Glossary

Verification glossary.

Plain definitions of the terms used across Certisyn determinations, standards and registry records.

Verification
The independent determination of whether a specific claim is true, made from evidence by a party with no stake in the answer, bound to the policy version in force and stating what it could not determine.
Audit
A review that records whether a process was completed against a standard at a point in time. An audit report is evidence that a verification consumes.
Verification Reconciliation Object (VRO)
The record in which Certisyn reconciles each claim against its evidence and reaches a determination.
Verification Attestation Object (VAO)
The cryptographically sealed, policy-versioned attestation issued from a VRO. A relying party can check it without asking Certisyn.
AI Governance Verified (AIGVS)
The verification standard for the governance claims an operator makes about its AI agents. It is published at the IETF as draft-hillier-certisyn-ai-governance-verified.
Essential Eight Verified
The verification standard for conformance claims against the ACSC Essential Eight Maturity Model, published at the IETF as draft-hillier-certisyn-essential-eight-verified.
Coverage Attestation Profile (CAP-1)
The specification for declaring the population a verification examined, with denominators, and for enumerating every unexamined unit with a reason. Published at the IETF as draft-hillier-coverage-attestation.
Conformance Continuity
The specification for carrying a verified conformance claim across a baseline, jurisdiction or period boundary while naming what carried and what did not. Published at the IETF as draft-hillier-conformance-continuity.
Attestation Reconciliation Protocol
The specification for establishing whether an accountable principal stands behind an autonomous agent, reconciled against sovereign registers with minimum disclosure. Published at the IETF as draft-hillier-scitt-arp.
Issuing Partner
An accredited party that reconciles evidence against a standard and seals the determination, under Certisyn's conflict-of-interest gate.
Conflict-of-interest gate
The control that runs at the point of sale and at issuance so that a party with a hand in building or operating a subject cannot issue its verdict.
Policy version
The exact rule set in force when a determination was issued. It travels with the determination so a later reader replays it under the rules that applied.
Derivation root
A hash over the evidence and the reasoning behind a determination, recomputable by anyone from the record.
Public anchor
The commitment of a derivation root to a public chain, which fixes the time of issue through a party with no interest in the outcome.
Maturity level
The level a control or claim earns against evidence: Documented, Operational or Adversarial-ready.
Could not determine
The result for a claim the evidence did not reach. It is stated plainly and counted against the total claims assessed.
Revocation
The withdrawal of a seal when monitoring finds the subject has drifted from the evidence. The public registry reflects the change immediately.
Relying party
Any party that depends on a determination: a buyer, a prime, an insurer, an auditor, a regulator or a counterparty.
Know-your-agent
The practice of establishing who an AI agent is and who stands behind it. It is the identity layer that a governance verdict builds on.
SCITT
Supply Chain Integrity, Transparency and Trust: the IETF working group and architecture for transparent, verifiable records about supply chain statements.

Related