The V2P Trust Seal

A current status with a visible evidence boundary.

The seal is a dynamic link to the most recently issued, time-stamped source-audit result. It lets a visitor inspect what was assessed, when it was assessed, and what the result does—and does not—cover.

V2P Verified Site trust seal
Time-stamped statusRefreshed by a newly issued audit result

Two trust marks. Different jobs.

Static placement. Dynamic verification.

The pill remains a compact, stable footer element on the host website. The seal is the richer status surface tied to the latest issued result.

V2P Verified Site footer pill

Static footer pill

A compact badge that stays in a consistent footer position on the host website. Hover or keyboard focus can reveal the issued score; clicking it opens the verification explanation.

“Static” describes its placement—not stale evidence.

V2P dynamic verification seal

Dynamic verification seal

The richer verification mark. It resolves to the most recently issued public result, so an eligible re-audit can update the displayed status, score, scope, and date.

Dynamic means issuance-based updates—not continuous runtime monitoring.

The certificate remains the fixed record.

It preserves one specific snapshot, scope, score, status, fingerprint, audit version, and issue date for documentation and procurement.

What a visitor can verify.

The public record communicates the current issued result without publishing proprietary source code or private findings.

Current public status and score
Assessed source scope and revision
Issue date and audit version
Source fingerprint

How the status changes over time.

01

Audit a defined snapshot

V2P assesses the submitted source at a specific revision and declared scope—not an undefined or continuously changing codebase.

02

Issue an eligible result

A public status is issued only after the score and applicable coverage, pillar, and critical-security gates are evaluated.

03

Link the seal to the record

The embeddable seal gives visitors a direct path to the public verification record while detailed findings and source remain private.

04

Re-audit to refresh

After material code changes, the team submits a new snapshot. A newly issued result supersedes the previously displayed status.

What the seal communicates

A stated source snapshot met the V2P source-audit standard at the displayed revision, scope, score, status, and date.

What it does not communicate

It is not continuous runtime monitoring and does not prove infrastructure, deployment identity, ownership, compliance, or the absence of vulnerabilities.

Make the current source result easy to verify.

Audit one defined source snapshot, review the private evidence, and issue a scoped public status only when it is ready.

Start your source audit
Vibe to Production Verified Site