Vendor claim verification is the independent check of what a supplier asserts about itself against evidence, by a party with no stake in the answer. Certisyn runs a Verification Reconciliation Object (VRO) over each claim and issues a cryptographically sealed, policy-versioned Verification Attestation Object (VAO) that the buyer, the buyer's auditor and the buyer's regulator can each check without asking Certisyn.
A procurement decision rests on claims the supplier makes. Each claim has an evidence base, and each deserves a determination.
| Claim | Evidence examined | Determination |
|---|---|---|
| A certification is held | The certificate, the certifying body's records, the stated scope | Held, in scope, in date, or the reason it could not be determined |
| A control is operated | Policy documents, telemetry, configuration snapshots, audit logs | Documented, Operational or Adversarial-ready, per control |
| Data resides in a stated jurisdiction | Hosting records, architecture evidence, contractual terms | Established for the examined population, with unexamined units listed |
| Insurance or registration is current | Registry entries and issuer records | Current at the time of issue, anchored |
| An operator is who it says it is | Registry and filing records | Established, or the claims that stayed open |
| Instrument | What it records | What verification adds |
|---|---|---|
| Security questionnaire | The supplier's own answers | A determination on each answer, from evidence |
| Audit report | A process was completed against a standard at a point in time | A determination on the underlying claim, replayable under a named policy version |
| Security rating | How an organisation looks from outside | A determination on a specific claim, with the gaps named |
| Trust centre | What a vendor chooses to publish about itself | A record issued by a party with no hand in the vendor's compliance programme |
The same evidence and the same policy version produce the same sealed result. A later reader can tell whether the standard moved after the determination, because the policy version travels with it. The derivation root is recomputable from the record, and the anchor fixes the time of issue.
Certisyn publishes its signing keys at keys.certisyn.com and resolves printed certificate codes at registry.certisyn.com, so a reader fetches the key and the record from addresses Certisyn does not control per request.
Vendor claim verification is the independent check of what a supplier asserts about itself against evidence, by a party with no stake in the answer. The claims typically cover certifications held, controls operated, residency, insurance and ownership.
Certisyn runs a Verification Reconciliation Object (VRO) over each claim and issues a cryptographically sealed, policy-versioned Verification Attestation Object (VAO) that travels with the claim across organisations and jurisdictions.
The buyer, the buyer's auditor, the buyer's regulator and any counterparty can each check it without asking Certisyn, because the record carries the policy version, the derivation root and the anchor.
Each determination states the claims it could not determine, and the coverage statement names what was examined and what was not, with denominators.
A questionnaire collects the supplier's own answers. A determination records what an independent party established from evidence about each of those answers.