> For the complete documentation index, see [llms.txt](https://idthrivo.gitbook.io/thrivosign-remote-signing-solution/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://idthrivo.gitbook.io/thrivosign-remote-signing-solution/thrivosign-remote-signing-solution-t-rss-documentation/introduction/compliance-profile.md).

# Compliance Profile

These specifications and standards ensure secure and reliable cloud-based digital signatures, particularly on mobile devices, by defining rules and protocols for Trusted Service Providers (TSPs) and offering technical guidance for secure system implementation. They cover system integrity, data protection, access control, software security, auditability, incident response, legal compliance, and interoperability. Adherence to these guidelines by TSPs ensures that their digital signature services meet stringent security requirements, instilling confidence in the authenticity and integrity of electronic transactions across cloud platforms and mobile devices.

<table><thead><tr><th width="263">Specification</th><th>Description</th></tr></thead><tbody><tr><td>EN 419241-1:2018</td><td>Trustworthy Systems Supporting Server Signing - Part 1: General System Security Requirements</td></tr><tr><td>EN 419241-2:2019</td><td>Trustworthy Systems Supporting Server Signing - Part 2: Protection profile for QSCD for Server Signing</td></tr><tr><td>EN 419221-5:2018</td><td>Protection Profiles for TSP Cryptographic Modules - Part 5: Cryptographic Module for Trust Services</td></tr><tr><td>Cloud Signature Consortium</td><td><a href="https://cloudsignatureconsortium.org/wp-content/uploads/2023/04/csc-api-v2.0.0.2.pdf
">https://cloudsignatureconsortium.org/wp-content/uploads/2023/04/csc-api-v2.0.0.2.pdf</a></td></tr></tbody></table>
