AcadCert is a technology intermediary: institutions issue cryptographically signed credentials, and anyone can verify them. The notes below cover the operational and compliance questions that come up during evaluation. Security and compliance are described as practices we implement, not certifications we hold.
Where is our data stored, and can we export it?
Credential records and document contents are held on encrypted servers with role-based access. Institutions can request an export of their public key material and credential records at any time, and retain access during a wind-down period if they leave.
How does AcadCert handle student privacy (e.g. FERPA, PDPA, GDPR)?
AcadCert acts as a data processor on behalf of the institution. It runs no advertising and no third-party analytics, sets no tracking cookies, and never sells personal data. The public verification result redacts the holder’s email. AcadCert builds to the data-protection principles behind PDPA and GDPR; these are practices, not certifications.
Can AcadCert integrate with our SIS or registrar system?
Yes. Credentials can be issued programmatically through the API, and webhooks notify your systems on issuance and revocation. Contact the team to scope an integration for your student information system.
What availability can we expect?
Verification is designed to keep working even if AcadCert is unavailable, because the proof is cryptographic and travels with the credential file. Institutions can also generate a point-in-time verification receipt, a cryptographically signed record confirming a credential’s validity at a specific moment, useful for audit trails or procurement documentation. For issuance and dashboard availability and support response, see the status page and your plan terms.
Who are your sub-processors?
Institutions can request an up-to-date list of current sub-processors. AcadCert gives thirty days’ notice of any material change to that list.
What happens to issued credentials if we leave AcadCert?
Signatures already issued remain mathematically valid and verifiable. Institutions receive an export of their public key material and credential records so verification can continue.
Still have questions?
For the technical detail (signature scheme, key handling, encryption, audit logging), see the security page. For anything specific to your institution, reach the team on the contact page.
- Onboarding and setup: onboarding@acadcert.com
- Security and disclosure: security@acadcert.com