RFC 3161 · RFC 5816 · Windows / IIS

Your own Timestamping Authority.
Inside your own infrastructure.

TSA Server turns a standard Windows server into an RFC 3161-compliant Time Stamping Authority. Issue trusted timestamps for electronic documents, invoices, reports, signatures and archives — under your keys, on your network, with no per-token fees and no dependency on an external provider.

Lifetime license from 1450 EUR · 60-day money-back guarantee · Current version 7.0

Adobe Acrobat validating a document timestamp signature issued by a TSA: signature valid, document unmodified, LTV enabled, PAdES B-LTA level

Why run the TSA yourself?

Public timestamping services work well — until volume, latency, network isolation or data governance become part of the equation. An on-premise TSA removes all four constraints at once.

Cost model

Unlimited tokens, one license

Timestamp millions of documents, invoices or log entries without metering. The license is perpetual — no subscriptions, no per-timestamp billing, no annual renewals required to keep operating.

Control

Your keys, your policy

The TSA signing key lives in your infrastructure — in an HSM via PKCS#11, or under MS-CAPI / CNG. You define the TSA policy OID, the certificate chain and the time source.

Availability

Works where the internet doesn't

Closed networks, classified environments, factory floors and DMZ segments can all reach an internal TSA endpoint. No outbound connectivity, no third-party SLA on your critical path.

Standards-compliant, drop-in compatible

TSA Server speaks the same protocol every signing tool already understands. Point your existing software at your internal endpoint — nothing else changes.

Protocol & cryptography

  • IETF RFC 3161 and RFC 5816 — ESSCertID and ESSCertIDv2
  • SHA-256, SHA-384, SHA-512 message imprints
  • RSA up to 4096-bit and elliptic-curve TSA certificates
  • HSM support through PKCS#11, plus MS-CAPI and CNG key stores
  • Up to 100 timestamps per second on standard hardware

Works out of the box with

  • Adobe Acrobat — PAdES signatures with LTV / LTA
  • Document management & archiving platforms — sealed documents with provable dates
  • ERP and invoicing systems — via OpenSSL and standard signing libraries
  • Any other RFC 3161 client — including Microsoft Authenticode and Java JarSigner
  • Your existing CA — issue the TSA certificate from your own PKI

What teams run on it

From sealing signed invoices and contracts for long-term validation to anchoring audit logs for NIS2 and DORA compliance — a private TSA becomes quiet, dependable infrastructure.

Signature LTV / LTA

Seal PAdES, CAdES and XAdES signatures so they remain verifiable years after the signing certificates expire.

Invoices & business reports

Give every e-invoice, financial report and contract flowing through your ERP or document system a trusted, verifiable date.

Logs, archives & evidence

Anchor audit trails, electronic archives and incident records to a provable point in time for NIS2, DORA and other compliance programs.

See all use cases in detail →

Evaluate it on your own server today

Download the fully functional package, install it on a Windows / IIS machine and issue your first timestamp in minutes — or try the hosted live demo endpoint first, with nothing to install.