How it works

How CERTavia works

CERTavia validates your domain's technical infrastructure against 80+ deterministic parameters across 6 clusters. The result is binary: CERTIFIED or FAILED. The process is rule-based, with a clear result and an unambiguous basis for interpretation.

The principle

Deterministic. Binary. Audit-ready.

The EU AI Act sets requirements for the technical integrity of AI systems and their data foundations. CERTavia checks exactly this layer: the infrastructure layer on which AI systems ingest, process and use data.

The result is cryptographically signed, DNS-anchored and available in 90 to 120 seconds. The Sovereign Vault stores the audit record as tamper-evident, timestamped evidence of the checked infrastructure state. Basic: vault availability 90 days (local archiving required afterward); Pro: Sovereign Vault permanently retrievable via token.

The process

Three steps to evidence

1

Enter domain

You enter your domain's URL. No form, no registration for the Quick Scan. The scan starts immediately.

2

Validation runs

The Sovereign Validation Protocol (SOVP) checks 80+ parameters across 6 clusters. The check covers DNS configuration, cryptographic signature infrastructure, machine-readable declarations, crawler access configuration and the AI governance layer. All parameters are deterministic: every check yields the same result.

3

Evidence is ready

The result appears as CERTIFIED or FAILED. In the Full Scan you receive a PDF audit report with cluster-based infrastructure assessment referencing infrastructure-relevant aspects of Art. 50, a cryptographic signature and a Sovereign Vault link as independently verifiable evidence.

The workflow in detail

From domain entry to re-scan

Enter domain

You enter your domain's URL. No form, no registration for the Quick Scan.

Scan runs – 80+ parameters, 6 clusters

The Sovereign Validation Protocol deterministically checks DNS configuration, cryptographic signature infrastructure, machine-readable declarations, crawler access configuration and the AI governance layer.

Signature and vault

The result is cryptographically signed and stored in the Sovereign Vault as timestamped, tamper-evident evidence.

Report and API output

PDF audit report, JSON and CSV output, and the machine-readable verification URL (Pro and above) are available immediately. Annual and Enterprise plans additionally unlock automatic access to the customer portal (login via email link, no account needed); with Basic and Pro, customer portal access is available on request.

Re-scan on the subscription cycle

Annual Subscription and Enterprise customers receive automatic re-scans on the agreed cadence, including change notifications when the status changes.

The difference

Before CERTavia. After CERTavia.

Before CERTavia

Infrastructure claims without external evidence. Manual screenshots for auditors, assembled one by one. No ongoing visibility into your own compliance status. Evidence is only produced on request – often under time pressure.

After CERTavia

Cryptographically signed evidence instead of unsubstantiated claims. A stable, machine-readable verification URL instead of manual screenshots. Quarterly re-scans on the Annual Subscription cycle instead of point-in-time checks. The evidence is ready before the request comes in.

Scope of validation

What CERTavia checks

CERTavia validates the infrastructure layer that sits upstream of content. At this layer, AI systems decide which domains to treat as trustworthy data sources.

Core technical integrity

DNS configuration, DNSSEC, TLS certificate chain, HTTP security headers, CAA records.

Privacy & consent

Crawler directives, robots.txt consistency, consent declaration integrity, AI discovery layer.

Machine-readable identity

Structured data, canonical entity declaration, machine-readable authorship signals.

AI governance hard gate

AI policy URL, privacy-AI section, deepfake disclaimer, AI training opt-out status, contact point for AI inquiries.

The 6 validation clusters (A–F) map onto these four strategic areas.

The certificate

What a CERTIFIED status means

A CERTIFIED status from CERTavia documents that the checked domain met all 80+ infrastructure parameters of the Sovereign Validation Protocol at the time of the query. The certificate includes a cryptographic signature, the validation timestamp and the Sovereign Vault link as independently verifiable evidence.

The certificate is a technical infrastructure document. It forms the basis for compliance documentation under Art. 50 EU AI Act. For legal advice on individual cases, consult qualified legal and compliance advisors.

Technical foundation

Powered by SOVP

CERTavia is based on the Sovereign Validation Protocol (SOVP), developed by Thorsten Litzki, Litzki Systems LLC. SOVP is formally filed as an IETF Internet-Draft (draft-litzki-sovp) and registered as USPTO Provisional Patent Application #64/005,737.

The protocol works exclusively with rule-based, deterministic parameters. All 80+ parameters yield the same result for a given infrastructure state.

Get started

Ready for your first scan?

Quick Scan – free

The Quick Scan is free and delivers your domain's layer-0 result in 90 to 120 seconds. No form, no registration.

Scan your domain now – free

Enterprise & custom requirements

For complex requirements or custom infrastructure configurations, the contact form is available.

Get in touch