COMPLIANCE & PUBLIC REPOSITORY

TRUST CENTER

A public repository of the legal framework, certification practices and cryptographic standards governing Trustvestor’s infrastructure as a candidate for a Qualified Trust Service Provider (QTSP) under eIDAS 2.0

Roadmap to QTSP Certification

Strategic milestones towards full compliance with ETSI EN 319 401

Architecture

Specification of the OpenZKA protocol and integration with local HSM modules (Sovereign Cloud)

Drafting

Formulation of CP/CPS documentation for issuing Qualified Electronic Attestations (QEAAs).

Pre-Audit

Preliminary audit by an independent Conformity Assessment Body (CAB)

Trusted List

Official entry in the National Trust List as a QTSP

Public Document Repository

Certificate Policy (CP)

Policy for issuing Qualified Electronic Attribute Attestations (QEAAs) under eIDAS 2.0.

Certification Practice Statement (CPS)

Statement of operational practices for attribute lifecycle management and ZKP oracles.

Acceptable Use Policy (AUP)

Terms of Use applicable to Relying Parties and integrators of ARF-compliant wallets.

Vulnerability Disclosure

Procedures for Responsible Disclosure of vulnerabilities by independent researchers.

Sovereign Cloud & HSM

The infrastructure operates exclusively within the EU, using local Hardware Security Modules (HSMs), eliminating jurisdictional risk

PQC Readiness

Integration of ML-KEM/Kyber standards (NIST FIPS 203) to protect the archival AMLR period against future quantum threats

GDPR Risk Isolation

A mathematical zero-knowledge proof (ZKP) that ensures that Trustvestor never stores the subject's data on a central server