Skip to content
Trust Service Provider (eIDAS) · ISO 27001 · ISO 9001 +34 910 606 161
06 / 06  eIDAS trust services

A Trust Service Provider with validity across the European Union

We are recognised and audited as a provider of electronic trust services under Regulation (EU) 910/2014 (eIDAS) and listed in the European Commission's Trusted List. We issue qualified electronic timestamps and build on them the certification of communications, electronic signature and custody of evidence.

Trust Service ProvidereIDAS · EU 910/2014
Provider
ASETEC Ingeniería de Sistemas, S.L. (Mensatek brand)
Supervision
Competent ministry in Spain; periodic conformity audits
Trusted List
EU Trusted List (Spain)
Qualified service
Qualified electronic timestamping (RFC 3161)
Double seal
Certificates sealed by two qualified providers: Mensatek and the FNMT
Documentation
Certification Policies & Practices
eIDAS Trust Service Provider
listed in the EU Trusted List
ISO/IEC 27001
information security, independently audited
ISO 9001
quality management, independently audited
Own infrastructure
high-performance data centres in Spain
Since 1998
28 years of uninterrupted engineering
eIDAS trust services

What being a trust service provider means

The eIDAS Regulation sets the common legal framework of the European Union for trust services: timestamping, electronic signatures and seals, electronic registered delivery and validation. A trust service provider is an entity supervised by the competent authority of its Member State, subject to conformity audits and published in the trusted lists maintained by the European Commission.

ASETEC appears in that list and issues qualified electronic timestamps: the evidence with the strongest legal presumption in Europe that certain data existed, unaltered, at a given moment (Article 41 of eIDAS). On that capability we build everything else: the certified communications of Mensatek and smscertificado.es, the online contracting of lofirmo.com, identity verification and the custody of evidence.

And we add a further guarantee: certificates are sealed by two qualified trust service providers (Mensatek and the FNMT), so the evidence never depends on a single party. All the provider's documentation (practice statement, disclosure statements, timestamping unit certificates and security policy) is published under Certification Policies & Practices.

Legal framework of the evidence

  • Regulation (EU) 910/2014 (eIDAS): legal effects of timestamps, signatures and registered delivery; presumption of accuracy and integrity of the qualified timestamp (Art. 41).
  • Spanish Law 6/2020 on certain aspects of electronic trust services.
  • Spanish Civil Procedure Act (Arts. 299 and 326): admissibility of electronic documents as evidence.
  • GDPR and ISO 27001 certification in the processing and custody of evidence.

Listing verifiable in the European Commission's Trusted List.

What is included

Trust services we provide

Available from the group platforms (Mensatek, smscertificado.es, lofirmo.com), via API and as part of the systems we build.

Qualified timestamping

Qualified electronic timestamps under eIDAS and RFC 3161 for documents, records, transactions and events, issued by our audited timestamping unit.

Certification of communications

Certified SMS, email, RCS and WhatsApp with proof of content, sending and delivery, and an evidence record sealed and kept for 10 years.

Contracting and e-signature

Document signing with several levels (acceptance, OTP, handwritten, certificate) and several signatories, with an evidence record and qualified timestamps.

SMS contract

Contracting by SMS: the recipient accepts by replying to the message and the whole exchange is certified.

Identity verification

Remote identification with an official document, facial biometrics and liveness detection, with a certified, timestamped result.

Evidence custody

Intact preservation of certificates and records for 10 years, with public verification by code and PDF download.

Cross-border validity

Legal effects recognised in every Member State of the European Union under the eIDAS Regulation.

API integration

Timestamping, certification, signature and identity embeddable in your applications with public documentation and technical support.

Bespoke trust services

Design of evidence workflows for specific processes (internal notifications, activity logs, document traceability) within engineering projects.

Technical guarantees

What a qualified timestamp guarantees

The difference between "having a record" and being able to prove it to a third party years later.

  • Legal presumption: A qualified timestamp enjoys a presumption of accuracy of the date and time and of integrity of the data (Art. 41.2 eIDAS).
  • Reliable time source: Time synchronised with reference sources and timestamping units with qualified certificates.
  • Open standard: Timestamps compliant with RFC 3161, verifiable with any standard tool, without depending on us.
  • Two providers: Communication certificates carry timestamps from two qualified providers (Mensatek and the FNMT).
  • Independent audit: Periodic eIDAS conformity audits and supervision by the competent authority in Spain.
  • Custody and verification: Evidence kept for 10 years on our own infrastructure under ISO 27001, publicly verifiable by code.
TIMESTAMP · VERIFICATION
Document hashSHA-256 · computed at source
intact
Mensatek timestamp (qualified)RFC 3161 · eIDAS-audited TSU
valid
FNMT timestamp (qualified)Second, independent provider
valid
Chain of trustEU Trusted List · Spain
verified
10 yearsCustody
EUValidity
CSVPublic verification
How we deliver it

How a piece of evidence is built

The same workflow for a timestamped document, a certified notification or a signed contract.

Capture

The full content (text, attachments, document) is recorded and its cryptographic hash computed.

Timestamping

Each milestone (issue, delivery, reading, signature) receives a qualified timestamp; certificates carry the Mensatek + FNMT double seal.

Certification

The PDF certificate is generated with content, chronology and seals, and electronically signed.

Custody and verification

It is kept for 10 years on our own infrastructure and can be verified publicly by its code.

Typical use cases

What they are used for

LEGAL

Certified notification

Formal demands, claims and communications with legal effect sent by certified SMS or email, with evidence of content and delivery.

CONTRACTS

Remote contracting

Policies, service contracts and consents signed from the phone with an evidence record and qualified timestamps.

DOCUMENTS

Timestamping of documents and records

Quotes, minutes, activity logs and files timestamped to prove their existence and integrity on a date.

IDENTITY

Onboarding with guarantees

Certified identity verification as a prior step to contracting or to accessing regulated services.

COMPLIANCE

Auditable traceability

Audit logs and internal communications with timestamping for audits, GDPR and sector regulations.

SYSTEMS

Embedded evidence

Timestamping and certification built via API into the systems we develop for our clients.

Frequently asked questions

Questions we are usually asked

Is ASETEC a qualified provider?

ASETEC (Mensatek brand) is a trust service provider listed in the European Union Trusted List and issues qualified electronic timestamps under the eIDAS Regulation. You can check the listing in the European Commission's trusted list browser.

What validity does a qualified timestamp have?

It enjoys a legal presumption of accuracy of the date and time it indicates and of integrity of the data to which it is bound (Article 41.2 of eIDAS), and is recognised as such in every Member State.

Why do certificates carry two seals?

Because evidence should not depend on a single party. Certificates are sealed by two qualified trust service providers, Mensatek and the FNMT, so that either one allows independent verification.

How long is evidence kept?

Ten years, on our own infrastructure in Spain under our ISO 27001 certification, with public verification by code and PDF download throughout that period.

Where is the provider's official documentation?

On the Certification Policies & Practices page: practice statement, disclosure statements, timestamping unit certificates, security policy and certificate status validation points.

Related areas

It works better combined

Do you need something to be provable?

Timestamping of documents, certified notifications, signature or identity: tell us the process and we will tell you which evidence it needs and how to integrate it.