Integrity
Why the record can be checked.
We keep the record and we sell the program it describes. The useful distinction is therefore between what we say about the record and what the record allows others to check.
The record is not built to be trusted. It is built to be checked.
There is no edit path
The record accepts new entries and nothing else: no update, no delete, and no correction in place. A correction is a new entry beside the old one, and both remain readable.
There is no administrative operation that removes a finding. Nobody at this company can make a recorded reading disappear.
Each entry seals the one before it
Every entry carries a fingerprint of the entry that preceded it. If an entry is changed, the entries after it no longer reconcile. The result can be checked independently.
This makes an altered row detectable. The chain alone does not prevent a complete reconstruction by someone with full access. That is why the external anchor matters.
The root goes where we cannot reach it
Each hour, a single value covering every record we hold is fingerprinted for publication to a public ledger outside our control. Once published, such a value cannot be moved, amended, or withdrawn. The mechanism is built; the ledger partner is not yet appointed, so no value has been published yet.
Illustrative. The public ledger partner is not yet appointed; the values below show the form a reference will take and are not live.
The most recent anchor
An ordinary transaction on a public ledger, carrying the value. A fingerprint, not the record: nothing about any organization is on a public chain.
- Published reference
- 0x7c4e1b93af02d658e17c39b4a0f5d82c6b91e370452fda8c19b73e60fa2c485d
- Block
- 25,848,093
- Block time
- 06 Sep 2026 14:00:07 UTC
- Anchored value
- 0x3a91c7f0e284bd56179c4fa8e03b21d75c68ff41920ae7d3b85c04619ef2a7d8
- Period covered
- 06 Sep 2026 13:00 — 14:00 UTC
- Cadence
- hourly
- Preceding anchor
- 0x6b0d4e8137fa25c9e0741b3ad86f92c50e3b7148ad920cf6e15837b4029da6c1
Checking a record against it, without asking us
- Hash your copy of the record.
- Follow the path from that hash to the anchored value. The path travels with the downloaded copy.
- Look the published reference up on any node or public explorer of the appointed ledger.
- Confirm its data field equals the anchored value above.
- The block time is when the value was published. Nothing written into the record after that moment can change what it contained before it.
What an anchor proves, and what it does not. It establishes what the record contained at that point in time and whether the record has subsequently been altered. It does not establish that the readings were correct or prove authorship. The ledger stores a fingerprint, not the record, so the record itself must be retained if it is needed.
The worst case, stated rather than hedged
This platform is breached tomorrow. Somebody has full access to the database and rewrites whatever they like.
Every altered entry stops reconciling against a value they never had and could not reach. It is visible to anyone holding the anchor, immediately, without asking us anything.
A breach of this company cannot make a false credential true.
An altered record can fail to reconcile with the anchored value. The anchor therefore provides a way to detect alteration independently of this company.
This is infrastructure, not a product
A product works while its vendor is healthy. Infrastructure keeps working when the vendor is breached, sold, or gone.
The ability to check an anchored record does not depend solely on our security posture, staff, or continued existence. A record established today can be checked later using the published anchor and a ledger we do not operate.
This gives two parties a common record that neither party can change: for example, a carrier and its insured, or a bank and its customer.
The important property is the absence of discretionary editing.
What we can still get wrong
None of the above makes the readings correct. An anchor fixes what the record said; it says nothing about whether the reading itself was true.
A vendor can report a machine as healthy when it has not been seen for fifty days. A permission can be scoped so narrowly that a population is only partly enumerated. A source can send us a file that appears complete but is truncated in fact.
Those are real and they are ours to catch. Where a reading is incomplete or a source is unreliable, the record says so and the safeguard is held at what was actually established rather than what was claimed. The way we describe our own limits is in Method, and it is the more useful page of the two.
Who operates this, and who owns it
The Cyber Credential Registry is owned by CyberStanding and lives at mycyberstanding.com. It is operated by Cyber Assurance Group, a separate company, which also sells a security program many registered organizations use. We state that plainly rather than obscure it, because a registry that hides its operator has given you a reason to wonder what else it hides.
The registry is indifferent to whose product it is reading. A business that buys its endpoint protection elsewhere, or satisfies its training requirement through another body, is read exactly the same way and reaches exactly the same tiers. Every reading is decided by one published definition set, applied identically to every vendor, and the definitions are the same document you can read on the Method page.
The important separation is between the record and our discretion over it. The record is designed to be checked without relying on our word.