Install and Pair the Windows Local Signer
Connect an authorized Windows signing session without uploading the certificate private key to Prospect.

The local signer runs on the authorized user's Windows computer and communicates with Prospect through the local bridge. Install it only from the download offered by Prospect.
Open Settings → eFaktura → Signing and download the current Windows installer or portable package.
Install or launch the signer, choose the correct qualified certificate, and keep its PIN private.
In Prospect, start pairing for the intended member and environment. Complete the short-lived pairing in the local application.
Return to Prospect and verify Connected, certificate identity, environment, and last verification time.
Use the outbox signing action while the local signer is running and unlocked.
The private key remains under the certificate provider and local operating environment; do not export or send it to Prospect support. Pair Test and Live deliberately. Remove or revoke a signer when a member changes role or loses authority.
If the bridge is unavailable, confirm the signer is running, the browser is on the expected device, local security software permits the loopback connection, and the selected certificate is valid.