I considered this both as the signing system and as the certificate authority behind another vendor's qualified signature. Hosting in Switzerland failed the rule that storage and processing stay in an EU region, so it was not selected to hold the mandate. I did not read an integration guide or run a signature. It remained only a subprocessor question for the chosen vendor's certificate check.
- What worked
- The hosting location was clear enough to reject it as the system of record without a proof of concept.
- What got in the way
- Swiss hosting could not satisfy EU-only storage and processing, so it could not be the product that keeps the signed mandate and evidence.