONOS in Germany for German customers), and Switzerland's adequacy decision keeps EU-CH transfers SCC-free, so there is no US-owned provider in the at-rest path. The score moved 5 to 3 at the 2026-08 re-verify because the published DPA names five US-incorporated sub-processors around that core: Cloudflare (network security and authentication, so plain-HTTP traffic passes through a US-owned network), plus SparkPost (email), Chargebee (billing), Userpilot (in-app messaging) and Clay Labs (data enrichment), with HubSpot, Stripe and Google Mail contracted through Irish entities of US parents. The rubric caps a listing at 3/5 once three or more US sub-processors are in the chain. The dual-bar ZertES + eIDAS coverage remains the directory's strongest cross-jurisdiction QES capability for buyers operating across CH and EU, and the at-rest picture is still cleaner than the AWS-hosted Namirial-group options.

CLOUD ACT
Actionnariat
Sous-trait.
0 aucun divulgué
Signaux vérifiés
Juridiction
  • Hébergement UE / adéquation
  • Opérateur UE / adéquation
  • Aucune exposition au CLOUD Act
Transparence
  • DPA public
  • Sous-traitants divulgués
  • Clients open source
  • Certification tierce
Aller à
Aperçu

À propos de Skribble

Skribble is a Zurich-headquartered Swiss e-signature platform that distinguishes itself in the QES market by uniquely covering both Swiss ZertES and EU eIDAS qualified-signature regulations under a single platform. Founded around 2018 with focus on the DACH region (Germany, Austria, Switzerland), the company has scaled to 4,000+ corporate customers and built its QES capabilities on a partnership with Swisscom, which issues the underlying qualified certificates under both ZertES (the Swiss Federal Act on Electronic Signatures) and eIDAS (the EU regulation). Skribble is not itself a Qualified Trust Service Provider and appears on no EU trusted list: it brokers those qualifications rather than holding them. Swisscom AG is the ZertES-side Swiss entity, while the eIDAS-qualified certificates, timestamping and remote signature-creation-device management sit with Swisscom IT Services Finance S.E., the entity actually carried on the Austrian trusted list. This dual-bar coverage matters because Switzerland and the EU are separate jurisdictions with no automatic mutual recognition of qualified signatures; a Swiss-only or EU-only QTSP can leave one half of a DACH transaction legally exposed, while Skribble's Swisscom-anchored stack delivers QES that is fully binding under both regimes.

Compliance posture is procurement-grade: ISO 9001 + ISO 27001 certified at the company level, GDPR + DSGVO compliant, Swiss federal legal-validity coverage under ZertES via Swisscom-issued certificates. The platform handles identity verification (video-ident, qualified e-ID, GwG / FATF-aligned KYC for higher signature tiers), signing workflows (Simple, Advanced, Qualified electronic signatures), and audit-trail packaging. Switzerland holds an EU adequacy decision under Art. 45 GDPR so cross-border EU↔CH transfers require no SCCs. Contracting is better than the Swiss address suggests: buyers seated in Germany or in any other country outside Switzerland contract with Skribble Deutschland GmbH (An der Raumfabrik 29, Karlsruhe), so an EU customer's counterparty is an EU-incorporated entity. Signed documents stay on Swiss infrastructure (cloudscale.ch and VSHN, with IONOS in Germany for German customers), but the published DPA names five US-incorporated processors around that core, Cloudflare among them for network security and authentication, which is why CLOUD Act exposure is recorded as Mineure rather than none.

Pricing is published per user per month, excluding VAT: a free Starter tier on pay-per-use at €1 per simple electronic signature, Team at 23 € per user per month on annual billing, Pro at €36 on the same basis, and Scale on request. Best fit: DACH companies with material cross-border CH↔EU contracting flows (Swiss banks contracting EU customers, EU insurers signing Swiss policy-holders, Swiss-EU joint ventures, dual-jurisdiction employment contracts), companies in regulated industries needing QES under either ZertES or eIDAS, and any organisation that values having Swisscom-issued qualified certificates as the trust anchor. Procurement-grade EU-only buyers operating purely inside the EU may prefer Youtrust (France, ANSSI-supervised, formerly Yousign and a QTSP in its own right) or the Signaturit / Namirial group (though the latter is US-private-equity-owned since 2025 and hosted at rest on AWS, so cloud_act_exposure: material), but for any DACH workflow Skribble's dual-regime QES is structurally differentiated.

Sous-traitants

Carte des sous-traitants · aucun divulgué

Source ↗
L'éditeur déclare zéro sous-traitant. Tout le traitement des données se fait en interne.
Certifications

Référentiels & certifications

ISO/IEC 27001
ACTIVE
Fonctionnalités

Matrice de fonctionnalités

Signature qualifiée (QES) Oui
Signature avancée (AES) Oui
Piste d’audit Oui
Modèles Non
Vérification d’identité Oui
API / webhooks Oui
INTéGRATION & ACCèS
REST API Yes
SSO (SAML / OIDC) Yes
CONFORMITé & GOUVERNANCE
Audit log Yes
Self-host / on-prem option No
Tarifs

Tarifs & paliers

FREEMIUM
à partir de 23 €/mois
facturé annuellement
Voir la page tarifs ↗
Documents publics

Documents publics

  • Contrat de sous-traitance (DPA)
    www.skribble.com/en-eu…
    Ouvrir ↗
  • Liste des sous-traitants
    www.skribble.com/en-eu…
    Ouvrir ↗
  • Conditions d'utilisation
    www.skribble.com/en-eu…
    Ouvrir ↗
Alternatives

Alternatives dans cette catégorie

Eversign (Xodo Sign)
Autriche · Fondé en 2017
LIé AUX US

Vienna-launched e-signature platform (eversign GmbH, 2017), acquired by Apryse (US/PDFTron) in 2022, rebranded as Xodo Sign.

DPA public Sous-traitants Open source
FROM
10 $/mois
facturé annuellement
CLOUD ACT
DIRECT
Signaturit (Namirial)
Espagne · Fondé en 2013
HéBERGé UE

Barcelona-based Spanish digital-trust group (Signaturit, a Namirial company; parent Namirial acquired by Bain Capital, US PE, 2025), 4 QTSPs with highest eIDAS qualifications; platform hosted at rest on AWS.

DPA public Sous-traitants Open source
FROM
CLOUD ACT
MATERIAL
Signicat
Norvège · Fondé en 2006
HéBERGé UE

Trondheim-based pan-European eIDAS QTSP for digital identity, e-ID and qualified e-signatures; Nordic Capital-owned, EEA-hosted on US hyperscalers.

DPA public Sous-traitants Open source
FROM
CLOUD ACT
MATERIAL