A portable, court-grade claim about a piece of evidence.
Every certificate is a PDF/A-3B container — the ISO archival PDF standard already accepted by courts and regulators — carrying six things: a class-specific human narrative, an embedded canonical JSON payload, a classical Ed25519 signature, a hybrid post-quantum co-signature (all three required), an OpenTimestamps anchor over the fully-signed certificate (which timestamps the signatures, defeating key-compromise backdating), and machine-discoverable XMP metadata. Signing is deterministic, so re-issuing from the same source is byte-identical.
Five classes + two subclasses
Verification
Cryptographic properties of the source evidence only — no judgement. Auto-issued on ingestion; single-signed.
Attestation
A licensed professional's opinion (SOC 2 Type II, ISO 27001, actuarial). Gated on a verified-licence record; fails closed.
Compliance
Satisfaction of a named requirement — SOC 2 TSC, ISO 27001 Annex A, CPS 230, EU AI Act Art. 12, MAS TRM, HKMA.
Coverage
Binds a policy to an evidence hash, predicate-enforced. Invalid the moment its Sovereignty Attestation predicate is revoked or expires.
Custody
Legal hold, chain of custody, deposition readiness — with EDRM/Concordance export for e-discovery.
Receipt & Acknowledgment
Regulatory Receipt (a Custody subclass, for regulatory incident notifications) and Acknowledgment (an Attestation subclass, for board and audit-committee reports).
Nine source documents → five classes
| Source document | Workspace | Certificate(s) |
|---|---|---|
| Control Evidence Package | Auditor | Attestation + Compliance |
| CPS 230 Supervisory Package | Regulator | Compliance (CPS 230 Supervisory Attestation) |
| Underwriting Submission | Underwriter | Quote → Coverage (predicate-enforced) |
| Litigation / Discovery Package | General Counsel | Custody + EDRM export |
| Board / Audit Committee Report | Board | Acknowledgment |
| Regulatory Incident Notification | Regulator | Regulatory Receipt |
| Monthly Attestation Report | Auditor + Underwriter | Monthly Compliance × 2 |
| Completeness Attestation | Automatic | Verification |
| Sovereignty Attestation | Automatic | Verification (Coverage predicate) |
Driven by four professional workspaces — Auditor (control library, evidence mapping, deterministic seeded sampling, partner review, working-paper export), Underwriter (explainable risk model → pricing → policy binding), Regulator / Board, and General Counsel (custody + e-discovery). All nine paths are realisable end to end today.
Two-tier registry
Public existence, private content. Anyone can confirm a certificate exists — its class, status (issued / superseded / revoked / expired), dates, and whether its anchor is confirmed — without ever seeing the content. The source tenant decides who retrieves the full certificate. This is what lets the registry be genuinely public without the confidentiality objection that sinks most transparency designs.
Predicate chains
A Coverage certificate references its Underwriting Submission + Sovereignty Attestation as predicates, enforced at issuance and offline. It goes invalid the instant a predicate is revoked or expires — trust that cannot drift out of date without the verifier noticing.
Expired ≠ forged
The verifier separates cryptographically sound from within its validity window: exit 0 valid, 2 sound-but-expired, 1 invalid. Any tool that reports both as "invalid" misinforms at the worst possible moment.
The escalation from free Verification to a licensed, priced, fail-closed Attestation is the commercial spine — and the free anchor is what makes every paid class meaningful. verify a real artifact →