A native macOS application
Sign PDF documents with the certificate on your Czech eObčanka. The key stays on the card, the document stays on your Mac.
Pero adds a signature to a PDF. It never edits the pages, never removes a signature somebody else made, and never sends the document anywhere. The private key never leaves the card — the signing operation happens on the chip, authorized by your QPIN, in the card software's own window that Pero cannot see into.
It produces PAdES signatures that can qualify as a qualified electronic signature under eIDAS when the certificate and the card allow it — and it says plainly when they do not.
Two kinds of connection, both only while signing, neither carrying your document: the time-stamp authority you chose, which receives a hash; and the revocation addresses printed inside the certificates themselves.
There is nothing else. No analytics, no crash reporter, no update check, no account, no upload. Document contents, file names, certificate details and the QPIN are never written to a log.
Before signing Pero says a signature is QES-eligible; after its own checks it says QES expected. It never says a finished file is a qualified electronic signature — that is a judgement for an independent validator, and no successful signing run is evidence of it.
Pero also does not validate signatures a document already carries.