Security & trust

What actually makes a certificate trustworthy

Not the PDF, and not the seal alone, a combination of a human approval gate, server-side cryptographic signing, and a live record that a QR code always points back to.

Certified gold seal

The gold seal

Every certificate carries this exact mark, in this exact gold, never recolored to an issuer's brand, never resized below legibility, never issuer-configurable. Because it's identical everywhere, a missing or poorly-reproduced seal is itself a red flag, on top of the cryptographic check underneath it.

How verification works

The record is authoritative, not the file

Non-sequential public IDs

Every certificate gets a random public ID, e.g. CERT-8F2K9-XQ41, never an incrementing number, so IDs can't be enumerated or scraped in order, and there's no endpoint that lists them all.

Server-side cryptographic signing

A signature is computed over the certificate's core fields at issuance, using a secret that never leaves the server and is never returned in any API response. Every verification re-checks it, a direct database edit that bypasses the signing service breaks the signature.

Rate-limited lookups

The verification endpoint is public by design, it has to be frictionless, but it's rate-limited per IP, with no bulk-listing capability anywhere in the system.

Revocation is disclosed, not hidden

A revoked certificate stays permanently visible as revoked, with its reason and date, deleting the record instead would undermine the whole point of the system.

Issuer trust

Nothing gets issued without a human review

Every organization on Certified Africa applied and was reviewed, identification and, for businesses, proof of operation are checked before any issuance capability unlocks. Unusual issuance volume spikes are surfaced to our staff for review, and two-factor authentication is required internally and available to issuers.

Your data

Consent first, gated by default

A trainee's public profile requires the issuer to confirm consent at the time it's created. Trainees get an emailed claim link to edit, hide, or manage their own profile at any time. Phone and email are never rendered directly on a public page for anyone unauthenticated, contact happens through a rate-limited relay instead. See our Privacy Policy for the full picture.