21.08.2026
The trust ecosystem is a walled garden. It’s a good garden, but who gets in and who gets trusted is decided behind the walls. We want an open garden with public rules for entry, where everyone can decide for themselves whether they trust what grows there.
TLDR: The green checkmark on a signed PDF is not actually a property of the signature itself. Behind it sits a trust list deciding which certificates should be trusted. Today, that trust largely comes through established networks that are expensive and difficult to enter. We think there should be an open alternative, built around transparent criteria and merit rather than opaque business relationships. So we want to build the Documenso Trust List.
This is Part 4 of Building Documenso, a series about the infrastructure we’re building behind an open signing ecosystem. In Part 4, I covered our move beyond Simple Electronic Signatures and the path towards native AES.
The green checkmark
One quick reminder before we get into this. A digital signature is created using a certificate issued by a certificate authority. Anyone opening the document can cryptographically verify the signature against that certificate and its certificate chain.
But verifying a signature and trusting who issued the certificate are two different things.
You probably know the green checkmark. You open a signed PDF in Adobe and it tells you that the signature is valid and trusted.
It feels like a pretty objective statement. Either the signature is valid or it isn't.
Cryptographically, that's mostly true. But the trusted part is more complicated.
You can have a perfectly valid cryptographic signature created with a perfectly valid certificate and still have Adobe tell you that it doesn't trust the certificate.
The reason is that someone has to decide which certificate authorities are trusted. And for PDFs, that decision often comes down to a list.

Adobe Acrobat showing a green checkmark for an already trusted Documenso signature.
That last line is the interesting part: Source of Trust obtained from Adobe Approved Trust List (AATL).
Adobe maintains the Adobe Approved Trust List, or AATL. It contains certificate authorities that Adobe has decided to trust. If your signature chains back to one of those certificates, Adobe can recognize it as trusted.
There are good reasons for this. You obviously can't trust every certificate authority someone creates on a random server. Trust has to mean something.
The more interesting question is how you earn it.
How Documenso works today
This is also why documents signed through Documenso Cloud get the familiar trusted status in PDF readers.
We use certificate infrastructure that is already part of the established trust ecosystem. The document can be cryptographically verified and the certificate chain eventually leads back to an authority the PDF reader already trusts.
Self-hosted Documenso is different.
A self-hoster can configure their own signing certificate. If that certificate comes from an authority already trusted by the reader, they can get the same result.
But they can also create and use their own certificate.
Cryptographically, that works. The document can still be signed, sealed and verified. What you don't automatically get is somebody else's stamp of trust.
Your certificate isn't suddenly part of AATL just because it is valid.
This distinction is important because it shows what the green checkmark actually represents. It isn't simply saying that the math checks out. It's also saying that the certificate ultimately comes from an authority this particular piece of software has decided to trust.
Who decides who gets trusted?
Today, the established trust ecosystem is built around organizations that have been part of the certificate business for years. Getting into those networks is complicated, expensive and largely invisible to the people who ultimately rely on them.
Certificates and trust have also become very good businesses. Once your certificates are trusted by software everyone uses, you have something valuable that is difficult for others to reproduce.
That isn't necessarily malicious. Trust networks naturally become more valuable as they grow.
But it does make them very good money printers.
We think there should be an open alternative.
When cryptography isn't enough
This matters because of where we are taking Documenso.
In Part 3, I wrote about going beyond Simple Electronic Signatures and building towards an open signature stack. CSC 2.0 now lets you connect your own certificate authority to Documenso. Native AES is next, including infrastructure that will allow self-hosters to authenticate signers, issue certificates and put the signer's identity directly into the cryptographic signature.
Eventually, you arrive at a slightly absurd situation.
You can run Documenso yourself. You can control the PDF infrastructure, authenticate the signer, operate the certificate authority and issue the certificate. You can cryptographically prove that the document was signed correctly.
Then someone opens the PDF and their software tells them it doesn't trust you.
At that point, the question isn't whether the signature is valid. It's who gets to decide which certificates are trusted in the first place.
An open alternative
Our answer isn't that Documenso should become the new gatekeeper.
We want to build an alternative trust ecosystem that people can choose to participate in.
The Documenso Trust List, or DTL, would be a public list of certificate authorities trusted within the Documenso ecosystem.
In practice, if your certificate is on DTL, an open source PDF viewer could recognize your signatures as trusted without relying on Adobe.
We would start small. Initially, that might simply mean publishing the certificate infrastructure operated by Documenso. As we roll out AES, organizations operating their own certificate authorities could apply to become part of it as well.
An open trust list can't mean that everyone is automatically trusted. If anyone can add a certificate, the list stops meaning anything.
Openness can't mean everyone is automatically trusted. It means the rules for earning that trust are open.
Getting onto DTL should therefore be based on clear, public criteria. Meet the requirements and you can participate. Don't meet them and you can't.
The certificates should be public. The requirements should be public. Changes to the list should be public. Ideally, the reasoning behind those changes should be public too.
Trust should be earned on merit rather than inherited through an opaque business network.
A trust ecosystem you choose
The other important part is that DTL would be voluntary.
We're not interested in replacing one trust network with another one controlled by Documenso.
You can trust Adobe's list. You can trust DTL. Your company can maintain its own list. Software can trust several lists at once.
You decide which trust ecosystems matter to you.
Documenso can then make that decision visible when you inspect a signature. Rather than simply showing a green checkmark, we can show which trust list recognizes the certificate, why it recognizes it and the certificate chain underneath it.
The goal isn't to replace Adobe's green checkmark with a Documenso green checkmark and ask you to trust us instead.
It's to make the infrastructure behind that checkmark visible and give you another choice.
Building trust in the open
The Documenso Trust List doesn't exist yet. Our AES certificate infrastructure comes first because that's what makes something like DTL genuinely useful.
But this is where we want to go.
Our idea of an open signature stack isn't to open the application while leaving every layer underneath it controlled by somebody else. We are making the PDF infrastructure open. We are making certificate infrastructure interchangeable. We are working towards identity and AES infrastructure that you can operate yourself.
Trust is the next layer.
The existing certificate ecosystem has had decades to build networks, relationships and business models around trust. We're not going to recreate that overnight.
But we can offer a different model.
A public list. Public requirements. Trust earned through clear criteria. An ecosystem anyone can choose to participate in and anyone can choose to trust.
That's the Documenso Trust List we want to build.
If you operate certificate infrastructure, work on digital trust, or want to help shape an open alternative, I’d love to talk.
Book a call with me: documen.so/timur
Building Documenso series: Part 1 · Part 2 · Part 3 · Part 4 · Part 5: The Trust Wars

