Skip to content

Standards-conformant proofs

Verifies with the tooling your auditor already trusts.

No proprietary verifier on the trust path

A proof bundle is only as trustworthy as the tooling required to verify it. Vitrified bundles are designed so every mechanism inside verifies with that mechanism’s standard reference tooling — the same tools your auditor, your customer’s enterprise security team, or a future regulator would reach for unprompted. No Vitrified-branded verifier sits on the trust path.

Standards we conform to

  • RFC 3161 — X.509 time-stamp tokens. Verifies with openssl ts -verify.
  • ETSI EN 319 421 / 422 — the eIDAS qualified timestamp profile. Verifies against the EU Trust Services List with the EU DSS validator at signatures.ec.europa.eu.
  • Sigstore bundle / Rekor v0.0.2 — verifies with cosign verify and rekor-cli.
  • OpenTimestamps.ots proofs verify with the standard ots client against Bitcoin block headers.
  • DSSE (in-toto) — envelopes verify with dsse-verify and any in-toto-aware tooling.
  • in-toto Statement v1 / SLSA Provenance v1 — predicates pass slsa-verifier when wrapped accordingly.
  • C2PA format-compatible — manifest layout interoperates with the C2PA specification for downstream content-authenticity tooling.

What Vitrified is not

  • Not a QTSP. Vitrified is not on the EU Trust List. eIDAS-qualified status comes from the QTSP signature embedded in the timestamp token, not from any claim Vitrified makes.
  • Not a proprietary verification path. Every witness mechanism in a bundle verifies against its standard public trust infrastructure with that mechanism’s reference tooling.
  • Not required for verification. Once you have a bundle, Vitrified can disappear and the proof remains independently verifiable.
Get Started

Self-serve. Subscription with volume-scaled tiers. See pricing