A certificate only means something if you can prove who signed it.
eIDAS-aligned electronic seals for diplomas, licenses, and legal documents. The issuer's private key is the proof. Not a database label.
A "Verified Authority" label
is not a cryptographic proof.
Existing platforms issue documents with database flags and brand logos. That is not verification. That is someone's word for it.
Database label, not identity
Anyone with the platform password can issue in your name. There is no private key, no certificate, no binding. The issuer's identity is a row in a table, not a mathematical fact.
no cryptographic bindingFalse eIDAS compliance
Claiming "eIDAS compliant" without TSP accreditation or TSL listing is a marketing claim, not a legal fact. The regulation is specific. Most platforms do not meet it.
regulatory misrepresentationProof dies with the vendor
URL-based documents resolve to nothing when the platform shuts down. Every certificate issued on that platform becomes unverifiable overnight.
vendor lock-in riskNo non-repudiation
Without a cryptographic signature, an issuer can deny issuing a document. There is no mathematical proof they authorised it. The recipient carries the burden and cannot meet it.
repudiation possibleWhat if "Issuer: Nordvik" was a mathematical fact,
not a claim you have to trust?
Signed by the institution's own key. Checking it needs nothing from us, and it still checks out when the issuing system is long retired.
Three steps. The issuer
is the proof.
The organisation's key signs the document and the QR carries the proof. Anyone can check the signature against the key the issuer published.
Sign
The organisation signs the document with its private seal key. Keys are sealed at rest and never exposed in plaintext. Only this organisation can produce this signature.
Pack
Document data and signature are packed into a self-contained envelope and encoded as a QR code. Printed on the certificate, embedded in the PDF, or delivered digitally. The proof travels with the document.
Verify
Any verifier checks the signature against the issuer's published key, in milliseconds, with no app and no account. What the document says comes from the issuer's record.
Any document an organisation
has authority to issue.
If an institution has authority to issue it, that authority can be made cryptographically verifiable.
Diplomas & Degrees
Universities issue degrees verifiable in seconds by any employer, in any country, without contacting the issuer.
- Bachelor, Master, PhD certificates
- Transcripts and course records
- Professional certifications
- Micro-credentials and badges
Professional Licenses
Regulatory bodies issue licenses that stay verifiable after the agency database is restructured or migrated. The proof is in the document.
- Medical and healthcare licenses
- Legal bar admissions
- Engineering certifications
- Financial and regulatory permits
Official Documents
Public authorities issue documents where authenticity matters at the point of presentation, not at the point of lookup against a central register.
- Court orders and judgments
- Official permits and approvals
- Notarised documents
- Cross-border legal instruments
Five layers.
One signed payload.
Everything needed to make document authenticity a mathematical property, not a platform policy.
Issuer Identity
The organisation's private seal key signs every document. The signature is mathematically bound to the issuer's identity. Not a username, not an API key.
- Sealed signing keys, never plaintext at rest
- Non-repudiable by design
- QSealC-ready by design
Legal Standing
Built for the eIDAS qualified ladder: a Qualified Electronic Seal carries a statutory presumption of integrity and origin under EU law. Intygio issues advanced electronic seals today; the QSealC chain activates when our QSCD is operational.
- Advanced electronic seals today
- QSealC contracted via DigiCert Europe
- Art. 35 presumption when the qualified chain is live
Self-Verifying
The proof is in the QR and the key is published, so checking a document is a computation rather than a request for permission. It still works in ten years, and it works if we are not the ones running it.
- Proof encoded directly in the QR
- Checking the signature needs nothing from us
- Survives a vendor shutdown
Trusted Timestamps
Each signature includes an RFC 3161 timestamp. The signing time is cryptographically bound: immutable, auditable, and built for long-term validation. Qualified eIDAS timestamps arrive with our TSA rollout.
- RFC 3161 timestamp authority
- Immutable signing time
- Long-term validation (LTV) design
API-First
Self-serve from day one. Integrate document signing into your issuance workflow via REST. Metered billing, pay per proof issued. No sales call, no annual contract, no minimum volume.
- REST Sign & Verify endpoints
- Metered billing per proof
- Self-serve portal
Every document your organisation issues
should be verifiable forever.
The issuer's private key is the only proof that matters. Everything else is a claim.
For the Chief Sustainability Officer at a European certification body, investigating a disputed conformity declaration takes two months, three email threads, and still produces no definitive answer. "We believe it is authentic" is not the same as "we can prove it."
Every certificate her organisation issues now carries a verifiable timestamp and issuer identity that any counterparty can check without calling her team. The counterparty scans the document seal on their phone. In two seconds, they have a definitive answer. No email thread.