For IT leaders and CTOs

Infrastructure integrity. Deterministically checked. Cryptographically secured.

AI systems decide at Layer 0 which domains are treated as trustworthy data sources. That decision happens before the first content request, before the first API call, at the infrastructure level IT leaders and CTOs are responsible for. CERTavia makes this status measurable, binary, and audit-ready.

JSON output · SIEM-integrable · REST API for CI/CD · cryptographically signed

The technical starting point

Layer 0 is the decision layer

Agentic systems and LLM pipelines traverse domains systematically. At Layer 0, they check DNS configuration, cryptographic signature infrastructure, machine-readable declarations, and AI governance parameters. Domains fully configured at this level are ingested as trustworthy sources. Domains with gaps at this level receive reduced or no access to agentic ingestion.

CERTavia checks exactly this level. 80+ parameters, 6 clusters, binary result: SOVP-CERTIFIED or SOVP-FAILED. Deterministically reproducible, cryptographically signed, in 90 to 120 seconds.

What CERTavia technically checks

80+ parameters in 6 clusters

The validation parameters are organized into four strategic areas. Every parameter is rule-based and deterministic. No probabilistic scoring, no AI component in the check procedure itself.

DNS and cryptographic base integrity

DNSSEC configuration, CAA records, TLS certificate chain, HTTP security headers (HSTS, CSP, DMARC), SPF, and DKIM. The base layer on which all further validation steps build.

Privacy & consent

Crawler directives in robots.txt, consistency of opt-in and opt-out declarations for all relevant AI crawlers, WAF response consistency, consent declaration integrity. Checks whether the declared configuration matches the actual infrastructure response.

Machine-readable identity and authorship

Structured data per Schema.org, canonical entity declaration, AI discovery layer (ai.txt, ai.json, llms.txt), machine-readable authorship signals, agent-card.json, WebMCP configuration.

AI Governance Hard Gate

AI policy URL, privacy AI section, robots.txt AI directives, deepfake disclaimer, AI training opt-out status, contact point for AI inquiries. The governance layer at which the regulatory requirements from Art. 50 of the EU AI Act become technically verifiable.

Note on the parameter base: CERTavia distinguishes between regulatorily anchored parameters (EU AI Act Art. 50, DORA, NIS2) and SOVP governance parameters (ai.txt, agent-card.json, llms.txt). The report lists both categories separately — with reference to the respective regulatory context.

The technical deliverable

API-capable, machine-readable, integrable into existing systems

JSON output

Every Full Scan delivers a machine-readable JSON output with all 80+ parameter values, cluster scores, overall score, and binary verdict. Directly integrable into SIEM systems, compliance dashboards, and internal reporting pipelines.

Cryptographic signature

The certificate carries a DNS-anchored cryptographic signature. The signature is independently verifiable and documents the check timestamp and infrastructure state in a tamper-proof way. Every re-scan produces a distinct, signed document.

Machine-readable verification URL

In the Pro package, CERTavia delivers a stable, machine-readable endpoint. External systems, auditors, and notified bodies retrieve the compliance status in an automated way. The endpoint follows the Sovereign Vault protocol with a 90-day TTL in the Basic package and storage with no automatic expiration date from Pro onward.

API access

From the Enterprise package, full REST API access is available for automated validation of unlimited domains. JSON response with all 80+ parameter values, cluster scores, and cryptographic evidence. Suitable for CI/CD integration and portfolio monitoring.

View API documentation

PDF audit report

The structured report with executive summary, strategic assessment across four clusters, and Sovereign Vault link is ready to hand to the board, compliance department, and external auditors.

Integration into existing infrastructure

A validation step that fits into any workflow

CERTavia is designed as a deterministic validation step that can be integrated into existing IT governance processes.

CI/CD integration

The API endpoint can be embedded as an automated validation step in deployment pipelines. Infrastructure changes trigger a re-scan and document the compliance status at deployment time.

SIEM and monitoring

The JSON output integrates directly into SIEM systems and internal monitoring dashboards. Change notifications in the Annual Subscription package add an external validation point to active monitoring.

Notified body workflow

For integration into review processes by TÜV, DEKRA, and audit firms, API access and white-label integration are available on request.

SOVP: The technical foundation

A deterministic protocol, not probabilistic scoring

CERTavia is built on the Sovereign Validation Protocol (SOVP), an open protocol for cryptographic infrastructure verification. IETF Internet Draft active, US patent pending.

The protocol contains exclusively rule-based, deterministic parameters. The same infrastructure state produces the same result on every check – no probabilistic scoring, no AI component in the check procedure itself.

Technical protocol details, IETF draft, reference implementation, and signature architecture: technologie.html →

Benchmark data

496 validated domains. Median readiness: 54.5.

CERTavia has validated 496 domains from Fortune 500 companies, DACH market leaders, and the enterprise segment. The benchmark data shows the current infrastructure state of the market — and where action is needed.

54.5
Median readiness score
Half of all checked enterprise domains fall below this value.
71.0
Q3 threshold
Only 25 percent of all checked domains reach or exceed this value.
0 / 150
Fortune 500 domains
In a sample, not a single domain delivered a complete machine-readable sovereignty declaration.

This data shows the current need for action at Layer 0 in the enterprise segment. IT leaders who want to know their own domain's status start with the free quick scan.

The right package for every technical need

Pricing for IT leaders and CTOs

Pro EUR 1,490

Full JSON and PDF output, Sovereign Vault with no automatic expiration date, machine-readable verification URL, API output. Suitable for technical evaluation and initial documentation.

Annual Subscription EUR 9,900 / year

Quarterly re-scans, annual evidence, change notifications, up to 25 domains. Suitable for ongoing infrastructure monitoring with external validation.

Enterprise from EUR 24,900 / year

Unlimited domains, monthly re-scans, 99.9% SLA, consolidated infrastructure evidence with Art. 50 reference and NIS2/DORA mapping, full API access. Suitable for portfolio-wide Layer 0 monitoring with CI/CD integration.

Annual Subscription and Enterprise automatically activate customer portal access (login via email link, no account needed); Pro can add portal access on request.

Start technical evaluation

Start technical evaluation

The quick scan delivers your domain's Layer 0 result in 90 to 120 seconds. Free, API-ready, with immediately available JSON output in the Full Scan.