A Trust Service Provider with validity across the European Union
We are recognised and audited as a provider of electronic trust services under Regulation (EU) 910/2014 (eIDAS) and listed in the European Commission's Trusted List. We issue qualified electronic timestamps and build on them the certification of communications, electronic signature and custody of evidence.
- Provider
- ASETEC Ingeniería de Sistemas, S.L. (Mensatek brand)
- Supervision
- Competent ministry in Spain; periodic conformity audits
- Trusted List
- EU Trusted List (Spain)
- Qualified service
- Qualified electronic timestamping (RFC 3161)
- Double seal
- Certificates sealed by two qualified providers: Mensatek and the FNMT
- Documentation
- Certification Policies & Practices
listed in the EU Trusted List ISO/IEC 27001
information security, independently audited ISO 9001
quality management, independently audited Own infrastructure
high-performance data centres in Spain Since 1998
28 years of uninterrupted engineering
What being a trust service provider means
The eIDAS Regulation sets the common legal framework of the European Union for trust services: timestamping, electronic signatures and seals, electronic registered delivery and validation. A trust service provider is an entity supervised by the competent authority of its Member State, subject to conformity audits and published in the trusted lists maintained by the European Commission.
ASETEC appears in that list and issues qualified electronic timestamps: the evidence with the strongest legal presumption in Europe that certain data existed, unaltered, at a given moment (Article 41 of eIDAS). On that capability we build everything else: the certified communications of Mensatek and smscertificado.es, the online contracting of lofirmo.com, identity verification and the custody of evidence.
And we add a further guarantee: certificates are sealed by two qualified trust service providers (Mensatek and the FNMT), so the evidence never depends on a single party. All the provider's documentation (practice statement, disclosure statements, timestamping unit certificates and security policy) is published under Certification Policies & Practices.
Legal framework of the evidence
- Regulation (EU) 910/2014 (eIDAS): legal effects of timestamps, signatures and registered delivery; presumption of accuracy and integrity of the qualified timestamp (Art. 41).
- Spanish Law 6/2020 on certain aspects of electronic trust services.
- Spanish Civil Procedure Act (Arts. 299 and 326): admissibility of electronic documents as evidence.
- GDPR and ISO 27001 certification in the processing and custody of evidence.
Listing verifiable in the European Commission's Trusted List.
Trust services we provide
Available from the group platforms (Mensatek, smscertificado.es, lofirmo.com), via API and as part of the systems we build.
Qualified timestamping
Qualified electronic timestamps under eIDAS and RFC 3161 for documents, records, transactions and events, issued by our audited timestamping unit.
Certification of communications
Certified SMS, email, RCS and WhatsApp with proof of content, sending and delivery, and an evidence record sealed and kept for 10 years.
Contracting and e-signature
Document signing with several levels (acceptance, OTP, handwritten, certificate) and several signatories, with an evidence record and qualified timestamps.
SMS contract
Contracting by SMS: the recipient accepts by replying to the message and the whole exchange is certified.
Identity verification
Remote identification with an official document, facial biometrics and liveness detection, with a certified, timestamped result.
Evidence custody
Intact preservation of certificates and records for 10 years, with public verification by code and PDF download.
Cross-border validity
Legal effects recognised in every Member State of the European Union under the eIDAS Regulation.
API integration
Timestamping, certification, signature and identity embeddable in your applications with public documentation and technical support.
Bespoke trust services
Design of evidence workflows for specific processes (internal notifications, activity logs, document traceability) within engineering projects.
What a qualified timestamp guarantees
The difference between "having a record" and being able to prove it to a third party years later.
- Legal presumption: A qualified timestamp enjoys a presumption of accuracy of the date and time and of integrity of the data (Art. 41.2 eIDAS).
- Reliable time source: Time synchronised with reference sources and timestamping units with qualified certificates.
- Open standard: Timestamps compliant with RFC 3161, verifiable with any standard tool, without depending on us.
- Two providers: Communication certificates carry timestamps from two qualified providers (Mensatek and the FNMT).
- Independent audit: Periodic eIDAS conformity audits and supervision by the competent authority in Spain.
- Custody and verification: Evidence kept for 10 years on our own infrastructure under ISO 27001, publicly verifiable by code.
How a piece of evidence is built
The same workflow for a timestamped document, a certified notification or a signed contract.
Capture
The full content (text, attachments, document) is recorded and its cryptographic hash computed.
Timestamping
Each milestone (issue, delivery, reading, signature) receives a qualified timestamp; certificates carry the Mensatek + FNMT double seal.
Certification
The PDF certificate is generated with content, chronology and seals, and electronically signed.
Custody and verification
It is kept for 10 years on our own infrastructure and can be verified publicly by its code.
What they are used for
Certified notification
Formal demands, claims and communications with legal effect sent by certified SMS or email, with evidence of content and delivery.
Remote contracting
Policies, service contracts and consents signed from the phone with an evidence record and qualified timestamps.
Timestamping of documents and records
Quotes, minutes, activity logs and files timestamped to prove their existence and integrity on a date.
Onboarding with guarantees
Certified identity verification as a prior step to contracting or to accessing regulated services.
Auditable traceability
Audit logs and internal communications with timestamping for audits, GDPR and sector regulations.
Embedded evidence
Timestamping and certification built via API into the systems we develop for our clients.
Questions we are usually asked
Is ASETEC a qualified provider?
ASETEC (Mensatek brand) is a trust service provider listed in the European Union Trusted List and issues qualified electronic timestamps under the eIDAS Regulation. You can check the listing in the European Commission's trusted list browser.
What validity does a qualified timestamp have?
It enjoys a legal presumption of accuracy of the date and time it indicates and of integrity of the data to which it is bound (Article 41.2 of eIDAS), and is recognised as such in every Member State.
Why do certificates carry two seals?
Because evidence should not depend on a single party. Certificates are sealed by two qualified trust service providers, Mensatek and the FNMT, so that either one allows independent verification.
How long is evidence kept?
Ten years, on our own infrastructure in Spain under our ISO 27001 certification, with public verification by code and PDF download throughout that period.
Where is the provider's official documentation?
On the Certification Policies & Practices page: practice statement, disclosure statements, timestamping unit certificates, security policy and certificate status validation points.
Do you need something to be provable?
Timestamping of documents, certified notifications, signature or identity: tell us the process and we will tell you which evidence it needs and how to integrate it.