Platform
Show what you actually check, not what you claim
A Trust Profile is a page you publish that lists evidence Nivaronix already holds about your infrastructure — verified domain ownership, monitoring history, uptime over the last 30 days, and credentials earned from checks that ran. Every line on it is re-derived from the underlying record each time the page loads, so it cannot say something your account stopped supporting.
What this is — and what it is not
Nivaronix issues evidence of checks it ran on your account. That is the whole claim. A Nivaronix credential is not a certification, not an audit, not a compliance attestation, and not a statement that your systems are secure. It records something specific and checkable — that a domain proved ownership, that a scan reached a particular score, that monitoring ran for a particular stretch — and it links to a page where anyone can read the exact rule behind it.
- Nothing here is hand-issued. Awards are written by the evaluator alone; there is no operator grant path and no way to self-assert a credential.
- There are no referral badges, no share-to-earn badges, and no counters for scans run or days logged in — those would measure usage, not anything about your infrastructure.
- No badge is keyed to your own uptime record, which would mean taking a badge away on the day you had an outage — the very event the product exists to catch.
How a Trust Profile works
It starts private
A profile is created the first time you open it, unpublished, on a random placeholder address nobody has been given. Nothing is public until you publish it.
You choose the address
Your profile lives at /trust/<your-slug>. Slugs are 3–63 characters, lowercase letters, digits and single hyphens. A short list of platform and generic words (admin, api, status, nivaronix, and similar) is blocked — that list exists to stop confusing addresses, not to arbitrate brand ownership.
You choose what goes on it
Four kinds of item can be added: a verified domain, an issued public badge, a credential, or a monitor's uptime figure. Each one has to belong to your organization — the server checks ownership of the referenced record before it will attach it to a page that may be public.
You control the order, and the off switch
Items can be reordered or removed one at a time, and unpublishing takes the whole profile down immediately. What you saw in preview is exactly what a visitor sees: the owner preview and the public page run through the same single render path.
Exactly what a published profile shows
A published profile returns the name and short description on the profile, a category you typed in yourself (shown labelled as self-described, because that is what it is), and one status line per item you added. Nothing else about your account is reachable through it.
| Item you add | What the public page shows |
|---|---|
| Verified domain | The domain name and the date its ownership was verified. If the asset is no longer verified, the line says verification is unavailable rather than quietly disappearing. |
| Public badge | The date monitoring on that asset began, and the badge type. If the badge is revoked or switched off, the line says so. |
| Credential | The credential's public identifier, which resolves to its own verification page. Revoked or withdrawn credentials read as no longer active. |
| Monitor uptime | A single uptime percentage over the last 30 days, from the same calculation the dashboard uses. If there is not enough data, it says so instead of estimating. |
What is never on it
- No incident history, no failing checks, no findings, no scores, and no live up/down signal.
- No internal identifiers, no asset ids, no email addresses, and no team member names.
- An unpublished profile and a slug that never existed return the identical response, so nobody can use the address to test whether an organization is a customer.
No status is stored on the profile itself. Every line is recomputed from the source record on each request, so a revoked verification or a disabled badge stops showing the moment it changes — not on the next refresh of something cached.
Renaming does not break a link you already shared
When you change your slug, the old one is kept permanently as an alias pointing at the profile, and it can never be claimed by another organization. Anyone who follows the old address is redirected to the current one with a real permanent redirect from the server, before any page is rendered.
Branding
A profile renders in one of two modes: the default Nivaronix presentation, or your own. Custom Trust Profile branding is included on the Studio plan. The gate is presentational only — the evidence on the page, and how it is derived, is identical on every plan.
Compare plansHow a credential is earned
Credentials are awarded automatically, by evaluating your own account data against a published rule. You cannot request one, buy one, or assert one — and neither can we hand you one.
The rule is evaluated against your account
Two catalogues exist. Security badges each carry a hand-written rule — for example, every asset on the account has passed ownership verification, or an asset that scored a failing grade on one scan scored a passing grade on a later one. Milestones are defined as data over four reusable shapes: days elapsed since an anchor, a count crossing a threshold, a trailing window with no incidents, and an event that happened at least once.
It is recorded once, with its evidence
The first time a rule is observed true, an award is written with a snapshot of the evidence behind it and the exact version of the rule that decided it. A uniqueness constraint means it fires once and only once, even if two evaluations race.
The rule version is frozen at that moment
If a rule's meaning is later changed, the version stored with your award does not move. A rule change can never retroactively alter what an already-issued credential is understood to mean.
A public verification handle is issued automatically
Every award gets an opaque public identifier and its own verification page. You can withdraw a credential from public view at any time, and a withdrawn or revoked one stops resolving.
Some credentials are permanent: they record something that happened and cannot un-happen, so they are never re-checked. Others describe a state that is true right now — those are re-evaluated live when the verification page is loaded, and read as no longer active the moment the state stops being true.
What a third party sees when they check one
Every credential resolves to its own page at /credential/<id>, served by Nivaronix, rendered from live data rather than a stored image. Anyone with the link can open it — no account, no login.
- Status
- Verified, or no longer active — for a live-state credential, decided at the moment you load the page.
- Statement
- What holding the credential means, in the same words shown to the customer.
- Evidence
- One plain sentence about why it was earned, written per credential and reviewed for disclosure.
- Issued
- The date the rule was first observed true.
- Credential ID
- The opaque public identifier in the URL.
- Rule version
- The version of the rule that decided this award.
- Verified at
- The timestamp of the check that produced the page you are reading.
Why that page can be trusted by someone who has never heard of us
- It is served by the issuer. The page has no static copy to drift out of date — it asks the credential API on each load, which is what makes the answer authoritative.
- It carries no organization-identifying information. A credential answers whether Nivaronix verified something, not who the customer is, so a shared link discloses nothing about the account beyond the credential itself.
- The evidence sentence is written by hand for each credential and never echoes the internal audit record, so a field added internally cannot leak onto a public page by omission.
- Unknown, withdrawn and revoked identifiers all return the same not-found response, so the page cannot be used to probe which one a given identifier is.
Badges you can embed on your own site
A published profile can issue a badge image that links back to it, and a verified asset can carry a monitoring badge. Both are deliberately restrained about what they say.
The monitoring badge carries a date, and nothing else
It says monitoring has run since a given date. It will never say a site is currently up. A live health signal published on the customer's own site, pollable by anyone, is a reconnaissance feed for whoever is deciding when to attack them — so there is no option that turns one on.
The certificate seal expires on its own evidence
The SSL seal asserts only that a certificate check passed recently. If the freshest passing check is more than 24 hours old, the image stops being served rather than continuing to imply something no longer supported.
A badge can only exist for a verified asset
Ownership verification is the gate, and it is re-checked when the image is rendered, not just when the badge was issued.
Common questions
- Is a Nivaronix credential a security certification?
- No. It is not a certification, an audit, or a compliance attestation, and it does not state that your systems are secure. It records that a specific check Nivaronix ran produced a specific result, and links to a page stating the exact rule and the evidence behind it.
- Can I award myself a badge, or ask for one?
- No. Awards are written only by the evaluator that tests the rule against your account data. There is no operator grant path, no purchase, and no self-assertion.
- Does my Trust Profile expose my incidents or failing checks?
- No. A published profile shows only the items you added, each as a single status line: a verified domain and its verification date, a badge and its start date, a credential identifier, or a 30-day uptime percentage. Incident history, findings, scores and live up/down status are not on it.
- What happens to a credential if the thing it describes stops being true?
- It depends on the credential. Ones that record an event that happened are permanent and are not re-checked. Ones that describe a current state are re-evaluated when their verification page loads, and show as no longer active once the state no longer holds.
- Can I take a profile or a credential down?
- Yes. Unpublishing takes the whole profile offline immediately, and individual items can be removed. A credential can be withdrawn from public view, after which its verification page stops resolving.
- If I rename my profile, do existing links break?
- No. The previous address is kept permanently and redirects to the current one, and it cannot be claimed by anyone else.
Related
Start with a measurement
Credentials are awarded from checks that ran on your own estate, so the first scan is where any of this begins.
Scan your domain free