How verification works
Methodology and limits
Hera Verify is independent of the companies it lists and of the firms that audit them. We do not perform audits, we do not sell certification, and we publish the source behind every record.
- 01
Document received
A company or its auditor submits the attestation letter, certificate or Attestation of Compliance, including the certificate number and period covered.
- 02
Issuing body checked
We confirm the issuer is entitled to issue that attestation: an accredited certification body for ISO/IEC 27001, a PCI SSC Qualified Security Assessor for PCI DSS, or a licensed CPA firm such as Armanino LLP for SOC 1 and SOC 2.
- 03
Cross-referenced to a public source
Where a free official registry exists, we record the exact source used and keep the link on the record so anyone can repeat the check.
- 04
Published and monitored
Records expire automatically at the end date. Suspensions and withdrawals are applied when the issuing body or the company notifies us.
What each status means
- Verified — in force
- Checked against the issuing body or an official registry, and inside its validity period.
- Expired
- The validity period has ended. A renewal may exist but has not been submitted here.
- Suspended
- The issuing body has paused the certificate, usually pending corrective action.
- Revoked
- The certificate or attestation has been withdrawn and must not be relied on.
Where our independence ends
A registry record is evidence, not a guarantee. Only the issuing body can confirm that a certificate is currently in force, and only the full report shows the exceptions an auditor raised. For a high-value decision, request the signed report under NDA and confirm the issuer in a public registry.
See the free public registries