Whitelabel licensing
Qualified electronic signature platform licensed under your brand
Tvarka Sign is a qualified electronic signature platform for the Lithuanian market. It is available for licensing under your organization's brand and, where security policy requires it, for deployment and operation within your own infrastructure. The client relationship, the documents and the audit trail remain with your organization. Development, updates and support are provided under contract.
Your brand
The portal, signing pages, notification messages and the visible signature stamp carry your organization's identity on your domain.
Your infrastructure
The platform is deployed on your servers. Documents, storage, the audit log and signature validation remain within them.
Maintained platform
Signing functions, document formats, the validation service and the API are maintained, updated and supported under contract.
Three deployment models
The API contract is identical in all three models. An integration developed against the hosted service operates without modification following a transfer to your own infrastructure.
| Model | Location of documents | Operated by | Applicable to |
|---|---|---|---|
|
Your infrastructure The platform is licensed and installed on your servers under your organization's brand. |
Your servers, under your sole control | Your operations team. Installation, updates and support are provided under contract | Institutions whose security, continuity or regulatory requirements preclude the use of an external service |
|
Dedicated instance A single-tenant deployment carrying your brand, isolated from all other clients. |
EU servers you nominate | SocAlg, under an agreed service level | Organizations requiring tenant isolation without operating the platform themselves |
|
Hosted API Your systems call the signing API. Signers are presented with your organization. |
Provider infrastructure within the EU | SocAlg | Integration, evaluation, and production use where hosting location is not a constraint |
Components within your infrastructure and external services
Qualified signing involves external trust services in every deployment model. The distinction of an on-premise licence is the extent of the platform that operates within your own infrastructure.
Within your infrastructure
Installed, branded and operated by your organization.
- Signing portal and signing pages
- Signing API, webhooks and the integration surface
- Document format engine: PAdES, ADOC family, ASiC-E
- Signature validation service
- Document storage, versions and audit log
- Database, background workers and administration
- Identity card signing over NFC and USB tokens
External qualified services
Provided by qualified trust service providers.
- Smart-ID and Mobile-ID signing sessions
- Qualified timestamps
- Certificate revocation data and EU trusted lists
- Mail server for notifications
Signing with the national identity card completes between the card, the platform and the timestamp authority. The private key does not leave the card.
Platform functions
Signing methods
Smart-ID, Mobile-ID, LT ID, USB tokens, and the national identity card read by a mobile device over NFC without additional reader hardware.
Document formats
PAdES B-LT with a visible signature stamp, the ADOC family including the public-sector profiles, and ASiC-E containers. Signatures already present on an imported document are preserved.
Regulation (EU) 2026/248 formats
All five referenced signature formats are produced: PAdES, XAdES, CAdES, JAdES and ASiC-E containers. Each has been verified at Baseline level against the European reference validator.
Signature validation
Validation operates within the deployment. Verification of documents produced by the platform and by third parties is unlimited and requires no external service.
Signing API
Multi-signer workflows with sequential or parallel ordering, invitations, reminders, deadlines, and authenticated callbacks to your systems. See the Sign API documentation.
Signing without registration
An external counterparty receives a link and signs in Lithuanian or English. No account, registration or software installation is required.
Client software under your brand
Android and iOS applications for identity card signing by mobile device, and a workstation component for USB tokens, published under your organization's identity.
European Digital Identity readiness
Wallet support is implemented as a relying-party capability and is delivered to existing deployments through the standard update channel following its introduction.
Control and continuity
An on-premise licence includes the following terms:
- Documents remain under your control. Storage, signatures, validation and the audit log remain within your infrastructure. Under the GDPR your organization is the controller and the host.
- No remote disablement. The platform contains no licence server, activation call, or mechanism by which it can be deactivated from outside your infrastructure.
- No external metering. Usage is confirmed by annual declaration. The deployment transmits no usage data.
- Continuity provisions. Source code escrow with defined release conditions, and a perpetual right to operate the version installed.
- Updates subject to your approval. Releases and security patches are delivered through an agreed channel and applied on your schedule.
- No per-employee or per-use licensing. Users, administrators and external signers are unlimited, as is signature validation.
External provider costs
Smart-ID and Mobile-ID signing sessions carry a per-signature cost charged by the identity provider. Signing with the national identity card carries no external provider cost.
Evaluation material
The following material is provided to security, legal and procurement reviewers in advance of any commitment.
- Deployment architecture – components, data flows, network egress and external dependencies
- Reference platform specification – supported operating systems, runtime versions and sizing guidance
- Acceptance protocol – written test procedure covering each signing method, completed before go-live
- Security documentation – key handling, PIN flow boundaries, audit logging and data retention
- Draft legal terms – licence grant, escrow, support levels and continuity provisions
- Operational runbooks – backup, restore and upgrade procedures
Implementation phases
Scoping
Signing scenarios, volumes, security requirements and the integration surface are documented and resolved into a deployment design.
Installation and branding
The platform is deployed in your environment and your organization's identity is applied to the portal, signing pages, notifications and signature stamps.
Acceptance
Integration with your systems, followed by testing of each signing method under the written acceptance protocol.
Operation
Releases, security patches and support at the agreed service level. Regulatory and format changes are tracked by SocAlg.
The platform is deployed as the same containerized stack that operates in production, and initial deployment is measured in weeks.
Organizations providing signing to others
Financial institutions
Execution of agreements within your own channels and under your own brand, without documents transiting a third party.
Public-sector bodies
Deployment within your own infrastructure, contractual continuity provisions, and the ADOC family formats used in public-sector document exchange.
Large service organizations
Signing by large client populations within your existing systems, without an intermediary between your organization and its clients.
Software vendors
Qualified signing integrated into your product through the API and presented to users as your own functionality.
Frequently asked questions
Does operating the platform require a licensed or supervised status?
No. The platform is signature creation and validation software. The qualified elements, being the signers' certificates and the qualified timestamps, are provided by qualified trust service providers. No additional status attaches to the organization operating the deployment.
Which components remain outside our infrastructure?
Smart-ID and Mobile-ID signing sessions, qualified timestamps, and certificate revocation and trusted-list data are obtained from external qualified providers, as is the case for any platform in this market. Signing with the national identity card involves no external per-signature service.
How are updates handled in an on-premise deployment?
Releases and security patches are published through an agreed channel and applied subject to your approval and on your schedule. The current and preceding versions are supported, and the reference platform is defined contractually so that support obligations are unambiguous.
What happens to the deployment if the contract ends?
Your organization retains a perpetual right to operate the version installed at that point. Updates and support cease; operation of the software does not. No mechanism for remote deactivation exists, and this is warranted contractually as well as stated technically.
Can existing systems be integrated?
Yes. The signing API with authenticated callbacks is the same contract in every deployment model, so integration work carries over without modification between them. The documentation is public and available before any commercial discussion.
How is the offering priced?
Pricing follows the deployment model, the volume band and the optional modules. Hosted use is billed according to actual usage; licensed deployments carry an annual licence and maintenance fee. A scoping discussion is sufficient for a written proposal to be issued.