Skip to content
CLOUD Act flagged on every listing
EU VETTED

Skribble

VERIFIED
E-signature · Switzerland
Founded 2018 · skribble.com ↗

Zurich-based Swiss e-signature platform with dual ZertES + eIDAS QES via Swisscom partnership; ISO 27001, 4,000+ DACH customers.

In short

Skribble, in the E-signature category, is a European service with Switzerland as its hosting location and at most minor, transient US exposure under the CLOUD Act.

Assessment notes

Skribble is a Zurich-based Swiss e-signature platform that uniquely covers both ZertES (the Swiss Federal Act on Electronic Signatures) AND eIDAS (the EU regulation) for Qualified Electronic Signatures. Skribble is not itself a Qualified Trust Service Provider: it brokers QES, and the eIDAS-qualified certificates, timestamps and remote QSCD management are issued by Swisscom IT Services Finance S.E., which is the entity actually carrying the qualified status on the Austrian trusted list (verified against that list at the 2026-08 re-verify; Skribble itself appears on no EU trusted list). ISO 9001 + ISO 27001 certified, GDPR + DSGVO compliant, serving 4,000+ companies in DACH (Germany / Austria / Switzerland). Signed documents stay on Swiss infrastructure (cloudscale.ch and VSHN, with IONOS in Germany for German customers), and Switzerland's adequacy decision keeps EU-CH transfers SCC-free, so there is no US-owned provider in the at-rest path. The score moved 5 to 3 at the 2026-08 re-verify because the published DPA names five US-incorporated sub-processors around that core: Cloudflare (network security and authentication, so plain-HTTP traffic passes through a US-owned network), plus SparkPost (email), Chargebee (billing), Userpilot (in-app messaging) and Clay Labs (data enrichment), with HubSpot, Stripe and Google Mail contracted through Irish entities of US parents. The rubric caps a listing at 3/5 once three or more US sub-processors are in the chain. The dual-bar ZertES + eIDAS coverage remains the directory's strongest cross-jurisdiction QES capability for buyers operating across CH and EU, and the at-rest picture is still cleaner than the AWS-hosted Namirial-group options.

CLOUD ACT
Ownership
Sub-procs
0 none disclosed
Verified signals
Jurisdiction
  • EU / adequacy hosting
  • EU / adequacy operator
  • No US CLOUD Act exposure
Transparency
  • Public DPA
  • Sub-processors disclosed
  • Open-source clients
  • Third-party certification
Jump to
Overview

About Skribble

Skribble is a Zurich-headquartered Swiss e-signature platform that distinguishes itself in the QES market by uniquely covering both Swiss ZertES and EU eIDAS qualified-signature regulations under a single platform. Founded around 2018 with focus on the DACH region (Germany, Austria, Switzerland), the company has scaled to 4,000+ corporate customers and built its QES capabilities on a partnership with Swisscom, which issues the underlying qualified certificates under both ZertES (the Swiss Federal Act on Electronic Signatures) and eIDAS (the EU regulation). Skribble is not itself a Qualified Trust Service Provider and appears on no EU trusted list: it brokers those qualifications rather than holding them. Swisscom AG is the ZertES-side Swiss entity, while the eIDAS-qualified certificates, timestamping and remote signature-creation-device management sit with Swisscom IT Services Finance S.E., the entity actually carried on the Austrian trusted list. This dual-bar coverage matters because Switzerland and the EU are separate jurisdictions with no automatic mutual recognition of qualified signatures; a Swiss-only or EU-only QTSP can leave one half of a DACH transaction legally exposed, while Skribble's Swisscom-anchored stack delivers QES that is fully binding under both regimes.

Compliance posture is procurement-grade: ISO 9001 + ISO 27001 certified at the company level, GDPR + DSGVO compliant, Swiss federal legal-validity coverage under ZertES via Swisscom-issued certificates. The platform handles identity verification (video-ident, qualified e-ID, GwG / FATF-aligned KYC for higher signature tiers), signing workflows (Simple, Advanced, Qualified electronic signatures), and audit-trail packaging. Switzerland holds an EU adequacy decision under Art. 45 GDPR so cross-border EU↔CH transfers require no SCCs. Contracting is better than the Swiss address suggests: buyers seated in Germany or in any other country outside Switzerland contract with Skribble Deutschland GmbH (An der Raumfabrik 29, Karlsruhe), so an EU customer's counterparty is an EU-incorporated entity. Signed documents stay on Swiss infrastructure (cloudscale.ch and VSHN, with IONOS in Germany for German customers), but the published DPA names five US-incorporated processors around that core, Cloudflare among them for network security and authentication, which is why CLOUD Act exposure is recorded as Minor rather than none.

Pricing is published per user per month, excluding VAT: a free Starter tier on pay-per-use at €1 per simple electronic signature, Team at €23 per user per month on annual billing, Pro at €36 on the same basis, and Scale on request. Best fit: DACH companies with material cross-border CH↔EU contracting flows (Swiss banks contracting EU customers, EU insurers signing Swiss policy-holders, Swiss-EU joint ventures, dual-jurisdiction employment contracts), companies in regulated industries needing QES under either ZertES or eIDAS, and any organisation that values having Swisscom-issued qualified certificates as the trust anchor. Procurement-grade EU-only buyers operating purely inside the EU may prefer Youtrust (France, ANSSI-supervised, formerly Yousign and a QTSP in its own right) or the Signaturit / Namirial group (though the latter is US-private-equity-owned since 2025 and hosted at rest on AWS, so cloud_act_exposure: material), but for any DACH workflow Skribble's dual-regime QES is structurally differentiated.

Sub-processors

Sub-processor map · none disclosed

Source ↗
Vendor discloses zero sub-processors. All data processing happens in-house.
Certifications

Frameworks & certifications

ISO/IEC 27001
ACTIVE
Features

Capability matrix

Qualified signature (QES) Yes
Advanced signature (AES) Yes
Audit trail Yes
Templates No
ID verification Yes
API / webhooks Yes
INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option No
Pricing

Pricing & tiers

FREEMIUM
from €23/mo
billed annually
View pricing page ↗
Public documents

Public documents

  • Data Processing Addendum (DPA)
    www.skribble.com/en-eu…
    Open ↗
  • Sub-processors list
    www.skribble.com/en-eu…
    Open ↗
  • Terms of Service
    www.skribble.com/en-eu…
    Open ↗
Alternatives

Alternatives in this category

Eversign (Xodo Sign)
Austria · Founded 2017
US-LINKED

Vienna-launched e-signature platform (eversign GmbH, 2017), acquired by Apryse (US/PDFTron) in 2022, rebranded as Xodo Sign.

Public DPA Sub-processors Open source
FROM
$10/mo
billed annually
CLOUD ACT
DIRECT
Signaturit (Namirial)
Spain · Founded 2013
EU-HOSTED

Barcelona-based Spanish digital-trust group (Signaturit, a Namirial company; parent Namirial acquired by Bain Capital, US PE, 2025), 4 QTSPs with highest eIDAS qualifications; platform hosted at rest on AWS.

Public DPA Sub-processors Open source
FROM
CLOUD ACT
MATERIAL
Signicat
Norway · Founded 2006
EU-HOSTED

Trondheim-based pan-European eIDAS QTSP for digital identity, e-ID and qualified e-signatures; Nordic Capital-owned, EEA-hosted on US hyperscalers.

Public DPA Sub-processors Open source
FROM
CLOUD ACT
MATERIAL