Capability · attestation certificates
Signed attestations whose hash anyone can check on the public verification portal.

An attestation is only as strong as the math behind it. Every Attestry certificate is a SHA-256 hash binding a specific system, a specific assessment, the framework set, and the score at the moment of issuance, wrapped in a W3C Verifiable Credential envelope and signed. Where score privacy matters, a Sigma-protocol zero-knowledge proof attests "score ≥ threshold and no critical gaps" without revealing the underlying numbers. Each certificate ships a public verify page, an embeddable SVG badge, a QR-coded PDF, and a stable revocation status, so a buyer, partner, or regulator can check a vendor's compliance claim against the public verification portal.
What's included
Each attestation is a SHA-256 hash over the system, assessment, score breakdown, and timestamp, wrapped in a W3C VC-format envelope (HMAC-SHA256 signed) so the credential is machine-readable in the standard VC data model.
Optional Sigma-protocol ZK proofs (Fiat–Shamir non-interactive) attest score ≥ threshold and absence of critical gaps without revealing the actual score, useful when buyers need assurance but the vendor doesn't want to publish a number.
Every certificate has a /verify/[hash] page anyone can hit without authentication. The same page is reachable from a QR code embedded in the rendered PDF, so paper attestations stay checkable on the same public verify page.
Six badge styles render as SVG so they paste into any site or doc. High-risk attestations expire after 6 months; lower-risk attestations after 12 months, automatically tracked and alerted before they lapse.
Powered by
Each capability rests on hash-anchored signature components; the Annex IV technical-file path is independently verifiable offline.
Free plan includes fingerprinting, unverified attestations, and a public registry listing. Upgrade when you need signed proofs or SLA-backed verification.