Skip to content
CEI OneCEI One
CapabilitiesHow it worksScreenshotsFAQSupport
RODownload
CapabilitiesHow it worksScreenshotsFAQSecuritySupport

CEI One · Security model of the current release

Security and local control

CEI One starts with a simple rule: the private key stays on the eID, and your document is not uploaded to our servers for signing.

On this pageAuthorized NFC readingSigning on the cardTimestamp and PAdES-LTOnline validationLibrary and iCloudWhat you can do

Authorized NFC reading

The CAN helps establish a secure channel with the card. The data PIN authorizes access to available information. Codes are used in the current session and are not synced to iCloud.

Signing on the card

The cryptographic operation is authorized with the signing PIN and executed with the private key inside the eID. The app receives the signing result, never the private key.

Timestamp and PAdES-LT

For newly signed documents, the app requests a trusted timestamp and can archive certificate chains and OCSP/CRL evidence inside the PDF so long-term validation has the required information.

Online validation

When embedded evidence is insufficient or needs refreshing, the app may contact revocation addresses referenced by certificates. Network access is required for a complete conclusion about current status.

Library and iCloud

The library is local by default. If iCloud is enabled, eligible PDFs and metadata are stored in your private CloudKit database. NFC session data and access codes are excluded.

What you can do

Keep iOS updated, use the correct codes, review every document before signing, protect access to your iPhone, and share PDFs only with the intended recipients.

CEI One

Read your eID. Sign knowingly. Stay in control.

ProductSecuritySupportContact
LegalPrivacyTerms and ConditionsRomână
© 2026 CEI OneIndependent app for the Romanian electronic identity card.