Author: Gorka Oteiza Oruetxebarria
Building trust in cross-border data exchanges, AI-driven document processing and digital legislation
As European public administrations accelerate digital transformation, data security has become a critical challenge. Governments increasingly rely on shared digital infrastructures, automated decision systems, and AI-driven services. Yet these innovations raise an essential question: how can public administrations guarantee the integrity, authenticity and confidentiality of the information they exchange and process?
LANTIK has developed a response to this challenge within GovTech4All. During the first phase of the project (SGA1), the entity created a Security Framework designed to support secure, interoperable, and quantum-resilient digital services across Europe. Now, in GovTech4All 2.0 (SGA2), this framework is essential to enable new digital government solutions.
Why is Security Framework needed?
Public administrations manage highly sensitive information: legal documents, administrative decisions, citizen data, and regulatory rules. As governments digitalise these processes and increasingly exchange information between countries, ensuring trust in digital systems becomes essential.
At the same time, cybersecurity faces a new and growing threat: quantum computing. Algorithms used in many cryptographic systems that secure digital services today are highly vulnerable to attacks by sufficiently powerful quantum computers. This means that data encrypted today could potentially be intercepted and decrypted in the future.
To address these challenges, governments must start adopting post-quantum cryptography (PQC) and stronger mechanisms to guarantee the authenticity and integrity of digital assets.
Ensuring secure exchanges in cross-border data spaces
These challenges were the starting point for Pilot 1 of the first GovTech4All phase (SGA1), led by LANTIK, working together with GRNET and DINUM, and focused on enabling secure cross-border data exchange between public administrations. To address this challenge, LANTIK designed and implemented a Security Framework capable of supporting advanced cryptographic operations while remaining accessible to developers and public sector IT teams.
The framework integrates modern technologies such as post-quantum cryptography (PQC), designed to resist attacks from future quantum computers, and fully homomorphic encryption (FHE), which enables computations to be performed on encrypted data without exposing the
underlying information. These capabilities are built on open-source cryptographic libraries, brought together into a unified and easy-to-deploy solution.
At its core, the Framework packages these cryptographic libraries and their dependencies into a single software module that can be deployed using Docker containers, making it platform-independent and compatible with virtually any server infrastructure. Through a standard API, the framework exposes cryptographic services that can be integrated into applications developed in any programming language, allowing public administrations to implement advanced security mechanisms without requiring specialised cryptographic expertise.
Protecting sensitive information in AI-driven document processing
Pilot 7 of GovTech4All 2.0 (SGA2), led by GRNET, focuses on automating document processing with artificial intelligence (AI) to avoid inefficiencies, risks of errors, and delays in public services caused by manual handling of administrative documents.
The pilot is addressing this challenge by developing a solution that combines several advanced technologies, such as AI and multimodal models, optical character recognition (OCR) and optical mark recognition (OMR), combined with human feedback loops to improve accuracy.
Within this architecture, the LANTIK Security Framework will ensure that the data processed by these systems remains secure, private, and verifiable. By integrating post-quantum encryption and secure data processing mechanisms, the Framework will protect sensitive information throughout the automated document processing pipeline.
Ensuring trust in digital legislation
Another pilot of GovTech4All 2.0, pilot 8, led by GRNET, addresses a different but equally important challenge: the digital transformation of legislation and public policies through citizen-centric rules as code (RaC). This approach aims to translate regulatory frameworks into structured digital formats that can be interpreted and executed by software systems.
While this can significantly improve efficiency and accessibility, it also introduces new risks. When legal rules are represented as digital artefacts, from natural language documents to formal models and executable code, their authenticity, integrity and provenance must be guaranteed.
The Security Framework developed by LANTIK provides the mechanisms needed to support this trust layer. Through cryptographic signatures and integrity verification together with aditional secure encryption, it enables authorities to verify that a rule was authored and approved by the correct authority, that it has not been altered since approval, and that its transformation from legal text to machine-readable format can be traced.
This capability is particularly important for digital rule management systems, legislative editors, and decision-automation platforms, where trust in the rule chain is essential.
Strengthening Europe's digital sovereignty
Beyond the specific pilots, the Security Framework reflects a broader strategic vision that GovTech4All is strongly aligned with: strengthening Europe’s capacity to build secure, interoperable and sovereign digital infrastructures. By developing the framework using open-source technologies and aligning it with worldwide emerging post-quantum cryptography standards, LANTIK contributes to creating a future-proof foundation for public digital services.
The initiative also aligns with Biscay’s quantum innovation roadmap, BIQAIN, which seeks to position the territory as a European reference in the application of quantum technologies within the public sector, fostering collaborations across borders, while maintaining strong commitments to transparency, interoperability and citizen-centered services.
Comments
Hello,
My name is Frederico Laffitte and I am part of [e-Security.BIO], a Portuguese deep-tech cybersecurity startup that has developed an innovative technology to protect public administration entities, armed forces, banks, insurance companies, businesses, and individuals from becoming victims of document forgery crimes — both in the digital and physical world.
Our solution ensures that documents signed with our technology, or with third-party solutions integrated with us, are virtually impossible to forge, preserving integrity and authenticity throughout their entire lifecycle, from digital to paper.
Our platform allows any document, signed or integrated with our technology, to be validated in seconds — even after being printed. Whenever our AI agent identifies tampering or fraud attempts, the platform automatically issues alerts to the signatories and to those validating the document's authenticity.
In simple terms: we make it impossible for anyone to forge, alter, or deny having signed a document — even if that document has been printed. It is like having a digital notary embedded in every signature.
Most remarkably, our technology was designed to continue functioning even in the event of a global network blackout or wartime scenarios.
Given what is described in this publication — particularly the challenges around document authenticity and integrity in cross-border data exchanges, secure AI-based document processing, and the need to guarantee trust in digital legislation — we believe our solution directly aligns with the objectives of the GovTech4All 2.0 (SGA2) pilot projects, specifically Pilot 7 (GRNET) and Pilot 8 (GRNET/LANTIK).
We would very much like to explore how [e-Security.BIO] could collaborate or participate in these pilots — whether as a technology partner, a complementary solution provider, or as an active participant in a future project.
Could you please indicate the process for expressing interest in participating? Is there an open call, a specific point of contact, or a formal application mechanism for European startups and SMEs wishing to join GovTech4All initiatives?
We appreciate your attention and remain available for any further clarification.
Kind regards,
Frederico Laffitte
[e-Security.BIO]