How our certificate check works

A certificate you can't fake, even with AI

Today anyone can make a perfect-looking certificate in a minute. So we stopped trusting how a certificate looks. A RoadVerified certificate is only a pointer to a record the school can't secretly change and nobody else can touch.

Six layers, and what each one stops

The check page is the truth, not the paper

A faker tries: Edit the PDF: change the name, the dates or the hours. Or ask an AI to make a brand-new certificate that looks perfect.

Why it fails: Scanning the QR code or typing the code opens the school's own record on our site. If the paper says anything different, the paper is fake. How good the fake looks no longer matters.

A fingerprint of the exact file

A faker tries: Keep the real code and QR, but change one detail on the PDF and hope nobody opens the check page.

Why it fails: We keep a SHA-256 fingerprint of the one official PDF. Upload any copy on the check page and it says either "Exactly the file we issued" or "This file was changed". One changed character is enough to fail.

A seal and a pattern unique to each certificate

A faker tries: Copy a real certificate's layout, seal and code onto another student's certificate.

Why it fails: The security seal is computed from the certificate's own contents with a secret key only our server holds. The banknote-style pattern behind it is drawn from the certificate's own code. Neither carries over to another certificate.

Only real, verified schools

A faker tries: Sign up as a made-up school, or borrow a real school's name and license number.

Why it fails: The license must match the state's official list, and the school name must match that license. A license can belong to only one account. Verified schools also send their license and the owner's ID, and we call the number the state has on file. The name, license and address lock once a school starts issuing.

A public ledger nobody can rewrite

A faker tries: Someone on the inside, or a hacked account, quietly adds an old-looking certificate or edits one after the fact.

Why it fails: Every certificate event goes into a public, append-only ledger where each entry locks in the one before it. Backdating or editing breaks every link after it, and anyone who saved a daily checkpoint can prove it. That includes catching us.

Every lookup is logged

A faker tries: Guess codes, or scrape student records through the insurer portal.

Why it fails: Codes are random, and checks are rate limited, so guessing goes nowhere. Insurers see a certificate only when the family sends it or gives them the code. Every insurer lookup goes into a log that can't be edited or deleted.

What makes this hard to copy

Anyone can print a QR code. What's hard to copy is everything behind it: official lists of licensed schools from 32 states so far, and the certificate rules for all 50; schools that have been checked one by one; and a ledger that has been running since the first certificate. A new copycat would start with none of that.

Check one now

Scan the QR code on any RoadVerified certificate, or type its code on the check page. To see the ledger itself, open the public ledger. To see how we protect student data, read Security.