Assurance
What you can check yourself, and what you have to ask for
We are not going to put certification badges on a page. Standards conformance you can verify against our output without our cooperation; formal assurance status you should ask us about directly, and you will get a straight answer.
- Conformance
- Independently checkable
- Formal assurance
- Ask us
- Badges
- None
Definition
How should you verify a Digital Product Passport vendor?
Verify conformance rather than certificates. Issue a passport and check the output against the GS1 Digital Link, EPCIS 2.0 and W3C Verifiable Credentials specifications directly. That evidence does not require trusting the vendor or an auditor, and it tests the thing that actually determines whether your data stays portable.
Certificates still matter for a security review, but ask for the scope statement before the certificate. A boundary that excludes the platform holding your data is the most common way a genuine certificate turns out to be irrelevant.
Evidence
What kind of evidence is available for what
| What you want to establish | How to get it | Needs us? |
|---|---|---|
| GS1 Digital Link conformance | Issue a passport and check the identifier resolves per the specification | A sandbox key only |
| EPCIS 2.0 conformance | Append an event and validate the JSON-LD against the standard | A sandbox key only |
| Credential verifiability | Verify a signed credential with any conforming W3C library | No — that is the point |
| Data portability on exit | Export and confirm the documents are standards-conformant | A sandbox key only |
| Security controls | Send your vendor questionnaire; we complete it against your controls | Yes |
| Formal certification status | Ask during procurement — we will tell you exactly where it stands | Yes |
Conformance
The specifications we implement
GS1 Digital Link
Resolvable product identity on the data carrier. Check that a scan resolves per the specification.
GS1 EPCIS 2.0
Supply chain events in the standard JSON-LD serialisation. Validate ours against the schema.
W3C Verifiable Credentials 2.0
Signed claims that verify with any conforming library, without calling us.
W3C Decentralized Identifiers
Issuer identity that resolves independently of this platform.
CIRPASS · CEN-CENELEC JTC 24
The passport data model the delegated acts are converging on.
ISO 14040 · 14067 · 59020
The methodologies footprint and circularity figures are recorded against.
Answers
Frequently asked questions
Do you hold SOC 2 or ISO 27001?
Not something we will claim on a web page. Formal assurance is on our roadmap and we will publish each certification here when it is issued, with the certifying body, the scope statement and the validity period attached. Until then, ask us directly during procurement and you will get a straight answer about current status.
Why does scope matter more than the certificate?
Because a certificate says an audit happened against a defined boundary, and the boundary is the interesting part. A certificate covering a corporate IT function tells you almost nothing about the platform holding your passport data. Whoever you are assessing, ask which systems the scope statement actually names.
Is GDPR a certification?
No. It is a legal obligation, not an audited scheme, so "GDPR certified" is not a meaningful claim from anyone. What can actually be evidenced is the data processing terms, the subprocessor list, the transfer mechanism and the security measures behind them — all of which we will provide.
What can I verify without talking to you at all?
Standards conformance. Issue a passport against a sandbox key and check the output directly against the GS1 Digital Link, EPCIS 2.0 and W3C Verifiable Credentials specifications. That is a stronger form of evidence than a badge, because it does not depend on trusting either us or an auditor.
How do we assess you in the meantime?
Send your vendor questionnaire to ceo@fistasolutions.com. We will complete it against your specific controls, and where the honest answer is that something is not yet in place we will say so rather than answering around it. That is more useful to a security reviewer than a badge would be.
Next step
Send the questionnaire, get a straight answer
Including where the answer is that something is not yet in place. A reviewer can work with that; a badge that turns out to be irrelevant at scope review wastes everyone's time.