Skip to content
Trust & Security

Security you can audit.
Proof you can verify.

certify's cryptographic architecture makes credential fraud mathematically impossible. Every claim is independently verifiable without trusting our servers.

Secure data center infrastructure with Moroccan zellige patterns
Security Architecture

5-layer cryptographic security

Each layer independently prevents a different class of forgery. A compromised verifier, network, or even our own servers cannot produce a valid credential.

1

Institutional Key Signing

Every credential is signed with the issuing institution's Ed25519 private key, stored in a FIPS 140-2 Level 3 Hardware Security Module (HSM). Private keys never leave the HSM — all signing happens in-module.

2

SHA-256 Cryptographic Hash

The complete credential JSON-LD document is hashed with SHA-256. Any modification — even a single character — produces a completely different hash, making tampering instantly detectable.

3

Blockchain Timestamp

An on-chain transaction records the credential hash and issuance timestamp on the Polygon network. This provides immutable, timestamped proof of existence independent of certify's servers.

4

Revocation Registry

All credentials reference a live revocation status endpoint. Verifiers always check current status — revoked credentials are flagged instantly across all verification methods.

5

W3C Verifiable Proof

Credentials are packaged as W3C Verifiable Credentials with cryptographic proofs. Any standards-compliant verifier can independently verify without contacting certify's servers.

Blockchain Integrity

Anchored on-chain. Forged-proof by design.

Each credential is anchored to the Polygon blockchain the moment it is issued — creating a public, immutable record that outlives any server, database, or institution.

Every credential hash is anchored on-chain at issuance
Immutable, timestamped proof of existence
Verification works even if certify servers are unreachable
Global Standards Compliance

Compliance certifications

certify meets the highest regulatory and industry standards for data protection and credential integrity.

CNDP (Morocco 09-08)

Compliant

Full compliance with Morocco's Data Protection Law. Data residency in Morocco. Consent management and DPO appointment.

How we complyData residency in MoroccoConsent managementAppointed Data Protection Officer

GDPR

Compliant

Cross-border data transfer protections, right to erasure, data portability, and lawful processing basis documentation.

How we complyCross-border transfer protectionsRight to erasure & portabilityDocumented lawful processing basis

ISO 27001

Aligned

Security management aligned with ISO 27001 framework including risk assessment, incident response, and audit logging.

How we complyRisk assessment frameworkIncident response planFull audit logging

SOC 2 Type II

In Progress

Annual third-party audit of security, availability, processing integrity, confidentiality, and privacy controls.

How we complyAnnual third-party auditSecurity, availability & integrity controlsConfidentiality & privacy controls

W3C VC 2.0

Certified

Full conformance with W3C Verifiable Credentials Data Model v2.0. Interoperable with any VC-compatible system.

How we complyW3C VC Data Model v2.0 conformanceInteroperable with any VC-compatible system

IMS CLR 2.0

Certified

Certified IMS Global Comprehensive Learner Record standard. Cross-institutional learner data portability.

How we complyIMS CLR 2.0 certifiedCross-institutional learner data portability
Blockchain credential verification network

Request our full security documentation

Get the complete security whitepaper, penetration test results, and CNDP compliance documentation sent to your legal team.

Request Security DocsTalk to us on WhatsApp