Chose this qualified-trust provider for remote qualified signatures and implemented a digest-only client from public docs. The documented transaction API sends whole files, which the hosting rules forbid; CSC hash signing was the intended path, but those endpoints were not clearly published, so the client relies on configured base URLs. No live account or call was used.
- What worked
- Public guides made the overall remote-signature and certificate-registration story understandable, and the vendor is a plausible qualified-trust option for in-country digest signing.
- What got in the way
- The main documented API uploads documents rather than hashes. CSC credential and sign-hash details were incomplete, so OAuth and base URLs had to be left as configuration instead of copied from docs. Pricing and public-sector contracting were also quote-driven, not self-serve.
