Standards-conformant proofs
Verifies with the tooling your auditor already trusts.
No proprietary verifier on the trust path
A proof bundle is only as trustworthy as the tooling required to verify it. Vitrified bundles are designed so every mechanism inside verifies with that mechanism’s standard reference tooling — the same tools your auditor, your customer’s enterprise security team, or a future regulator would reach for unprompted. No Vitrified-branded verifier sits on the trust path.
Standards we conform to
- RFC 3161 — X.509 time-stamp tokens. Verifies with
openssl ts -verify. - ETSI EN 319 421 / 422 — the eIDAS qualified timestamp profile. Verifies against the EU Trust Services List with the EU DSS validator at
signatures.ec.europa.eu. - Sigstore bundle / Rekor v0.0.2 — verifies with
cosign verifyandrekor-cli. - OpenTimestamps —
.otsproofs verify with the standardotsclient against Bitcoin block headers. - DSSE (in-toto) — envelopes verify with
dsse-verifyand any in-toto-aware tooling. - in-toto Statement v1 / SLSA Provenance v1 — predicates pass
slsa-verifierwhen wrapped accordingly. - C2PA format-compatible — manifest layout interoperates with the C2PA specification for downstream content-authenticity tooling.
What Vitrified is not
- Not a QTSP. Vitrified is not on the EU Trust List. eIDAS-qualified status comes from the QTSP signature embedded in the timestamp token, not from any claim Vitrified makes.
- Not a proprietary verification path. Every witness mechanism in a bundle verifies against its standard public trust infrastructure with that mechanism’s reference tooling.
- Not required for verification. Once you have a bundle, Vitrified can disappear and the proof remains independently verifiable.
Get Started
Self-serve. Subscription with volume-scaled tiers. See pricing