PUBLIC CERTIFICATE REGISTRY

A badge should be verifiable.

Every issued certificate should resolve to a public record showing exactly what was evaluated, under which profile, for how long, and whether the status remains valid.

CERTIFICATE IDHIOP-AGENT-2026-000001
SUBJECTExample Agent / v3.2
PROFILEHIOP Agent Control Profile 1.0
SCOPECRM + email; no payment authority
STATUSEXAMPLE — NOT ISSUED
VALIDITYExample only

Registry fields

Status
Valid, conditional, suspended, withdrawn, expired or replaced.
Scope
Agent/version, deployment, effect categories, exclusions and applicable profile.
Evidence identity
Non-sensitive evidence digest or report identifier that can be matched to the certification decision.
Change history
Renewals, scope changes, surveillance findings, suspension/withdrawal dates and replacement certificates.

Complaint and appeal path

A credible certification program needs a way for customers, researchers, employees or affected parties to report a false claim, scope violation or observed control failure. Complaints should be logged, investigated, dispositioned, and able to trigger surveillance, suspension or withdrawal. Applicants also need an independent appeal path for disputed certification decisions.

Registry status: IN DEVELOPMENT. When the certification program launches, customers will be able to verify certificate ID, scope, version, status, expiry and surveillance history here.