INTYGIO

A certificate only means something if you can prove who signed it.

eIDAS-aligned electronic seals for diplomas, licenses, and legal documents. The issuer's private key is the proof. Not a database label.

27
EU states where the proof verifies
QSealC
in provisioning via DigiCert
0
servers needed at verification
The problem

A "Verified Authority" label
is not a cryptographic proof.

Existing platforms issue documents with database flags and brand logos. That is not verification. That is someone's word for it.

Database label, not identity

Anyone with the platform password can issue in your name. There is no private key, no certificate, no binding. The issuer's identity is a row in a table, not a mathematical fact.

no cryptographic binding

False eIDAS compliance

Claiming "eIDAS compliant" without TSP accreditation or TSL listing is a marketing claim, not a legal fact. The regulation is specific. Most platforms do not meet it.

regulatory misrepresentation

Proof dies with the vendor

URL-based documents resolve to nothing when the platform shuts down. Every certificate issued on that platform becomes unverifiable overnight.

vendor lock-in risk

No non-repudiation

Without a cryptographic signature, an issuer can deny issuing a document. There is no mathematical proof they authorised it. The recipient carries the burden and cannot meet it.

repudiation possible

What if "Issuer: Nordvik" was a mathematical fact,
not a claim you have to trust?

Signed by the institution's own key. Checking it needs nothing from us, and it still checks out when the issuing system is long retired.

How it works

Three steps. The issuer
is the proof.

The organisation's key signs the document and the QR carries the proof. Anyone can check the signature against the key the issuer published.

1

Sign

The organisation signs the document with its private seal key. Keys are sealed at rest and never exposed in plaintext. Only this organisation can produce this signature.

eIDAS-aligned seal · Sealed keys
2

Pack

Document data and signature are packed into a self-contained envelope and encoded as a QR code. Printed on the certificate, embedded in the PDF, or delivered digitally. The proof travels with the document.

QR · PDF embed · Any carrier
3

Verify

Any verifier checks the signature against the issuer's published key, in milliseconds, with no app and no account. What the document says comes from the issuer's record.

EUTL compatible · under 1 ms
Certificate verification · Intygio
Document type Master of Science, Computer Science
Issued to Sven Svensson
Issuing body Nordvik Institute of Technology
Issue date 2025-06-13
Trust service eIDAS-aligned (advanced seal)
Verification ✓ Authentic, signature valid
✓ Verified
Use cases

Any document an organisation
has authority to issue.

If an institution has authority to issue it, that authority can be made cryptographically verifiable.

Education

Diplomas & Degrees

Universities issue degrees verifiable in seconds by any employer, in any country, without contacting the issuer.

  • Bachelor, Master, PhD certificates
  • Transcripts and course records
  • Professional certifications
  • Micro-credentials and badges
Licensing

Professional Licenses

Regulatory bodies issue licenses that stay verifiable after the agency database is restructured or migrated. The proof is in the document.

  • Medical and healthcare licenses
  • Legal bar admissions
  • Engineering certifications
  • Financial and regulatory permits
Legal & Public

Official Documents

Public authorities issue documents where authenticity matters at the point of presentation, not at the point of lookup against a central register.

  • Court orders and judgments
  • Official permits and approvals
  • Notarised documents
  • Cross-border legal instruments
What you get

Five layers.
One signed payload.

Everything needed to make document authenticity a mathematical property, not a platform policy.

Issuer Identity

The organisation's private seal key signs every document. The signature is mathematically bound to the issuer's identity. Not a username, not an API key.

  • Sealed signing keys, never plaintext at rest
  • Non-repudiable by design
  • QSealC-ready by design
eIDAS-aligned · QSealC-ready

Legal Standing

Built for the eIDAS qualified ladder: a Qualified Electronic Seal carries a statutory presumption of integrity and origin under EU law. Intygio issues advanced electronic seals today; the QSealC chain activates when our QSCD is operational.

  • Advanced electronic seals today
  • QSealC contracted via DigiCert Europe
  • Art. 35 presumption when the qualified chain is live
eIDAS 910/2014 · Art. 35

Self-Verifying

The proof is in the QR and the key is published, so checking a document is a computation rather than a request for permission. It still works in ten years, and it works if we are not the ones running it.

  • Proof encoded directly in the QR
  • Checking the signature needs nothing from us
  • Survives a vendor shutdown
Self-contained · Timestamped

Trusted Timestamps

Each signature includes an RFC 3161 timestamp. The signing time is cryptographically bound: immutable, auditable, and built for long-term validation. Qualified eIDAS timestamps arrive with our TSA rollout.

  • RFC 3161 timestamp authority
  • Immutable signing time
  • Long-term validation (LTV) design
RFC 3161 · TSA · LTV

API-First

Self-serve from day one. Integrate document signing into your issuance workflow via REST. Metered billing, pay per proof issued. No sales call, no annual contract, no minimum volume.

  • REST Sign & Verify endpoints
  • Metered billing per proof
  • Self-serve portal
REST API · Metered

Every document your organisation issues
should be verifiable forever.

The issuer's private key is the only proof that matters. Everything else is a claim.

For the Chief Sustainability Officer at a European certification body, investigating a disputed conformity declaration takes two months, three email threads, and still produces no definitive answer. "We believe it is authentic" is not the same as "we can prove it."

Every certificate her organisation issues now carries a verifiable timestamp and issuer identity that any counterparty can check without calling her team. The counterparty scans the document seal on their phone. In two seconds, they have a definitive answer. No email thread.