Skip to main content

Public trust model

Verification is a registry decision, not a visual guess.

Nyvarra checks its registry record, the issuer’s registered key and domain-control evidence, the signed payload, and current lifecycle state. The issuing organisation—not Nyvarra—asserts that the recipient earned the credential. Verification does not prove accreditation, the truth of the achievement, or biological identity.

Nyvarra Trust Horizon
Public proof protocol

Trust packet

Evidence in one public view

Issuer approval and public profile01
Credential serial and permanent verification URL02
Signed JSON-LD payload03
Payload and PDF hashes04
Revocation, expiration, and supersession checks05
Downloadable verifier receipt06
Integrity

Payload hash

Canonicalized and checked against stored SHA-256.

Registry decision

Distinct outcomes

Verified, revoked, superseded, tampered, or unknown.

Verification checks

What Nyvarra checks before showing a result.

01

Integrity

Payload hash

The credential payload is canonicalized and checked against the stored SHA-256 hash.

02

Signature

Registered issuer key

The signed JSON-LD proof is checked against the key registered to the issuing organisation in Nyvarra.

03

Issuer

Approved issuer snapshot

The public result includes the issuing organisation, verified domain, and issuer profile link where available.

04

Lifecycle

Revocation and correction

Revoked, expired, superseded, tampered, unknown, and verified states are shown as distinct outcomes.

Public result states

Verifiers should not have to interpret ambiguous proof.

Public pages use separate states for verified, revoked, superseded, expired, tampered, unavailable, and unknown results. A failed registry lookup is never presented as verified.

Verified

Signature, payload hash, issuer context, and lifecycle checks pass.

Revoked

The issuer has withdrawn the credential while keeping the audit trail visible.

Superseded

A corrected credential has replaced the original serial.

Tampered or unknown

The proof failed or the serial cannot be resolved in the registry.

Issuer context

Review approved issuers before trusting a credential.

Public issuer profiles show legal and domain context, program activity, credential counts, and verification activity where the issuer has published a profile.

Review

Issuer approval

Organisations are reviewed before approval. Domain control proof is optional and is shown separately from application approval on issuer records and credentials.

01

Domain

Verified domain signals

A verified-domain signal means Nyvarra observed the required DNS proof. It does not establish accreditation or validate every claim the issuer makes.

02

Registry

Public issuer directory

Approved issuers can publish public profiles with active programs, counts, and recent credential activity.

03