I — Datum

Verifiable Calibration Certificates

A calibration certificate is relied upon by people who were not present for the calibration and hold no account with the issuer. SVEND issues each one against a hash-chained record, so a recipient can establish that the document in their hands matches what the issuer recorded, and that the record has not been altered since.

Ref: ISO/IEC 17025 · JCGM 200 (VIM) · ANSI/NCSL Z540.3 · GS1 GIAI (AI 8004)

II — The specimen

A published example, watermarked, for an instrument that does not exist. Its chain entry is genuine, so the verification link printed on it resolves and recomputes exactly as a customer's would — which is the only way to demonstrate a check rather than assert one.

Specimen SPECIMEN-2026-0001

The certificate as issued →
Its verification page →

The instrument does not exist and no calibration was performed. Nothing on the specimen attests to a measurement.

III — What the seal proves

Stated narrowly, because a trust claim wider than the mechanism supports is worse than no claim.

A seal establishes that the chain has not been re-anchored since the seal was taken. It does not attest that anything before the first seal was unaltered, and it is not a signature: it says the record is intact, not that a particular person stands behind it. Binding an issuer identity to exact bytes is what a PAdES signature does, and it requires a signing certificate SVEND does not hold and should not mint. That distinction is printed on the certificate rather than left for a reader to infer.

The mechanism is detection, not prevention. Any document can be imitated. What an imitation cannot do is carry an identifier that resolves at the issuer's verification address.

IV — What is chained

Everything a reader of the printed certificate relies on: which instrument, when it was calibrated and issued, on whose authority, the result and the as-found state, the decision rule behind them, the standard relied on, every measurement point, and the digest of every file held against it. Any change to those makes it a different certificate, and the chain reports it.

The device's own row is deliberately outside the chain. An instrument's custodian, location and status change while it remains the same instrument, and covering them would report every certificate as altered the first time a caliper moved cells. The instrument is identified in the payload by id and serial, which do not move.

V — The label on the instrument

The sticker states the instrument's real standing, computed from the record rather than chosen by whoever prints it. There is no way to obtain a CALIBRATED label for an instrument that is not: the module is asked what an instrument is, and answers.

The square on the label carries either a QR that reaches the certificate, or a GS1 DataMatrix holding the instrument's Global Individual Asset Identifier under the organization's own GS1 company prefix — identity only, which is what AI 8004 is for. The due date stays on the label in words, where it is read at arm's length, rather than being encoded a second time where it could go stale separately. An organization without a prefix gets no mark rather than an invented one.

VI — The certificate as data

The same calibration is available as a Digital Calibration Certificate — the machine-readable XML certificate led by Germany's PTB — served at its own address and validated against PTB's schema. It carries the measurement points, the uncertainty, the standard relied on and the decision rule, so the receiving system gets the judgment rather than only the numbers.

It reads in the same direction. A laboratory that issues a DCC can have it read rather than retyped, which is the complaint metrologists make about calibration software more than any other. Units are handled as D-SI rather than as free text, so a value cannot arrive having quietly lost its unit.

Stated plainly: DCC adoption today is largely European and institutional, and most US shops still receive a PDF. This is here so that the ones who do receive one are not typing it in, and so a customer who asks for machine- readable output has an answer that is not a spreadsheet.

VII — Boundaries

SVEND is not an accredited calibration laboratory and issues no accreditation. The certificate records the authority and accreditation the issuing organization states, and the chain establishes that the record of that statement is intact. It does not verify the statement.

A seal is not a signature. Repeated because it is the distinction most often collapsed when a document carries a hash.

Verification requires the identifier. The verification address is a 64-character hash and cannot be enumerated, so a certificate whose identifier has been lost cannot be checked here — the issuer holds the record and can reissue it.