Tallship /

A native macOS application

Pero

Sign PDF documents with the certificate on your Czech eObčanka. The key stays on the card, the document stays on your Mac.

Download Pero 0.3 Disk image · 4.7 MB · macOS 14+
Universal — Apple silicon and Intel. Signed and notarized by Apple. SHA-256 d682bdee06ae550a0c613268cd94bf8b7c684c9cb698f06ecd697ec1927bd342
What it is

Pero adds a signature to a PDF. It never edits the pages, never removes a signature somebody else made, and never sends the document anywhere. The private key never leaves the card — the signing operation happens on the chip, authorized by your QPIN, in the card software's own window that Pero cannot see into.

It produces PAdES signatures that can qualify as a qualified electronic signature under eIDAS when the certificate and the card allow it — and it says plainly when they do not.

How it works
01
Open and review
Pero works on its own private copy and shows you the pages, the document's SHA-256 fingerprint and every finding before anything is signed. Encrypted files, XFA forms and active content are refused rather than quietly stripped.
02
Plan the signatures
One row per signature: certificate, level, an optional claimed capacity signed exactly as typed, a reason, and a visible rectangle you draw on the page yourself. Several signatures in one pass, in the order you set.
03
Choose a certificate, knowingly
The chooser groups what the card offers by what it can actually be — qualified, advanced, ordinary, or unusable — with the reason behind every verdict. Nothing is ever selected for you.
04
Time-stamp it
PAdES B-B, or PAdES B-T with a time-stamp authority you pick. The authority receives a hash of the signature value and nothing else — never a page, never a name.
05
Confirm, one signature at a time
Each signature gets its own confirmation screen and authorizes exactly one operation on the card. Return does not sign. Anything that changes in between makes the confirmation stale and you see it again.
06
Save a new file
Your original bytes are preserved and the signature is added as an incremental update. Pero refuses to write over the document you opened, and nothing is ever half-written — a failure leaves your file untouched.
What leaves your Mac

Two kinds of connection, both only while signing, neither carrying your document: the time-stamp authority you chose, which receives a hash; and the revocation addresses printed inside the certificates themselves.

There is nothing else. No analytics, no crash reporter, no update check, no account, no upload. Document contents, file names, certificate details and the QPIN are never written to a log.

Honestly

Before signing Pero says a signature is QES-eligible; after its own checks it says QES expected. It never says a finished file is a qualified electronic signature — that is a judgement for an independent validator, and no successful signing run is evidence of it.

Pero also does not validate signatures a document already carries.

What you need
  • macOS 14 or newer, on Apple silicon or Intel.
  • The official eObčanka middleware, installed by you. Pero bundles no card software and needs no Java, no OpenSSL and no PKCS#11 setup.
  • The card in a reader, and its QPIN. Pero never sees the QPIN.
  • A network connection, only if you want a time-stamped signature.
  • Other smart cards and Keychain identities work too, in a clearly labelled non-qualified mode.
  • Pero speaks English and Czech, and every action is reachable from the keyboard.