Robust Digital Signature Verification Solution with EU Trusted Lists

Khatim Digital Signature Verification Solution enables organizations to validate digital signatures against Custom or EU Trusted Lists or LOTL, ensuring long-term trust and regulatory compliance. It empowers enterprises to verify the authenticity, integrity, and non-repudiation of digitally signed documents—and the provenance of images and video through C2PA content credentials—both today and years into the future.

  • Ensures compliance with eIDAS & ETSI standards
  • Validates timestamps, revocation status, and certificate chains
  • Verifies post-quantum ML-DSA (FIPS 204) signatures alongside RSA & ECDSA
  • Supports long-term validation (LTV) for archived documents
  • Supports PAdES, XAdES, JAdES, CAdES, ASiC, PKCS#7, PKCS#1, C2PA & more

Why Khatim Verification Server?

Enterprise Focused

Whether integrated with CRMs, ECMs, or ERPs, it delivers rapid and reliable digital signature verification—ideal for high-volume, trust-critical environments.

Fine Grained Control

Get full control over acceptable cryptographic algorithms, giving enterprises precise control over digital signature verification.

Secure Trust Validation

Enforces strict security for certificate chain validation, revocation checking, and trust list management following ETSI & eIDAS standards.

Unified Monitoring

Gain full visibility with real-time & historical signature verification insights across your infrastructure from a centralized dashboard.

Core Features

Features you get from Khatim Verification Server

  • Supported Signature Formats

    Verifies advanced digital signatures based on IETF and ETSI standards including:

    XAdES
    CAdES
    JAdES
    PAdES
    ASiC
    C2PA
    PKCS#1, PKCS#7  signatures formats.

    Performs detailed revocation & PKI trust building checks for all of the certificates found against signer, timestamp, OCSP etc.

  • Combat Deepfakes with C2PA

    Verifies content provenance in images and video using the C2PA specification:

    Content provenance detection
    Digital signature validation
    Certificate chain building
    Revocation checking (CRL/OCSP)
    Manifest integrity verification
    Ingredient analysis (multi-layered edits & sources)

    One policy verifies C2PA alongside XAdES, JAdES, CAdES, PAdES and ASiC. See how this counters deepfakes.

  • Verify EU Trust List & LOTL

    Define multiple verification policies to handle diverse trust and compliance requirements—such as accepted cryptographic algorithms, signature formats, and trust sources including the EU Trust List and List of Trusted Lists (LOTL). This flexibility enables tailored validation for different business applications, document types, and regulatory environments.
  • Cryptographic Agility

    Supporting both RSA and ECDSA with SHA-256, SHA-384, and SHA-512, Khatim Verification Server ensures compatibility with diverse cryptographic standards required for signature verification across industries.
  • Post Quantum Ready Verification

    Khatim Verification Server validates ML-DSA (FIPS 204) signatures at all three security levels—44, 65 and 87—through the same engine and the same policies as RSA and ECDSA. Post-quantum acceptance is set per verification policy, so each application migrates on its own timeline.
  • Quick Developer Integrations

    Khatim Verification Server offers developer-friendly, RESTful APIs for rapid integration with your ECM, CRM, and CMS platforms. All endpoints are secured via TLS client authentication, enabling secure and efficient deployment in minutes.
  • Cross Platform, Diverse Deployments

    Khatim verification server is built with platform independence in mind hence supports Windows and Linux alike. You can deploy in different environments be it on-premise, private or public cloud, VMs or physical machines.
  • Unlimited Scalability

    Designed to handle high-volume signature validations, Khatim Verification Server supports clustered deployment for horizontal scaling. Add verification nodes without disruption to increase throughput and resilience under load.
  • Military Grade Access Control

    Ensure hardened security during administrative operations with AES-256 encryption and strict TLS client authentication—protecting your verification infrastructure from unauthorized access.
  • Admin Friendly GUI

    Manage trust lists, verification policies, and logs through an intuitive web-based interface. From configuring LOTL/TSL sources to reviewing validation results, all admin functions are accessible in one place.
  • Proactive Alerts & Troubleshooting

    If the verification server detects trust failures or signature anomalies, administrators are proactively alerted for swift action. All incidents are logged and can be securely forwarded to central monitoring systems like Splunk, Grafana, Graylog, or LogRhythm.
  • Logging & Auditing

    Every signature verification request is logged with full cryptographic traceability—including certificate chains, CRLs, OCSP responses, timestamps, and trust list sources. Admins can review raw inputs and verification outcomes for diagnostics or audits at any time.
  • Reporting & Statistics

    Gain real-time insight into verification operations across all nodes. Drill down by signature format, algorithm, trust source, policy outcome, or alert status. Daily summary reports provide a clear view of validation success, errors, and trust chain behavior.

How Khatim Verification Server works?

Core Components:

  • Khatim Verification Admin Portal: Access verification configs, transactions & statistics
  • Khatim Verification Engine: Provides Restful digital signature verification services to business apps
  • Khatim Verification Diagnostic: Performs background housekeeping and health checks
  • Storage: Stores configurations and transactional data

Processing Steps:

  • Business application sends a document or media file for verification
  • Verification Engine verifies the incoming request
  • Verification Engine verifies digital signatures and C2PA content credentials
  • Performs revocation checking & PKI trust building
  • Returns the verification response with detailed report

Deployment

  • Supported OS

    All flavors of Windows Server & Linux (Centos, Ubuntu, RedHat, Fedora)

  • Languages

    50+ Languages (English, Chinese, French, Italian Spanish, Arabic, German, Portuguese etc.)

  • Minimum H/W Requirement

    8 GB RAM, 2 vCPU (2.3 GHz), 10 GB disk space.

Words from Client

Leading companies rely on us for their PKI and digital signature needs

We recently had the pleasure of working with the talented team at Codegic to develop an e-signing platform. From the initial consultation to the final delivery, Codegic’s team was attentive to our needs and consistently went above and beyond to ensure the success of the project. Their knowledge of the latest technologies and industry best practices was evident in every aspect of their work, and they were able to deliver a high-quality product that met all of our requirements.”

Calvin Tan,Director, Hiend Software Pte Ltd.

Pricing

  • Khatim Verification Server is charged per bundle
  • Each bundle allows you to deploy 2 instance of verification server in high availability mode
  • To add more servers in your existing pool; Add more bundles OR Buy a single server instance at 50% of the bundle price
  • Test environments or Staging environments are charged 20% of the price

Maintenance Plan

With active annual software maintenance plan:

  • Keep your installation safe and secure with the latest security updates
  • Get free access to the newest features, enhancements, and bug fixes
  • Get premium support from our technical engineers (within 24 hours on business days)

Has your maintenance expired?

Want to renew your maintenance plan? The price for 12 months is 25% of your license’s (current) list price.

Save more with extended supported

  • Extend for 24 months and save 10%
  • Extend for 36 months and save 15% best value

FAQs

Can you list the ETSI standards supported by Khatim Verification Server

Khatim Verification Server suppors the following ETSI standards

  • Digital Signature Formats
    • ETSI EN 319 132 parts 1-2 – XAdES digital signatures
    • ETSI EN 319 122 parts 1-2 – CAdES digital signatures
    • ETSI EN 319 142 parts 1-2 – PAdES digital signatures
    • ETSI EN 319 162 parts 1-2 – Associated Signature Containers (ASiC)
    • ETSI TS 119 182 part 1 – JAdES digital signatures
  • Signature Creation and Validation
    • ETSI EN 319 102-1 – Procedures for Creation and Validation of AdES Digital Signatures
    • ETSI TS 119 102-2 – Extended Procedures for AdES Digital Signatures
  • Signature Policies
    • ETSI TS 119 172-1 – Building blocks and human-readable signature policy documents
    • ETSI TS 119 172-2 – XML format for signature policies
    • ETSI TS 119 172-3 – ASN.1 format for signature policies
    • ETSI TS 119 172-4 – Signature validation policy using trusted lists
  • Trust Lists
    • ETSI TS 119 612 – Trusted Lists specification
    • ETSI TS 119 615 – Use and interpretation of national Trusted Lists (LOTL/TSL)
  • Cryptographic Requirements
    • ETSI TS 119 312 – Cryptographic Suites
  • Certificate & QC Profiles
    • ETSI EN 319 412-5 – Certificate Profiles; QCStatements

Can alerts to be pushed to a central logging system?

For the purpose of traceability, secure alerts can be sent to your central logging systems, such as Splunk, Grafana, Greylog, LogRhythm, and more.

How can we increase the throughput of Khatim verification server?

There are many factor which can boost the performance. This includes:

  • Only allow signature formats which are supported
  • Allow only the acceptable list of encryption & hashing algorithms
  • Deploying multiple load balanced servers instead of a single instance
  • Better internet connection as this improve download of Trusted Lists & revocation checking

How to diagnose why digital signature verification is failing?

Check the verification response and check the reason. You may get multiple errors such as:

    • Signature being tampered
    • Certificates are expired
    • Failing to get revocation information
    • X.509 Certificates are marked as revoked
    • Trust building failing due to missing certificates

What is C2PA?

 C2PA (Coalition for Content Provenance and Authenticity) is an open specification for content provenance. C2PA-compliant tools embed a digitally signed manifest inside an image or video recording who created or edited it, when, and with which tool. Each subsequent edit adds a new manifest, forming a tamper-evident chain of custody. Read more in our blog: Combating Deepfake with Khatim Verification Server with C2PA.

Can Khatim Verification Server detect AI-generated images?

 It verifies whether media carries valid content credentials and what those credentials say about its origin and edit history. Where provenance is present, you get a cryptographically verifiable record of how the file was made. Where it is absent, the server reports that no content credentials were found—which is itself useful signal for editorial and compliance workflows.

Do I need a separate verification policy for C2PA?

No. One policy can handle C2PA alongside XAdES, JAdES, CAdES, PAdES and ASiC. Enable C2PA in your content validation rules, configure trust anchors for the issuers you accept, and submit media over the same REST API you already use for documents.

Which industries need content provenance?

Media and journalism, legal, brand and marketing, defence, healthcare and government—anywhere the origin and integrity of visual evidence carries legal, regulatory or reputational weight.