PARAMANT
Document signing and encrypted file transfer · Press Kit
About
Paramant is document signing and encrypted file transfer for professional firms in the EU, from Paramantis Solutions B.V. in Harderwijk. ParaSign signs with ML-DSA-65. ParaSend encrypts files on your device, on the authenticated paths with an ML-KEM-768 and ECDH P-256 hybrid, and holds only ciphertext, in RAM. Servers at Hetzner in Nuremberg, Germany.
Paramant has two products on one post-quantum core. ParaSign signs documents with ML-DSA-65 (FIPS 204) and enters every signature in a public, append-only log, so a signed document can be checked later without contacting us. ParaSend encrypts a file on the sender's device before it leaves: the ParaSend web app uses an ML-KEM-768 and ECDH P-256 hybrid, the one-time link path AES-256-GCM with a key made in the browser. For a ParaSend transfer the relay holds only ciphertext, in RAM, and wipes it after the last read the link allows, the first on Community. Sending needs a free account; receiving does not. The Community plan is free, forever: 2 signatures and 50 transfers a month. Organisations pay for higher limits on Firm, including one send to up to 30 named recipients, each with their own one-time link. The servers are at Hetzner in Nuremberg, Germany.
Paramant is a product of Paramantis Solutions B.V. in Harderwijk, the Netherlands, founded by Mick Beer, privacy and security researcher. It is built for professional firms in the EU that sign and send confidential documents.
ParaSign signs documents with ML-DSA-65 (FIPS 204). Every signature is entered into a public, append-only log, and a signed document verifies without contacting us. A ParaSign signature is a Simple Electronic Signature, not a qualified signature under eIDAS.
ParaSend encrypts a file on the sender's device before upload. The ParaSend web app uses an ML-KEM-768 and ECDH P-256 hybrid; the one-time link path uses AES-256-GCM with a key generated in the browser. For a ParaSend transfer the relay holds only ciphertext, in RAM, never on disk, and destroys it after the last read the link allows, which on Community is the first. Sending needs a free account; the person receiving the file needs none.
The Community plan is free, forever, with no card: 2 signatures and 50 transfers a month, one recipient per send. Organisations pay for higher limits. Firm, at 29 euro a month excl. btw, covers both products: 100 signatures and 500 transfers a month, and one send to up to 30 named recipients, each with their own one-time link. Every plan gets the same encryption.
Three external security audits reviewed the relay code in April 2026. Forty findings across three audits, including 4 critical. The Smart Cyber Solutions review is published finding by finding in the April 2026 audit report.
Paramant is not certified under NIS2, NEN 7510 or IEC 62443. It publishes documentation mapped to those frameworks as input for a customer's own compliance process, and signs a data processing agreement under GDPR Article 28. The servers are at Hetzner in Nuremberg, Germany, under EU and German law. The relay is source-available under BUSL-1.1.
Key facts
- Company
- Paramantis Solutions B.V., Harderwijk, the Netherlands · KvK 42115132
- Founder
- Mick Beer, privacy and security researcher
- Products
- ParaSign (document signing) · ParaSend (encrypted file transfer)
- Infrastructure
- Hetzner, Nuremberg, Germany
- Third parties
- Every outside party with its status: /en/partners
- Jurisdiction
- EU / Germany · GDPR · data processing agreement
- Version
- v3.1.0
- Cryptography
- ML-DSA-65 signatures (FIPS 204) · ML-KEM-768 + ECDH P-256 hybrid with AES-256-GCM (FIPS 203)
- Plans
- Community, free forever · Firm, 29 euro a month excl. btw · Enterprise, on request. See pricing
- Recipients
- One per send on Community · up to 30 per send on Firm and Enterprise
- Certification
- None. Framework documentation for NIS2, NEN 7510 and IEC 62443, not a certification
- Audit
- April 2026, three external audits; audit report
- License
- BUSL-1.1, source available; see license
- Contact
- privacy@paramant.app
What makes PARAMANT different
- No plaintext, ever. Encryption happens on your own machine before upload, in Rust compiled to WASM on the hybrid path and in Web Crypto on the link path. The relay cannot read your file, not even under court order, because it never had it.
- Burn-on-read, and a ceiling. A blob is destroyed when the last read its link allows is spent, which on Community is the first one. It is destroyed on a timer too if that read never comes: one hour on Community, twenty-four hours on Firm, seven days on Enterprise. Whichever comes first, an attacker who compromises the relay afterwards finds nothing.
- EU jurisdiction by design. Infrastructure is on Hetzner Nuremberg DE, and no US entity ever holds ciphertext or a key. One sub-processor is American, and the DPA names it: email (only the email address and the invite link, never the document or a key) still goes through Resend Inc. in the United States for now. That is the one exception in the chain; we are moving to a Dutch provider. No CLOUD Act exposure for transfer content. GDPR-compliant by architecture, not by policy.
- One file to a group. On Firm one send reaches up to 30 named recipients, each with their own one-time link. On Community a send goes to one recipient.
- Post-quantum now, not later. ML-KEM-768 (NIST FIPS 203) protects against store-now-decrypt-later attacks. Healthcare data sent today cannot be decrypted by a quantum computer in 2030.
Logo & brand assets
Use PARAMANT brand assets only in editorial/press contexts. Do not modify the logo or use it to imply endorsement without written permission.
SVG available on request: privacy@paramant.app
Screenshots & product images
Compliance
Documentation mapped to NIS2, NEN 7510 and IEC 62443, as input for your own compliance process. Not a certification.
Compliance in docs →Press contact
Email: privacy@paramant.app
Response time: 24 hours (EU business hours)
Available for: product demos, technical briefings, compliance review calls, researcher access