Verify a certificate

Check a ProvenClosed certificate without trusting us.

You need no account, and you do not need to trust this website. The check runs on your own machine, against a key you can save yourself.

Three steps

  1. Download the verifier, verify.py. It is one Python file with a single dependency, written to be read end to end before you run it — please do read it.
  2. Save the public key set once and keep it: vexora-attestation-keys.json. A verifier that fetches the key fresh every time trusts this server every time; one you saved trusts it once.
  3. Run it on the certificate you were given — the .html page or the .json file, both work:
    pip install cryptography
    python verify.py certificate.html --keys vexora-attestation-keys.json
    Without --keys, the verifier fetches the key set fromhttps://provenclosed.com — the one issuer it trusts, never whichever issuer a certificate names about itself. A certificate naming any other issuer is refused. Saving the key set yourself is still the stronger check.

What it prints

Four lines come first, before any detail, so that nothing below them can be read as stronger than they are. For a production certificate (the entry number and time here are an example):

Signature ........ VALID       DSSE, RS256, kid nuI2dD6CCxH2...
Issuer ........... TRUSTED     https://provenclosed.com
Transparency ..... VALID       Sigstore Rekor entry 123456789, logged 2026-10-01 09:14 UTC
Attestation ...... VERIFIED    production

Transparency is the proof that the certificate's fingerprint is in Sigstore's public transparency log. It travels inside the certificate, and the verifier checks it without contacting the log. Anyone can also look an entry up by its number at search.sigstore.dev — it shows a hash, a signature and a public key, and nothing else.

Certificates issued before transparency logging began arev0.1-alpha: signed and checkable, but never logged. For those the verifier prints Transparency NOT PRESENT andAttestation NOT PRODUCTION-VERIFIED, and says why.

Exit codeMeaning
0Production-verified: valid signature, trusted issuer, valid transparency proof.
3Valid signature from the trusted issuer, but not production-verified — an alpha certificate, or one whose proof is missing.
1Refused. The reason is printed.
2The file or the key set could not be read.

A script that treats 0 as "accept" is never satisfied by anything less than a production-verified certificate.

Current signing key

nuI2dD6CCxH2_SH-PgIQa5UfvPbgbN5s

A certificate signed by any other key is not one of ours.

What a certificate proves, and what it does not

It proves what ProvenClosed observed about the resources it names, when, and that the document has not been altered since it was signed.

  • It does not prove that an estate is secure, and it says nothing about any moment after the dates it carries.
  • It does not say who changed anything. ProvenClosed only observes; it never changes a customer's infrastructure.
  • The signature covers the document embedded in a certificate, not the wording printed around it. The verifier re-prints every claim from the signed bytes — where the two disagree, trust the verifier.
  • A production certificate's fingerprint — a hash, and nothing about the estate it describes — is in Sigstore's public transparency log. That is what stops ProvenClosed backdating a certificate or later pretending it was never issued: the verifier refuses one whose stated issue time is more than fifteen minutes before it was logged.

The states a certificate can carry

  • VERIFIED — the exposure was seen, then seen gone, by the same pinned scanner in a recorded scan run.
  • VERIFIED_WITH_LIMITATIONS — seen gone, with what weakens the proof named in the certificate.
  • OBSERVED_ONLY — recorded, but not yet seen gone by a later scan.

ProvenClosed is not a CERT-In empanelled auditor. Its certificates are not VAPT certificates and do not replace one.