Skribble
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based This listing EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Zurich-based Swiss e-signature platform with dual ZertES + eIDAS QES via Swisscom partnership; ISO 27001, 4,000+ DACH customers.
Skribble is a European service hosted in Switzerland, with at most minor, transient US exposure under the CLOUD Act. It is listed under E-signature.
Assessment notes
Skribble is a Zurich-based Swiss e-signature platform that uniquely covers both ZertES (the Swiss Federal Act on Electronic Signatures) AND eIDAS (the EU regulation) for Qualified Electronic Signatures. Skribble is not itself a Qualified Trust Service Provider: it brokers QES, and the eIDAS-qualified certificates, timestamps and remote QSCD management are issued by Swisscom IT Services Finance S.E., which is the entity actually carrying the qualified status on the Austrian trusted list (verified against that list at the 2026-08 re-verify; Skribble itself appears on no EU trusted list). ISO 9001 + ISO 27001 certified, GDPR + DSGVO compliant, serving 4,000+ companies in DACH (Germany / Austria / Switzerland). Signed documents stay on Swiss infrastructure (cloudscale.ch and VSHN, with IONOS in Germany for German customers), and Switzerland's adequacy decision keeps EU-CH transfers SCC-free, so there is no US-owned provider in the at-rest path. The score moved 5 to 3 at the 2026-08 re-verify because the published DPA names five US-incorporated sub-processors around that core: Cloudflare (network security and authentication, so plain-HTTP traffic passes through a US-owned network), plus SparkPost (email), Chargebee (billing), Userpilot (in-app messaging) and Clay Labs (data enrichment), with HubSpot, Stripe and Google Mail contracted through Irish entities of US parents. The rubric caps a listing at 3/5 once three or more US sub-processors are in the chain. The dual-bar ZertES + eIDAS coverage remains the directory's strongest cross-jurisdiction QES capability for buyers operating across CH and EU, and the at-rest picture is still cleaner than the AWS-hosted Namirial-group options.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
European This listing Swiss/EEA-owned, with no significant US ownership; treated as European.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
- Sub-processors
- 0 none disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Not assessed
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Skribble
Skribble is a Zurich-headquartered Swiss e-signature platform that distinguishes itself in the QES market by uniquely covering both Swiss ZertES and EU eIDAS qualified-signature regulations under a single platform. Founded around 2018 with focus on the DACH region (Germany, Austria, Switzerland), the company has scaled to 4,000+ corporate customers and built its QES capabilities on a partnership with Swisscom, which issues the underlying qualified certificates under both ZertES (the Swiss Federal Act on Electronic Signatures) and eIDAS (the EU regulation). Skribble is not itself a Qualified Trust Service Provider and appears on no EU trusted list: it brokers those qualifications rather than holding them. Swisscom AG is the ZertES-side Swiss entity, while the eIDAS-qualified certificates, timestamping and remote signature-creation-device management sit with Swisscom IT Services Finance S.E., the entity actually carried on the Austrian trusted list. This dual-bar coverage matters because Switzerland and the EU are separate jurisdictions with no automatic mutual recognition of qualified signatures; a Swiss-only or EU-only QTSP can leave one half of a DACH transaction legally exposed, while Skribble's Swisscom-anchored stack delivers QES that is fully binding under both regimes.
Compliance posture is procurement-grade: ISO 9001 + ISO 27001 certified at the company level, GDPR + DSGVO compliant, Swiss federal legal-validity coverage under ZertES via Swisscom-issued certificates. The platform handles identity verification (video-ident, qualified e-ID, GwG / FATF-aligned KYC for higher signature tiers), signing workflows (Simple, Advanced, Qualified electronic signatures), and audit-trail packaging. Switzerland holds an EU adequacy decision under Art. 45 GDPR so cross-border EU↔CH transfers require no SCCs. Contracting is better than the Swiss address suggests: buyers seated in Germany or in any other country outside Switzerland contract with Skribble Deutschland GmbH (An der Raumfabrik 29, Karlsruhe), so an EU customer's counterparty is an EU-incorporated entity. Signed documents stay on Swiss infrastructure (cloudscale.ch and VSHN, with IONOS in Germany for German customers), but the published DPA names five US-incorporated processors around that core, Cloudflare among them for network security and authentication, which is why CLOUD Act exposure is recorded as Minor rather than none.
Pricing is published per user per month, excluding VAT: a free Starter tier on pay-per-use at €1 per simple electronic signature, Team at €23 per user per month on annual billing, Pro at €36 on the same basis, and Scale on request. Best fit: DACH companies with material cross-border CH↔EU contracting flows (Swiss banks contracting EU customers, EU insurers signing Swiss policy-holders, Swiss-EU joint ventures, dual-jurisdiction employment contracts), companies in regulated industries needing QES under either ZertES or eIDAS, and any organisation that values having Swisscom-issued qualified certificates as the trust anchor. Procurement-grade EU-only buyers operating purely inside the EU may prefer Youtrust (France, ANSSI-supervised, formerly Yousign and a QTSP in its own right) or the Signaturit / Namirial group (though the latter is US-private-equity-owned since 2025 and hosted at rest on AWS, so cloud_act_exposure: material), but for any DACH workflow Skribble's dual-regime QES is structurally differentiated.
Sub-processor map · none disclosed
Frameworks & certifications
Capability matrix
Table 1Capabilities of Skribble
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Austria · $10/moUS-LinkedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct This listing The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
SpainEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
NorwayEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
US-Linked | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
$10/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |