Document Trust Grade

How a document is graded.

Every grade Tindom issues is produced by this rubric, and nothing else. It is published in full so that any grade can be checked against the rules that produced it — including by the supplier whose document was graded.

Validate a document

Pre-release. This is a 0.x version under semantic versioning: the scale and its thresholds have not yet been calibrated against a real distribution of documents and may still change materially. Grades issued under a pre-release rubric carry no commitment and should not be cited as a settled assessment.

Version 0.1.0 · published 2026-08-31

What the grade measures

How strongly this file proves, on its own, who signed it and that it has not changed — and how long it will keep proving it, without the signing platform.
This is not a judgement of legal validity. The grade measures how independently verifiable a file is. Under eIDAS Article 25 an electronic signature cannot be denied legal effect merely for not being qualified — so a low grade does not mean a document is not binding.

Three questions in strict order: integrity (has it changed?), then trust (does the identity chain to a recognised trust regime?), then durability (will it still verify years from now without anyone's help?). This is a ladder of necessary conditions, not a points total — a file receives the highest grade whose conditions it meets in full, and one failed gate caps it regardless of everything else.

The scale

A+

Beyond the standard

All of the following:

  • Everything required for A.
  • ETSI baseline B-LTA — carries archive timestamps, so the proof can be refreshed as cryptographic algorithms age and outlives the certificate itself.
  • No post-signing modification permitted or detected.
  • At least one marker from the closed list below.

The supplier went further than the standard asks.

A

The ETSI standard, met in full

All of the following:

  • Validation outcome TOTAL_PASSED — intact, chain valid, not revoked.
  • Chains to a trust regime whose ceiling is A: an EU/EEA Trusted List, or a third-country list recognised through an eIDAS Article 14 mutual-recognition agreement.
  • Qualifies as a qualified electronic signature (QES) or qualified electronic seal (QESeal).
  • ETSI baseline B-LT or B-LTA — certificates and revocation data embedded, so the file verifies offline without contacting anyone.
  • The signature covers the whole document.

This is what a properly signed document looks like. It proves who signed it, when, and that nothing has changed — on its own, offline, without the platform that made it.

B

Trusted and time-anchored

All of the following:

  • Clears everything required for C, and carries a qualified timestamp (ETSI B-T or better).
  • Misses at least one A requirement — either the trust regime's own ceiling is B, or it is qualified but not yet self-contained (B-T rather than B-LT/B-LTA).

An independent third party has proven when this was signed, and it will keep verifying for years.

C

Trusted, but decaying

All of the following:

  • Intact, and chains to a recognised trust regime.
  • ETSI baseline B-B — no qualified timestamp, no embedded validation material.

Verifies today. There is no independent proof of when it was signed, and once the signing certificate expires or its revocation data goes offline, it may stop verifying entirely.

D

Provable file, unprovable signer

All of the following:

  • The signature verifies and the document is intact.
  • The certificate chains to no trust regime we recognise — self-signed, a private CA, or an unknown issuer.

You can prove this file has not changed. You cannot prove who signed it.

E

A claim, without proof

All of the following:

  • The file carries a signing claim — an attached evidence package, a platform audit trail, or a visual signature.
  • There is no cryptographic signature over the document that can be independently verified, so integrity cannot be checked at all.

Something was signed. This file cannot prove it. The proof sits with the signing platform, not with you. Nothing here is wrong — it is simply not self-proving.

F

Fails

Any one of the following:

  • The signed content has been modified since signing.
  • The signature is cryptographically invalid.
  • The signing certificate was revoked at the time of signing.

This document does not prove what it claims. Do not rely on it without going back to the source.

Not graded

No letter is issued when there is no signature and no evidence package to assess, or the file cannot be read. This is never shown as F. F means we checked and the document failed; absence of proof is a different statement from disproof.

Important limits

  1. This grade measures independent verifiability, not legal validity. Under eIDAS Article 25 an electronic signature cannot be denied legal effect merely for not being qualified. A low grade does not mean a document is not binding.
  2. Every grade is dated and tied to a rubric version. A file graded A today can grade lower in five years as certificates expire — that decay is precisely what the long-term ETSI forms exist to prevent, and a grade is always a point-in-time assessment.
  3. Tindom is not a qualified trust service provider. This grade is independent evidence, not a qualified validation service under eIDAS, and carries no legal presumption of its own.

Trust regimes

Tindom validates against every trust source it carries and names the one that vouched for each document, rather than refusing documents that sit outside a preferred list. What differs between regimes is not whether we check them — it is what a positive result legally means, and that is what sets the ceiling.

RegimeWhat it isLegal weightCeiling
EU/EEA qualifiedMember-state trusted lists under eIDAS Article 22, where the service is granted for qualified certificates. Published by each member state, aggregated by the European Commission.Presumption under eIDAS Article 25 (signatures) / Article 35 (seals).A+
Recognised third countryTrusted lists of countries holding an eIDAS Article 14 mutual-recognition agreement — currently Ukraine and Moldova.Legally equivalent to EU-qualified, by agreement.A+
EU/EEA non-qualifiedOn a member-state trusted list, but the service is not granted for qualified certificates.Supervised; no presumption.B
National regulatedA national trusted list operating outside eIDAS recognition — the Swiss list (ZertES, Swiss Accreditation Service) and the UK list (Information Commissioner's Office). Real supervision, real audit, no EU mutual recognition.Regulated nationally; no eIDAS presumption.B
Commercial programmeThe Adobe Approved Trust List — around 300 certificate authorities admitted under Adobe's published technical requirements and independent audit. This is what makes Adobe Acrobat show a green tick.Contractual, not statutory; no presumption.B
Not recognisedChains to no list we carry: self-signed, a private certificate authority, or an unknown issuer.None.D

The A+ markers

This list is closed and published, so A+ is achievable rather than a matter of taste. A document needs everything required for A, plus the conditions listed under A+, plus at least one of these:

  • A qualified certificate held on a qualified signature creation device (QSCD).
  • A qualified electronic seal from the issuing platform over the finished document, in addition to the party signatures.
  • Two or more independent qualified timestamps.
  • A complete machine-readable evidence package embedded in the file.

Rules that apply to every grade

A document's grade is the lowest of its signatures' grades — a contract is only as good as its weakest party's proof. Each signature also carries its own grade, so the roll-up is never opaque.

A grade is never shown as a bare letter. It always appears with the assurance level, the ETSI form, and the trust regime that vouched for it — the letter carries the legibility, the rest carries the defensibility.

A real document, walked through the ladder

A PDF sealed by an e-signing platform, validated by Tindom. It clears every gate up to the top of the ladder and is then held at B by two separate things — which is the ordinary case, not a failure.

IntegrityIntact — the signed content has not been modified since sealing.
RevocationNot revoked, checked live against the issuer's OCSP responder at validation time.
Trust regimeEU Trusted List (Norway), via a trust service granted for qualified certificates. Regime ceiling: A+.
Signature scopeCovers the whole document.
DurabilityPAdES-BASELINE-T. A timestamp proves when it was sealed, but the certificates and revocation data are not embedded — verifying it later means fetching them from the issuer, which will not be possible forever. A needs B-LT.
Assurance levelAdvanced electronic seal supported by a qualified certificate — not a full qualified electronic seal. A requires QES or QESeal.

Grade B. Trusted and time-anchored, and it will keep verifying for years — but two separate things stand between it and A, and either one alone would be enough to hold it there. Both are configuration changes on the signing platform's side, not re-architecture.

How to raise a grade

The scale is only useful if it says what to change. Each entry below is a ceiling a document can hit, what it means, and what would move it up.

Timestamped, but the file does not carry what is needed to verify it on its own later (B-T).

Embed the certificate chain and revocation data at signing time — B-T becomes B-LT. Usually a setting in the signing platform.

The signature alone, with no independent proof of when it was made (B-B).

Add a qualified timestamp at signing — B-B becomes B-T, and the document stops depending on a claimed signing time.

An advanced signature or seal, possibly on a qualified certificate, but not a qualified signature or seal in the eIDAS sense.

Issue on a qualified certificate held on a qualified signature creation device (QSCD). This is a change of product with the trust service provider, not a file-format change.

Self-contained, but without archive timestamps the proof cannot be refreshed as cryptographic algorithms age (B-LT).

Apply an archive timestamp — B-LT becomes B-LTA, and the evidence outlives both the certificate and the algorithms in use today.

The certificate chains to nothing we recognise — self-signed, a private authority, or an unknown issuer.

Sign with a certificate from a provider on one of the trust lists above. An internal certificate authority cannot reach beyond D, however well run.

The file records that signing happened, but carries no cryptographic signature we can check.

Embed a real signature in the document itself (PAdES for PDFs) rather than keeping the proof on the platform. This is the single largest step available — it moves a document from E to a graded rung.

Content sits outside what the signature actually covers.

Sign the whole document. A partial signature vouches only for the part it covers, whatever the rest of the file appears to say.

How this rubric is versioned, and what has changed between versions: Full changelog.

What introduced this version

0.1.0 · 2026-08-31 · initial

First published version of the scale. Pre-release under semantic versioning: the thresholds have not yet been calibrated against a real distribution of documents, so they may still move.

Grades affected: Not applicable — no earlier version exists.

Changelog

What changed between versions, and which grades moved as a result. Subscribable by RSS.

Changelog

Published versions

Every version stays available so a grade issued under it can still be checked.