generated: '2026-07-25' method: searched source: >- https://trustservices.swisscom.com/en/esignature-hub/downloads-and-documents ; https://sign.swisscom.ch/docs/guide/authentication ; openapi/swisscom-sign-integration-api-openapi.json ; openapi/swisscom-all-in-signing-service-openapi.yml ; https://www.gsma.com/solutions-and-impact/gsma-open-gateway/ standards: - id: oauth2 conforms: true evidence: >- OpenAPI securityScheme type oauth2 (clientCredentials) on the Swisscom Sign Integration API; authorization-code/implicit/client-credentials documented for the api.swisscom.com gateway at consent.swisscom.com. - id: oidc conforms: true evidence: >- Live Keycloak discovery document at https://sign.swisscom.ch/realms/swisscom-public/.well-known/openid-configuration (saved to well-known/swisscom-sign-openid-configuration.json). - id: rfc8414-oauth-authorization-server-metadata conforms: partial evidence: >- The Keycloak realm serves openid-configuration but no /.well-known/oauth-authorization-server document was found on any Swisscom host. - id: rfc9116-security-txt conforms: true evidence: https://www.swisscom.ch/.well-known/security.txt (saved to well-known/swisscom-security.txt) - id: rfc9457-problem-details conforms: false evidence: >- Neither API uses application/problem+json. Swisscom Sign returns a custom Error object (id/timestamp/name/message/path/httpStatus/clientSubject/clientBody); the api.swisscom.com gateway returns a custom uuid/status/code/message/detail object. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support documented or present in either spec. - id: openapi-3 conforms: true evidence: >- OpenAPI 3.1.0 served live at https://sign.swisscom.ch/system/api-docs; OpenAPI 3.0.1 for the All-in Signing Service ETSI interface published on the SwisscomTrustServices GitHub org. - id: etsi-ts-119-432 conforms: true evidence: >- The All-in Signing Service REST interface implements the ETSI TS 119 432 remote signature creation profile; the request carries profile http://uri.etsi.org/19432/v1.1.1#/creationprofile#. - id: etsi-ades-baseline conforms: true evidence: >- signDoc accepts conformanceLevel values in the AdES-B-* family (for example AdES-B-LT) and returns SignatureObject with OCSP/CRL validation info for long-term validation. - id: eidas conforms: true evidence: >- Swisscom is an accredited qualified trust service provider under EU Regulation eIDAS; certificate of conformity issued by the supervisory authority KPMG and listed on the EU/EEA trusted list. - id: zertes conforms: true evidence: >- Swisscom is a qualified certification service provider under the Swiss federal signature act ZertES; certificate of conformity issued by KPMG and listed by OFCOM. - id: adobe-aatl conforms: true evidence: Swisscom is an Adobe Approved Trust List (AATL) member. - id: gsma-open-gateway conforms: partial evidence: >- Swisscom was one of the 21 founding signatories of the GSMA Open Gateway Memorandum of Understanding (February 2023), but publishes no CAMARA API definition, no Open Gateway developer portal and no callable network-API endpoint of its own. - id: camara conforms: false evidence: No CAMARA API (Number Verification, SIM Swap, Device Location, QoD) is published by Swisscom. - id: json-api conforms: false evidence: Plain JSON resource representations; no JSON:API media type or envelope. - id: odata conforms: false - id: scim2 conforms: false - id: fhir-r4 conforms: false - id: fapi conforms: false evidence: No FAPI profile, PAR/DPoP requirement or mTLS-bound token claim is documented for the public APIs. - id: psd2 conforms: false - id: asyncapi conforms: false evidence: >- Webhook callbacks are documented in prose for SMS delivery notification but no AsyncAPI document is published — see asyncapi/swisscom-messaging-webhooks.yml. - id: pagination conforms: true evidence: >- GET /api/process implements page/size/sort with a ProcessPage envelope and PageMetadata (totalElements, totalPages, size, number). - id: idempotency conforms: partial evidence: >- No idempotency-key header or parameter exists on any Swisscom API. The one documented idempotent write is POST /api/process/{processId}/release, which returns 208 Already Reported with the same permanently-valid participant URLs on repeat. - id: mutual-tls conforms: true evidence: The All-in Signing Service is authenticated with a client certificate issued under contract. compliance_program: published: true url: https://trustservices.swisscom.com/en/esignature-hub/downloads-and-documents supervisory_auditor: KPMG certifications: - name: Qualified certification service provider (ZertES) scheme: ZertES (Swiss federal signature act) evidence: Certificate of conformity from the supervisory authority KPMG (PDF), published on the downloads page. - name: Qualified trust service provider (eIDAS) scheme: EU Regulation 910/2014 (eIDAS) evidence: Certificate of conformity from the supervisory authority KPMG (PDF), published on the downloads page. - name: Remote signature issuance conformity (ZertES) scheme: ZertES evidence: Certificate on the conformity of the remote signature from the supervisory authority KPMG (PDF). list_memberships: - EU/EEA trusted list - OFCOM list of providers of certification services in Switzerland - Adobe Approved Trust List (AATL) not_found: - SOC 2 - ISO 27001 (no public certificate published for the API/trust-services surface) - PCI DSS - HIPAA - FedRAMP note: >- Swisscom's published compliance posture is trust-service accreditation, not a general-purpose SaaS trust center. No SOC 2 or ISO 27001 certificate is published on the Trust Services or Digital Marketplace surfaces; regulated-sector documentation (FINMA, AML) sits in the partner area.