- Shipped
- September 9, 2026 at 10:58 PM UTC
- Author
- Kamo
- Commit
- fcfcfa3
ESigService reports SES and only SES now. eIDAS Article 26 lets a signature call itself ADVANCED only if the signature creation data is something the signatory uses under their SOLE CONTROL, and an emailed link plus a passcode read out of the same mailbox is an authentication factor rather than signature creation data. AES stays in the union because it becomes claimable the day a signer holds their own key; the comment is here so the next person to add a second factor does not read the empty branch as an invitation.