CERTavia CERTavia Vault — Cryptographic Verification Record ID: cv_101e93359321c148
🇬🇧 EN🇩🇪 DE

CERTavia is an independent technical compliance-evidence methodology developed by Litzki Systems LLC for organizations deploying AI-adjacent systems. It evaluates infrastructure integrity, machine readability, identity consistency, transparency, agentic declarations, and AI governance across 6 clusters — producing a binary verdict of CERTIFIED or FAILED. This is a technical assessment, not a legal opinion and not a conformity assessment under EU AI Act Art. 43.

This is a read-only, time-stamped verification record anchored at time of audit completion. No rescan occurs on this page. The data reflects the state of certavia.org at the moment of the CERTavia Compliance Audit. Record expires 90 days after issuance.
Audit Verdict
✓ CERTIFIED
EU AI Act · CERTavia v1.1
CES Score
88 /100
CERTavia Compliance Score
Valid Until
October 7, 2026
⇓ Download PDF Report
Technical Score Breakdown
CES
88
/100
CERTavia Compliance Score
EU AI Act Annex III
CERTavia Compliance Audit v1.1
Compliance Clusters A–F (click to expand)
Cluster A Digital Infrastructure
96/100 PASS
Art.15 DORANIS2
1 Parameter nicht erfüllt: integration.sslGrade.
Technische Sicherheitsinfrastruktur erfüllt DORA- und NIS2-Anforderungen vollständig.
SPF Record NIS2 Art.21
DMARC Record NIS2 Art.21
DMARC Policy (Enforcement) NIS2 Art.21 / DORA Art.13
CAA Record NIS2 Art.21
DNSSEC DORA Art.13 / NIS2 Art.21
SPF Permissiveness (+all) NIS2 Art.21
DMARC Reporting (rua=) NIS2 Art.21
HSTS (Strict-Transport-Security) DORA Art.13 / NIS2 Art.21
HSTS (max-age ≥ 1 year + preload) DORA Art.13
X-Content-Type-Options NIS2 Art.21
Framing Protection (X-Frame-Options) NIS2 Art.21
Referrer Policy NIS2 Art.21
Content Security Policy (CSP) DORA Art.13 / NIS2 Art.21
No Server Version Disclosure NIS2 Art.21
HTTP/2 (ALPN) DORA Art.13
HTTP/3 (QUIC)
HTTPS Only (no HTTP) DORA Art.13 / NIS2 Art.21
TLS Grade (Target: A or A+) DORA Art.13
Disable TLS 1.0 and 1.1. Recommended nginx config: ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:...; ssl_prefer_server_ciphers on; Test with SSL Labs: ssllabs.com/ssltest
Google Safe Browsing NIS2 Art.21
sameAs URLs Reachable Art.13 EU AI Act
Security Header Score NIS2 Art.21
No Mixed Content NIS2 Art.21
MX Record (Mail Server) adjusted
Cluster B Data Protection & Consent
72/100 PASS
Art.13Art.50
5 Parameter nicht erfüllt: aiSignals.webCorpusIndexing, aiSignals.aiCitability, D2.definedTerm….
Inhalte maschinenlesbar aufbereitet. Art.13-Transparenzpflicht nachweisbar erfüllt.
API Catalog (OpenAPI/JSON) Art.13 EU AI Act
JSON-LD SoftwareApplication Art.13 EU AI Act
Link Header (RFC 8288) RFC 8288
LLMS Structured (Sections) Art.13 EU AI Act
LLMS Content Coverage Art.13 EU AI Act
LLMS / Sitemap Consistency Art.13 EU AI Act
/llms.txt Art.13 EU AI Act
/llms-full.txt Art.13 EU AI Act
/.well-known/sovp-identity.json SOVP RFC draft-03
Knowledge Cluster (JSON-LD) Art.13 EU AI Act
/agents.md RFC 9727 / Art.13 EU AI Act
D2.agentsMdStructured
llms.txt (Agentic Readability) Art.13 EU AI Act
Web Corpus Indexing Art.13 EU AI Act
Open robots.txt for AI crawlers: "User-agent: CCBot\nAllow: /" and "User-agent: GPTBot\nAllow: /". Check for wildcard blocks affecting AI bots.
AI Citability Art.13 EU AI Act
Improve citability for AI: add DOI or permanent URLs for key content, structured author information (schema.org/author), and machine-readable publication dates (datePublished).
Speakable (schema.org)
sameAs Authority (Wikidata/Wikipedia) Art.13 EU AI Act
DefinedTerm (JSON-LD) Art.13 EU AI Act
Include at least one DefinedTerm entity in the JSON-LD of the main page: {"@type":"DefinedTerm","name":"Technical Term","description":"Explanation"}.
DefinedTerm (Rich) Art.13 EU AI Act
Enrich DefinedTerm entries with additional fields: termCode, inDefinedTermSet, url. At least 3 technical terms with complete data.
Markdown Pages Available Art.13 EU AI Act
Provide Markdown versions of key pages (e.g. /about.md, /products.md) or link to Markdown sources in llms.txt.
Cluster C Legal Compliance
86/100 PASS
Art.13
2 Parameter nicht erfüllt: schema.hasDefinedTerm, D4.wikipedia.
Unternehmensidentität konsistent über alle Quellen. Identitätsnachweis erbracht.
RCC llms.txt Policies SOVP RCC / Art.13 EU AI Act
RCC JSON-LD Compliance SOVP RCC
RCC DNS-TXT Declaration SOVP RCC
JSON-LD Present Art.13 EU AI Act
Organization Schema Art.13 EU AI Act
Person Schema (Responsible Persons) Art.13 EU AI Act
FAQ Schema
Date (datePublished) Art.13 EU AI Act
sameAs (Identity Proofs) Art.13 EU AI Act
Canonical URL
Language Attribute (lang=) DSGVO / Barrierefreiheit
Robots Meta (Correct) Art.13 EU AI Act
Internal Links Reachable
DefinedTerm in Schema Art.13 EU AI Act
Include DefinedTerm entries for key organizational terminology in JSON-LD. Each term should have name, description, url. Reference: schema.org/DefinedTerm.
Semantic HTML
Wikipedia Entry Art.13 EU AI Act
Create a Wikipedia entry (if notability criteria are met) or review an existing entry for accuracy. Link the Wikipedia article URL in the JSON-LD sameAs array.
Wikidata Entry Art.13 EU AI Act
Cluster D Transparency
70/100 PASS
Art.50
3 Parameter nicht erfüllt: consent.coverage, consent.consistency, consent.granularity.
Consent-Management und Bot-Zugangspolitik dokumentiert und konform nach Art.50.
Consent Coverage DSGVO / Art.50 EU AI Act
Activate a cookie consent banner on all pages of the domain. Platforms: Cookiebot, OneTrust, Usercentrics, or a custom IAB-TCF-compliant implementation.
Consent Consistency DSGVO / Art.50 EU AI Act
Deploy the consent banner consistently across all subdomains and pages. Resolve inconsistencies between subdomains (www. vs. non-www).
Consent Granularity DSGVO Art.7 / Art.50 EU AI Act
Break consent down by category: Necessary / Statistics / Marketing / AI Personalisation. Users must be able to accept or reject each category individually.
AI Crawler: GPTBot (OpenAI) Art.53 EU AI Act
AI Crawler: ClaudeBot (Anthropic) Art.53 EU AI Act
AI Crawler: PerplexityBot Art.53 EU AI Act
AI Crawler: OAI-SearchBot (OpenAI) Art.53 EU AI Act
AI Crawler: Google-Extended (Bard/Gemini) Art.53 EU AI Act
AI Crawler: anthropic-ai Art.53 EU AI Act
AI Crawler: CCBot (Common Crawl) Art.53 EU AI Act
Cluster E Agentic Readiness
100/100 PASS
Art.13Art.50
Alle Parameter erfüllt (100/100).
Agentic-Schnittstellen vollständig deklariert. Maschinelle Interoperabilität nachweisbar.
MCP Endpoint (/.well-known/mcp.json) SOVP RFC draft-03
API Catalog (OpenAPI/JSON) Art.13 EU AI Act
/agents.md RFC 9727 / Art.13 EU AI Act
Link Header (RFC 8288) RFC 8288
/llms.txt Art.13 EU AI Act
Cluster F AI Governance
100/100 PASS
Art.14Art.50DORA 19
AI-Governance: 100/100 (122/135 Rohpunkte: 120 Kern + 15 Deklarations-Bonus)
KI-Governance-Deklaration vollständig. Kernnachweis für CERTIFIED erfolgreich erbracht.
AI System Disclosure (ai-disclosure.json) Art.13 EU AI Act25/25pts
Human Oversight (Art. 14) Art.14 EU AI Act20/20pts
Annex III Classification Annex III EU AI Act20/20pts
Data Governance (Art. 10) Art.10 EU AI Act20/20pts
Technical Documentation (Art. 11) Art.11 EU AI Act20/20pts
incidentReporting Art.73 / DORA 1912/15pts
AI Policy Page Art.50 EU AI Act0/3pts
Publish a dedicated AI policy page, e.g. under /ai-policy — a short overview of which AI systems are in use and how users are affected.
AI Section in Privacy Policy Art.13 EU AI Act3/3pts
AI Bot Directives in robots.txt Art.50 EU AI Act2/2pts
Deepfake/AI Content Disclaimer Art.50 EU AI Act0/2pts
If AI-generated content (text, image, video) is published: add a clear disclaimer on the relevant page or in the legal notice.
AI Training Opt-Out Notice Art.10 EU AI Act0/3pts
Add an opt-out notice regarding the use of site content as AI training data to the privacy policy or a dedicated page.
AI Contact Point Art.14 EU AI Act0/2pts
Provide a reachable email address in the legal notice or contact page that can also be used for AI governance inquiries.
Cryptographic Attestation
CERTaviaAttestation Signature Present
Subject Domain certavia.org
Verdict CERTIFIED
CES Score 88.3
Issued by certavia.org
Framework CERTAVIA_V1
Signed Jul 9, 2026, 04:12 PM
Expires
Public Key Ref dns:txt:_sovp.certavia.org
Signature (Ed25519) RqvHqXkEJaDOjb7tkNuupuvDQsyptDWXo48gdkIai7Zy+Qrv…
Full Attestation Document (JSON)
{
  "@context": "https://litzki-systems.com/protocol/v1.5",
  "@type": "CERTaviaAttestation",
  "attestation": {
    "ces_score": 88.3,
    "compliance_framework": "CERTAVIA_V1",
    "issued_by": "certavia.org",
    "scanned_at": "2026-07-09T16:12:59.345Z",
    "valid_until": "permanent",
    "vault_hash": "101e93359321c148",
    "verdict": "CERTIFIED"
  },
  "subject": {
    "canonical_url": "https://certavia.org",
    "domain": "certavia.org"
  },
  "integrity_proof": {
    "signature": "RqvHqXkEJaDOjb7tkNuupuvDQsyptDWXo48gdkIai7Zy+QrvN1YYnHgnF2V2+0vmndsSdG70TEvw9+gh+Pd0DA==",
    "created": "2026-07-09T16:12:59.349Z",
    "public_key_ref": "dns:txt:_sovp.certavia.org",
    "nonce": "50bed183-7390-4201-bdb5-c6ca52a39bcf"
  }
}
Embed This Certificate

Paste this HTML snippet on your website to display a verifiable badge for this certificate.

<a href="https://certavia.org/verify?hash=101e93359321c148" target="_blank" rel="noopener noreferrer" style="display:inline-flex;align-items:center;gap:14px;background:#fff;border:1px solid #e5e7eb;border-radius:10px;padding:14px 18px;text-decoration:none;font-family:system-ui,sans-serif;max-width:520px;box-shadow:0 1px 4px rgba(0,0,0,.06);"> <img src="https://certavia.org/assets/img/certavia-seal-light.png" width="56" height="56" alt="CERTavia CERTIFIED" style="display:block;object-fit:contain;flex-shrink:0;"> <span style="flex:1;min-width:0;"> <span style="display:block;font-size:14px;font-weight:600;color:#1e3b5f;margin-bottom:2px;white-space:nowrap;overflow:hidden;text-overflow:ellipsis;">certavia.org</span> <span style="display:block;font-size:11px;font-weight:500;color:#4b6080;margin-bottom:6px;">CES 88 · Zertifiziert bis 09.07.2027</span> <span style="display:flex;gap:4px;flex-wrap:wrap;"><span style="font-size:10px;font-weight:600;padding:2px 6px;border-radius:4px;background:rgba(30,59,95,.08);color:#1e3b5f;border:1px solid rgba(30,59,95,.2);">A ✓</span> <span style="font-size:10px;font-weight:600;padding:2px 6px;border-radius:4px;background:rgba(30,59,95,.08);color:#1e3b5f;border:1px solid rgba(30,59,95,.2);">B ✓</span> <span style="font-size:10px;font-weight:600;padding:2px 6px;border-radius:4px;background:rgba(30,59,95,.08);color:#1e3b5f;border:1px solid rgba(30,59,95,.2);">C ✓</span> <span style="font-size:10px;font-weight:600;padding:2px 6px;border-radius:4px;background:rgba(30,59,95,.08);color:#1e3b5f;border:1px solid rgba(30,59,95,.2);">D ✓</span> <span style="font-size:10px;font-weight:600;padding:2px 6px;border-radius:4px;background:rgba(30,59,95,.08);color:#1e3b5f;border:1px solid rgba(30,59,95,.2);">E ✓</span> <span style="font-size:10px;font-weight:600;padding:2px 6px;border-radius:4px;background:rgba(30,59,95,.08);color:#1e3b5f;border:1px solid rgba(30,59,95,.2);">F ✓</span></span> </span> <span style="font-size:12px;font-weight:600;color:#fff;background:#1e3b5f;border-radius:7px;padding:8px 13px;white-space:nowrap;flex-shrink:0;">Verifizieren ↗</span> </a>
Independent Verification
Who stands behind CERTavia?
CERTavia is a technical compliance-evidence methodology developed and operated by Litzki Systems LLC (Florida, USA). The scoring methodology is the Sovereign Validation Protocol (SOVP), submitted to the IETF as draft-litzki-sovp-03. Protected by U.S. Provisional Patent Application No. 64/005,737.

Thorsten Litzki, inventor of SOVP and founder of Litzki Systems LLC, is responsible for the design and integrity of the CERTavia scoring framework.