Security Report
Belgian eID signing in Nitro Sign Enterprise Verified: Security Report
Last updated: August 10, 2026
In early 2026, as part of our bug bounty program, an independent security researcher reported vulnerabilities in the browser extension and local signing component that enable Belgian eID signing in Nitro Sign Enterprise Verified and identification in Identity Service. We investigated, developed fixes, and a series of remediations were deployed, with the final hardening enforced in production in July 2026. The vulnerabilities are now resolved.
We found no evidence that any of these vulnerabilities were exploited. The vulnerabilities were reported to the Centre for Cybersecurity Belgium, and we coordinated closely with them throughout the process.
Customers running current versions are protected. The fixes are distributed automatically through the Nitro plugin installer, which delivers the updated SignID component and the current browser extensions. Any customer running an older on-premise deployment can contact our team at service@gonitro.com for assistance in confirming they are up to date.