What Those Certifications Actually Certify, and Why We Hold None of Them

Nothing on this page is legal advice.

What they certify, which is narrower than people assume

That an organisation does what it says it does.

You write down your controls. Somebody independent checks that the controls exist, that they are operating, and that evidence supports it. The output says your described system matches your actual system over some period.

They do not certify that your described system is adequate. A company can hold one of these with weak controls, provided the weak controls are documented, followed, and evidenced. That is not a loophole; it is what the instrument is for, and reading it as a security grade is the common mistake.

And the second distinction: certification is not a code audit

One is an assessment of an organisation's management system. The other is somebody reading your code looking for flaws.

A product can hold the first and have never had the second, and vice versa. The category treats them as interchangeable signals and they measure different things entirely.

We have neither, which at least spares us the temptation to imply one from the other.

Where we actually stand

There is nothing an assessor could assess. Certification audits a documented control set with an evidence trail; ours does not exist as a document. The honest blocker is not cost or time, it is that the prerequisite artefact has not been written.

The unfavourable input, since a comparison page already carries it

A product in this exact category holds two of these certifications and is independently audited, per our own brief captured 2026-05-31 and extended 2026-06-13.

We stated that on its comparison page and we are repeating it here rather than letting a page about certifications quietly omit the fact that a competitor has them and we do not.

We are also not going to argue that certifications matter less than they look. That argument exists, it is sometimes even correct, and making it from a position of holding none would be transparently self-serving.

What is already built, because absences alone would misdescribe us

The key-custody design is deliberate and would survive scrutiny: generated on device, never written to disk, unrecoverable by us, with the usability cost paid openly every time a reload locks the wallet.

The engineering that has been read closely holds up: the sign-in client checks more than the server requires, the recovery approvals are bound against replay, and the key module stores hashes rather than keys.

That is evidence of practice, and it is not evidence of certification. The two are different, and this page exists partly so nobody reads the first as the second.

What a buyer should take from this

Ask what the certification covers, because scope is chosen by the party being certified.

Ask whether there has also been a code audit, because the answer is often no and the two get conflated.

And for us, the answer to both is no, which is the correct input to a decision even though it is not the input we would prefer.

Keep reading

What Those Certifications Actually Certify, and Why We Hold None of Them · Solidus