RFC 3161 · RFC 5816 · Windows / IIS
Your own Timestamping Authority.
Inside your own infrastructure.
TSA Server turns a standard Windows server into a fully compliant RFC 3161 Time Stamping Authority. Issue trusted timestamps for electronic documents, invoices, reports, signatures and archives — under your keys, on your network, with no per-token fees and no dependency on an external provider.
Lifetime license from 1450 EUR · 60-day money-back guarantee · Current version 7.0
Why run the TSA yourself?
Public timestamping services work well — until volume, latency, network isolation or data governance become part of the equation. An on-premise TSA removes all four constraints at once.
Cost model
Unlimited tokens, one license
Timestamp millions of documents, invoices or log entries without metering. The license is perpetual — no subscriptions, no per-timestamp billing, no annual renewals required to keep operating.
Control
Your keys, your policy
The TSA signing key lives in your infrastructure — in an HSM via PKCS#11, or under MS-CAPI / CNG. You define the TSA policy OID, the certificate chain and the time source.
Availability
Works where the internet doesn't
Closed networks, classified environments, factory floors and DMZ segments can all reach an internal TSA endpoint. No outbound connectivity, no third-party SLA on your critical path.
Standards-compliant, drop-in compatible
TSA Server speaks the same protocol every signing tool already understands. Point your existing software at your internal endpoint — nothing else changes.
Protocol & cryptography
- IETF RFC 3161 and RFC 5816 — ESSCertID and ESSCertIDv2
- SHA-256, SHA-384, SHA-512 message imprints
- RSA up to 4096-bit and elliptic-curve TSA certificates
- HSM support through PKCS#11, plus MS-CAPI and CNG key stores
- Up to 100 timestamps per second on standard hardware
Works out of the box with
- Adobe Acrobat — PAdES signatures with LTV / LTA
- Document management & archiving platforms — sealed documents with provable dates
- ERP and invoicing systems — via OpenSSL and standard signing libraries
- Any other RFC 3161 client — including Microsoft Authenticode and Java JarSigner
- Your existing CA — issue the TSA certificate from your own PKI
What teams run on it
From sealing signed invoices and contracts for long-term validation to anchoring audit logs for NIS2 and DORA compliance — a private TSA becomes quiet, dependable infrastructure.
Signature LTV / LTA
Seal PAdES, CAdES and XAdES signatures so they remain verifiable years after the signing certificates expire.
Invoices & business reports
Give every e-invoice, financial report and contract flowing through your ERP or document system a trusted, verifiable date.
Logs, archives & evidence
Anchor audit trails, electronic archives and incident records to a provable point in time for NIS2, DORA and other compliance programs.
Evaluate it on your own server today
Download the fully functional package, install it on a Windows / IIS machine and issue your first timestamp in minutes — or try the hosted live demo endpoint first, with nothing to install.