Security you can audit.
Proof you can verify.
certify's cryptographic architecture makes credential fraud mathematically impossible. Every claim is independently verifiable without trusting our servers.
5-layer cryptographic security
Each layer independently prevents a different class of forgery. A compromised verifier, network, or even our own servers cannot produce a valid credential.
Institutional Key Signing
Every credential is signed with the issuing institution's Ed25519 private key, stored in a FIPS 140-2 Level 3 Hardware Security Module (HSM). Private keys never leave the HSM — all signing happens in-module.
SHA-256 Cryptographic Hash
The complete credential JSON-LD document is hashed with SHA-256. Any modification — even a single character — produces a completely different hash, making tampering instantly detectable.
Blockchain Timestamp
An on-chain transaction records the credential hash and issuance timestamp on the Polygon network. This provides immutable, timestamped proof of existence independent of certify's servers.
Revocation Registry
All credentials reference a live revocation status endpoint. Verifiers always check current status — revoked credentials are flagged instantly across all verification methods.
W3C Verifiable Proof
Credentials are packaged as W3C Verifiable Credentials with cryptographic proofs. Any standards-compliant verifier can independently verify without contacting certify's servers.
Compliance certifications
certify meets the highest regulatory and industry standards for data protection and credential integrity.
CNDP (Morocco 09-08)
CompliantFull compliance with Morocco's Data Protection Law. Data residency in Morocco. Consent management and DPO appointment.
GDPR
CompliantCross-border data transfer protections, right to erasure, data portability, and lawful processing basis documentation.
ISO 27001
AlignedSecurity management aligned with ISO 27001 framework including risk assessment, incident response, and audit logging.
SOC 2 Type II
In ProgressAnnual third-party audit of security, availability, processing integrity, confidentiality, and privacy controls.
W3C VC 2.0
CertifiedFull conformance with W3C Verifiable Credentials Data Model v2.0. Interoperable with any VC-compatible system.
IMS CLR 2.0
CertifiedCertified IMS Global Comprehensive Learner Record standard. Cross-institutional learner data portability.
Request our full security documentation
Get the complete security whitepaper, penetration test results, and CNDP compliance documentation sent to your legal team.
Request Security Docs
