The use of digital certificates for the electronic signing of documents and interaction with online portals has become the cornerstone of modern corporate operations. However, traditional management methods using physical tokens and shared passwords lead to operational inefficiencies and pose serious risks to organisations operating under this model.
So, is it possible to sign documents without the need for physical devices, from anywhere, and without requiring a local installation? The answer is yes, through centralised signing.
In this article, we analyse what a cloud-based certificate is, how it protects your organisation’s assets using HSM technology, and how centralised signing drives a secure, agile and scalable digital transformation.
What is centralised signing?
Centralised signing refers to a form of electronic signature in which the digital certificate is stored securely in the cloud on an HSM server. This means it can be used just as efficiently from any location or device, without the need to install it on every device where it is to be used.
However, due to the high levels of security in place, accessing the digital certificate requires two-factor authentication, which may take the form of:
- A password
- A verification code sent by SMS or email
- Some form of biometric data that unambiguously identifies the holder (iris scan, voice recognition, biometric signature, fingerprint, etc.)
Is a centralised signature legal?
The eIDAS Regulation, the most robust and modern regulatory framework in Europe, sets out three types of electronic signature for signing agreements digitally. All are legally binding, although some offer a higher level of security.
For this reason, we focus on the one that, from the outset, offers an acceptable level of security: the centralised signature with a certificate. This is a 100% secure option that allows the signatory to be identified unequivocally and which, in turn, is impossible to forge.
4 advantages of the centralised signature for the signatory
- Adaptable to any business. The centralised signature, supported by eIDAS, enables and validates any global transaction requiring the signature of any of the parties
- Multi-device and user-friendly. Your company’s certificates are hosted in a highly secure cloud (HSM), so users can carry out procedures and sign documents from anywhere and on any device
- Reduced costs and paperwork. Thanks to the centralised certificate, costs arising from manual and paper-based processes are avoided, which eliminates unnecessary travel and, consequently, contributes to a more sustainable environment
- Enhanced security. Thanks to our robust authentication system and the ability to verify the origin of each document, we can identify the user unequivocally. Furthermore, centralised signing with a certificate ensures that documents cannot be altered at a later date.
Why the centralised certificate is the security standard for organisations
Beyond the significant competitive advantages offered by centralised signing, the key benefit of this signing method lies in the protection of assets. By centralising digital certificates, we eliminate the vulnerability posed by having private keys scattered across multiple computers or mobile devices.
Below, we detail the different layers of technical and operational protection offered by this method:
Enhanced security
Digital certificates are stored in HSMs, devices specifically designed to protect cryptographic keys and sensitive operations against physical and logical threats, including attempts to tamper with or extract keys. Consequently, the security of the associated private key is strengthened, as the HSM provides a secure and isolated environment for key storage.
Prevention of cloning
HSMs generally incorporate features that make it difficult or impossible to clone keys. This mechanism protects against the unauthorised duplication of certificates and reinforces the authenticity of the digital identity associated with the certificate.
Prevention of data breaches
The risk of keys being compromised or stolen is reduced, helping to prevent data breaches and ensuring the integrity and confidentiality of digital certificates.
Auditing
Every operation carried out using a centralised digital certificate is recorded in detail within the system. This makes it much easier to monitor and analyse events relating to key and certificate management.
Scalability
A cloud-based solution allows capacity to be easily adjusted according to requirements. For example, a company that initially had around 5 or 10 certificates and which, due to various circumstances, subsequently sees this number increase exponentially will have no problem increasing the number of certificates in the cloud.
Ease of implementation and management
Implementing and managing centralised certificates in the cloud is quicker and simpler than managing them on each individual user’s device, which leads to reduced maintenance costs.
Collaboration and resource sharing
The cloud facilitates collaboration between teams and the sharing of resources, which is particularly useful when several parties need to access and manage digital certificates collaboratively.
Control and manage your certificates with Viafirma
As part of its range of digital solutions, Viafirma offers a tool designed for corporate environments, capable of storing, controlling and delegating the use of digital certificates to third parties: the digital certificate manager. This tool complies with current regulations and can also be integrated via API with any of your corporate tools.
Your company’s certificates will never be stored on your device, but will instead be hosted in an ultra-secure cloud, accessible from any device and location, so that you can sign documents and carry out procedures online from any device, without the need for local installation.
The certificate and its private keys are securely stored in an HSM (Hardware Security Module), a device designed to manage and safeguard sensitive data, ensuring maximum security, encryption and confidentiality.



