Direct answers about Certisyn, what verification establishes, how anyone checks a result and where the standards stand.
Certisyn is verification infrastructure for institutional reliance. It issues independent, sealed, policy-versioned determinations about specific claims, and every determination resolves at a public registry.
Joel Hillier founded Certisyn and is its Founder and CEO. Certisyn, Inc. is based in Salt Lake City, Utah.
No. Certisyn is an independent company. The names are similar and the companies are unrelated. The name guide sets out each one.
Certisyn holds ISO/IEC 27001:2022 for information security and ISO 9001:2015 for quality management. The trust posture page lists scope and registration details.
Verification is the independent determination of whether a specific claim is true, made from evidence, bound to a policy version and stating what it could not determine. See verification and audit.
An audit records that a process was completed against a standard at a point in time. Verification determines whether a claim is true and issues a record a counterparty can replay. An audit report is an input to a verification.
A rating summarises how an organisation looks from outside. A determination addresses a specific claim and names its gaps. See the comparison.
A Verification Attestation Object (VAO) is the cryptographically sealed, policy-versioned attestation Certisyn issues from a Verification Reconciliation Object (VRO). A relying party checks it without asking Certisyn.
The policy version in force, a derivation root anyone can recompute, a public anchor that fixes the time of issue, a maturity level, the claims the evidence did not reach, and the current revocation state.
It is the result for a claim the evidence did not reach. Certisyn states it plainly and counts it against the total claims assessed, so a reader knows how much of the picture the determination covers.
Each printed code resolves at registry.certisyn.com and the signing keys are published at keys.certisyn.com. A reader needs no account, key or signup.
Yes. Monitoring withdraws the seal when the subject drifts from the evidence, and the registry reflects the change immediately.
Accredited Issuing Partners reconcile evidence against a standard and seal the determination. A conflict-of-interest gate runs at the point of sale and at issuance.
Yes. The agent verification page runs a public check, and AI agent verification explains the 8 control areas and the verdict.
Certisyn's founder has published 6 specifications at the IETF as individual Internet-Drafts, open for review. They cover agent accountability, AI governance, Essential Eight conformance, coverage attestation, conformance continuity and the Chorale transport. The plain-language summary describes each one.
They are individual submissions to the IETF, open for review. The standards page records the status of each against the Datatracker.
AI Governance Verified (AIGVS) is the standard for verifying the governance claims an operator makes about its AI agents. It is published as draft-hillier-certisyn-ai-governance-verified.
Essential Eight Verified is the standard for verifying conformance claims against the ACSC Essential Eight Maturity Model. See Essential Eight verification.
Buyers verifying supplier claims, primes assessing defence-industrial suppliers, insurers and boards reading maturity claims, counterparties to AI agents, and regulators reading disclosures.
Pricing is published at app.certisyn.com/pricing, and a free verification is available at app.certisyn.com/live.
Use the contact page. Press enquiries go to press@certisyn.com.