IT in notary office: Between sealing wax and zero trust

How the IT support of a notary differs from that of a normal office
Read the article
Read the article
back
back

IT in notary office: Between sealing wax and zero trust

Author
Philipp Krey
Time to read
7 mins
Published
March 2026

A notary in Berlin called us last year because his notary assistant had not been able to submit a registry application for two hours. The error message was meaningless; the previous IT service provider had recommended restarting the router over the phone. She had. Three times. The problem wasn't a router. The certificate for the VPN tunnel to the notary network had expired three days earlier, and no one had the date on the calendar.

For a scheduled GmbH registration, this is not just annoying.

We hear stories like this more often since we started servicing notary offices. The common denominator is almost always the same: The IT service provider knows Windows, knows Office, may still know Exchange. But XNP, qualified electronic signatures, notary network? He's never heard of that before. And why should he. It's a world that doesn't exist anywhere else.

Three things that distinguish a notary's office from an office

The notary network is the most obvious. XNP connects the notary office with the Federal Chamber of Notaries, with the commercial and association registers, with electronic legal transactions. The connection runs via VPN tunnels with specific parameters and certificates with a fixed runtime. If a certificate expires, the connection is completely terminated. No partial failure, no workaround. All electronic legal transactions are stopped. Register applications, transmission of documents, everything.

With normal VPN access to the company network, this can be resolvedthe next working day. Not in the case of a registry application with a deadline.

Then the qualified electronic signatures. The combination of signature card, card reader and software sounds simple in theory. In practice, every card reader manufacturer has its own driver versions, and a Windows update can ensure that the signature that worked yesterday no longer works in the morning. We have experienced this several times, and each time the first suspicion was a signature card defect. It never was. It was always a driver issue after an automatic update.

If the signature card itself expires because the application for the new one was initiated too late, electronic legal transactions come to a standstill. The lead time for a new card is several weeks.

And finally the data. A notary's office contains wills, real estate sales contracts, articles of association, marriage contracts, inheritance contracts, and pension powers of attorney. This is a different category than customer lists or project data. Becoming aware of a single document can have financial and personal consequences that cannot be repaired. The duty of confidentiality results directly from the Federal Notary Code. It is not negotiable, it is not graduated, it is absolute.

What is currently changing?

Video certifications have been possible since DiRUG. The creation of a digital GmbH via video conference is already happening. Stable bandwidth, encrypted transmission, audit-proof recording. Requirements that many notary offices do not cover with their existing infrastructure. At a notary's office, we saw that the first video notarization attempt failed due to an asymmetrical DSL line whose upload was insufficient for stable video transmission. This is not noticeable in daily work, because emails and registry traffic require little upload. A video conference is different.

The Federal Chamber of Notaries is constantly updating XNP. New interfaces, changed security requirements, occasionally changed configuration parameters. After an XNP update, the local configuration must be checked and adjusted if necessary. If you don't, you'll notice it the next time you try to connect.

The data protection supervisory authority has begun to pay more attention to liberal professions. Until now, notary offices have rarely been audited. A draft contract sent unencrypted by e-mail, a lost USB hard drive, access via an unsecured WLAN in the meeting room. It's all happened before. The consequences go beyond fines.

What must be available?

We do not support the specialist application, that is the responsibility of the manufacturer. We maintain the platform below. On the infrastructure level, by the way, the systems are more similar than the manufacturers say: They all need a high-performance database, a clean network, and a functioning backup. The specific differences lie in the application layer, not in the infrastructure.

A business firewall. A non-negotiable Guest WiFi in the meeting room and notary network in the same segment is a security incident that just hasn't happened yet. Network segmentation separates what belongs separately.

Backup with offsite copy and restore test. A loss of data in a notary's office is relevant under professional law. Daily backup, encrypted copy offsite, and regularly check whether the data can actually be restored. A backup that has never been tested is a hypothesis.

And someone who keeps track of runtimes. VPN certificate for XNP, signature card, SSL certificate from the law firm website, TLS certificate from the mail server. Each has an expiration date. None of them announce themselves. If no one maintains a list, the problems will come on time.

DaPhi

We support IT for industries where outages not only disrupt operations, but also paralyze them. Hotels, medical practices, retirement homes. And this includes notary offices. We have daily experience with VPN configurations, certificate management, network segmentation, and operating sensitive infrastructures. Hardware, software and licenses via DaPhi. From the firewall to the signature card, from the Microsoft license to the card terminal.

FAQ

What IT equipment does a notary office need? Notary software server, business firewall with segmentation, VPN connection to the notary network, qualified electronic signature, backup with offsite copy, monitoring for certificate runtimes and backup status.

What happens when the XNP certificate expires? Access to the notary network is interrupted, resulting in register applications, transmission of documents and electronic legal transactions until a new certificate is configured.

Does DaPhi maintain AnnoText or Notar.plus? We support the infrastructure including: server, database, network, backup. In the event of faults, we clarify whether the problem is at the infrastructure or application level and coordinate with the manufacturer.

Which IT security requirements apply specifically to notary offices? The Federal Notaries Act requires confidentiality to be protected. Technical: Encryption, access controls, segmentation, documented processes. Plus GDPR.

What does a notary's office need technically for video certifications? Stable line with sufficient upload, camera and microphone of suitable quality, encrypted transmission, software that meets legal recording requirements.

Can an IT service provider without specializing in notarial services support a notary's office? The IT infrastructure yes. server, network, firewall, backup. The notarial-specific components, XNP connection, signature cards, certificate management, require familiarization.

Can we purchase hardware and licenses via DaPhi? Yes Servers, firewalls, Microsoft licenses, security software, signature cards, card terminals. Procurement, configuration, management.

Photo by Pixabay and Cottonbro Studio