← Back to constatvault
The certificate model

A portable, court-grade claim about a piece of evidence.

Every certificate is a PDF/A-3B container — the ISO archival PDF standard already accepted by courts and regulators — carrying six things: a class-specific human narrative, an embedded canonical JSON payload, a classical Ed25519 signature, a hybrid post-quantum co-signature (all three required), an OpenTimestamps anchor over the fully-signed certificate (which timestamps the signatures, defeating key-compromise backdating), and machine-discoverable XMP metadata. Signing is deterministic, so re-issuing from the same source is byte-identical.

Five classes + two subclasses

Free · the anchor

Verification

Cryptographic properties of the source evidence only — no judgement. Auto-issued on ingestion; single-signed.

Dual-signed

Attestation

A licensed professional's opinion (SOC 2 Type II, ISO 27001, actuarial). Gated on a verified-licence record; fails closed.

Framework

Compliance

Satisfaction of a named requirement — SOC 2 TSC, ISO 27001 Annex A, CPS 230, EU AI Act Art. 12, MAS TRM, HKMA.

Insurance

Coverage

Binds a policy to an evidence hash, predicate-enforced. Invalid the moment its Sovereignty Attestation predicate is revoked or expires.

Subclasses

Receipt & Acknowledgment

Regulatory Receipt (a Custody subclass, for regulatory incident notifications) and Acknowledgment (an Attestation subclass, for board and audit-committee reports).

Nine source documents → five classes

Source documentWorkspaceCertificate(s)
Control Evidence PackageAuditorAttestation + Compliance
CPS 230 Supervisory PackageRegulatorCompliance (CPS 230 Supervisory Attestation)
Underwriting SubmissionUnderwriterQuote → Coverage (predicate-enforced)
Litigation / Discovery PackageGeneral CounselCustody + EDRM export
Board / Audit Committee ReportBoardAcknowledgment
Regulatory Incident NotificationRegulatorRegulatory Receipt
Monthly Attestation ReportAuditor + UnderwriterMonthly Compliance × 2
Completeness AttestationAutomaticVerification
Sovereignty AttestationAutomaticVerification (Coverage predicate)

Driven by four professional workspaces — Auditor (control library, evidence mapping, deterministic seeded sampling, partner review, working-paper export), Underwriter (explainable risk model → pricing → policy binding), Regulator / Board, and General Counsel (custody + e-discovery). All nine paths are realisable end to end today.

Two-tier registry

Public existence, private content. Anyone can confirm a certificate exists — its class, status (issued / superseded / revoked / expired), dates, and whether its anchor is confirmed — without ever seeing the content. The source tenant decides who retrieves the full certificate. This is what lets the registry be genuinely public without the confidentiality objection that sinks most transparency designs.

Predicate chains

A Coverage certificate references its Underwriting Submission + Sovereignty Attestation as predicates, enforced at issuance and offline. It goes invalid the instant a predicate is revoked or expires — trust that cannot drift out of date without the verifier noticing.

Expired ≠ forged

The verifier separates cryptographically sound from within its validity window: exit 0 valid, 2 sound-but-expired, 1 invalid. Any tool that reports both as "invalid" misinforms at the worst possible moment.

The escalation from free Verification to a licensed, priced, fail-closed Attestation is the commercial spine — and the free anchor is what makes every paid class meaningful. verify a real artifact →