Verification keys are never stored in plain text
Every verification key is one-way hashed (argon2id) before it touches our database. Even we cannot retrieve or read the original key. Only the report itself can be matched against it.
Security & Privacy
Independent testing only means something if the process around it can be trusted. Below is a plain, specific account of how submissions, reports, and communications are protected on this platform: no vague claims, just what is actually in place.
$ curl -sI https://convalencelabs.com HTTP/2 200 strict-transport-security: max-age=31536000; includeSubDomains content-security-policy: default-src 'self'; script-src 'self' 'nonce-…'; object-src 'none'; frame-ancestors 'self'; … x-content-type-options: nosniff referrer-policy: strict-origin-when-cross-origin
Anyone can run this command and see the same result.
Defence in depth
Tamper-evident certificates
When we issue a certificate we record the SHA-256 fingerprint of the exact PDF. On the Verify page anyone can compare their copy against it, in their own browser, without uploading anything.
Verify a certificateTiny edit → 0 of 64 characters changed. A tampered PDF can't match the fingerprint on record.
What is in place
Every verification key is one-way hashed (argon2id) before it touches our database. Even we cannot retrieve or read the original key. Only the report itself can be matched against it.
Certificates are generated in server memory and uploaded directly to private cloud storage. There is no public directory of past reports. Each download link is signed and expires within minutes.
The public verification page enforces a strict attempt limit per visitor, with escalating cool-down periods, in addition to Cloudflare Turnstile screening on every form.
Every uploaded photo is automatically re-processed to remove EXIF metadata, including GPS location and device information, before it is stored or embedded in any certificate.
The laboratory's admin panel requires a password and a time-based one-time code from an authenticator app, with attempt limits on both steps.
Server access uses SSH keys only; password logins for the administrator account are disabled, and only the ports each service needs are open.
We accept Bitcoin payments through our self-hosted, non-custodial payment server, hosted within the European Union. No third party ever holds or processes a payment on our behalf. We store only a payment reference linked to your order, never card or bank account details.
Our domain is configured with SPF, DKIM, and DMARC, email authentication standards that make it far harder for anyone to send a convincing message impersonating Convalence Labs.
Our database is hosted in Frankfurt (Germany) and our web and payment servers in Finland, in line with GDPR principles for data handling and residency.
Every connection to convalencelabs.com, whether browsing, submitting a request, or downloading a certificate, is encrypted in transit (HTTPS/TLS), enforced site-wide.
No system is unbreakable, and we would rather hear about a problem than have it exploited. Security reports go to [email protected], as published in our security.txt.