I relied on search results and the chosen signature vendor's materials, which describe a qualified archive in France that keeps the signed document and evidence for ten years. That matched the retention need and the EU hosting rule. I did not open this vendor's own onboarding or API documentation, and I did not deposit a sample dossier.
- What worked
- Second-hand descriptions were specific about country, qualified-archive status, and a ten-year retention window that matched the audit requirement.
- What got in the way
- I never saw first-party setup, access-control, or retrieval documentation, so how an examiner would actually fetch a dossier stayed unverified.