Adobe Approved Trust List

AATL-trusted digital signatures

When a BeeSign document is finalized, it is sealed with a digital signature from a certificate on the Adobe Approved Trust List — so it opens as trusted in Adobe Acrobat and Reader, with no manual trust setup for the recipient.

What is the AATL?

The Adobe Approved Trust List (AATL) is a program run by Adobe that maintains a list of trusted root certificates from vetted certificate authorities. Adobe distributes this list to Acrobat and Reader, so any PDF signed with a certificate that chains to an AATL root is shown as trusted automatically.

In practice, that means the difference between a recipient seeing a reassuring "Signed and all signatures are valid" banner versus a yellow warning asking them to manually decide whether to trust the signer. AATL trust is what makes a digital signature look — and verify — as legitimate out of the box.

AATL trust applies to the document-level digital signature (a cryptographic seal over the whole PDF), which is distinct from the handwritten-style signature a person draws on the page.

How BeeSign delivers AATL-trusted signatures

Issued by an AATL member CA

BeeSign seals finalized documents with a document-signing certificate issued by SSL.com, a certificate authority on the Adobe Approved Trust List.

Chains to an AATL root

The signature embeds the certificate chain — leaf and intermediates — so Adobe can build a path to its trusted AATL root and validate the signature without any recipient action.

Hardware-protected signing key

The signing private key lives in Google Cloud HSM and is non-exportable; the seal is produced inside the HSM, so the key never leaves the hardware boundary.

Tamper-evident by design

The digital signature covers the entire finalized PDF. Any change after signing breaks the seal, so recipients can see immediately if a document was altered.

What the digital seal gives you

  • “Signatures are valid” in Adobe Acrobat and Reader
  • No manual trust configuration for recipients
  • Certificate issued by an AATL member CA (SSL.com)
  • Full certificate chain embedded for validation
  • Signing key held in a FIPS 140-2 Level 3 HSM
  • Whole-document tamper detection

Frequently asked questions

Will BeeSign documents show as trusted in Adobe without extra setup?

Yes. Because the seal uses a certificate that chains to an AATL root, Adobe Acrobat and Reader validate it automatically and show the document as signed with valid signatures — the recipient does not have to manually trust anything.

Is an AATL signature the same as a qualified (eIDAS QES) signature?

No. AATL is Adobe’s trust program for validation in Acrobat/Reader. eIDAS QES is a separate EU legal tier requiring a qualified trust service provider. They are complementary but distinct — an AATL-trusted seal is about how the signature verifies in Adobe, not the eIDAS legal tier.

What is the difference between the seal and a signer’s signature?

The signer’s signature is the mark a person adopts on the page. The AATL seal is a cryptographic digital signature applied to the whole finalized PDF, proving integrity and origin and validating automatically in Adobe.

Where is the signing key kept?

In Google Cloud HSM (a FIPS 140-2 Level 3 validated hardware security module). The key is non-exportable and the signature is generated inside the HSM, so the private key never leaves the hardware.

Compliant from your first document

Every BeeSign plan includes legally binding signatures, tamper-evident audit trails, and a certificate of completion. Start your free trial today.