QRCertificates
Security & trust

Tamper-proof certificate security, verifiable by anyone

QRCertificates is built so a credential cannot be quietly altered and a forgery cannot pass as real. Here is exactly how.

Cryptographic signing

Every credential is signed with Ed25519 over its canonical fields — the meaningful data, not the image bytes.

Anchored verification

Verification checks signatures against a fixed platform public key, never the key stored alongside a certificate, so re-signed forgeries fail.

Immutable records

Certificates are generated once and never regenerated. The stored copy is the record of truth for its lifetime.

Evidence-based issuer identity

Issuer tier is derived from real evidence — verified email, domain, or business registration — and never from a self-asserted name.

Instant revocation

A revoked credential reports as revoked the moment you act, with the reason kept on record.

Same-origin verification

The verification page and API share one origin, so what a recipient sees is exactly what the API attests.

A certificate sealed with a tamper-evident wax seal
Trust model

How a verification decision is made

When someone verifies a credential, QRCertificates answers two independent questions. First, is it authentic and unaltered? We recompute the signature over the certificate's canonical fields and check it against the platform key. Any change to any field — a name, a date, a course — breaks the signature.

Second, who really stands behind it? The issuer shown is derived only from evidence the organization actually provided: a verified email, a domain confirmed by DNS, or a business registration. An organization can never display an unearned identity — the public page says “issuer not verified” rather than show an unverifiable claim.

Because these are separate, a credential can be cryptographically valid yet still flagged as coming from an unverified issuer — exactly the honesty a verifier needs.

Issue your first credential in minutes

Start free — no credit card. Design a certificate, issue a verifiable copy, and watch it verify on a public page. Scale to thousands when you are ready.