Compliance & recordsv4.1.0

Certora

Certificates with a unique code and a public verify page, delivered to recipients by private link.

For training providers, course creators, event organizers and HR teams. Often replaces Certifier, Sertifier or Accredible.

Single license $79 · Extended license $179 · paid once, yours for good

Try the live demoNo sign-up. The demo resets itself, so click anything.

What it does

Public verify page

Anyone can confirm a certificate by its code: recipient, course, issuer, issue date and validity. A miss is a plain not-found.

One run, many certificates

A template and a recipient list give one certificate each, with a unique code. Tick more templates and each person gets a set.

Delivered by private link

Each recipient gets a private link to their own PDF, no account needed. Batches send in slices and nothing sends twice.

Add to LinkedIn, one click

Recipients add the certification to LinkedIn from the verify page or their email. Name, dates, code and your verify link are filled in.

Open Badges on your domain

Switch on hosted Open Badges 2.0. Each certificate's badge data lives on your server, with the recipient's email hashed.

See that they are checked

Every lookup on your verify page is counted, by certificate and template. Near-misses on a real code are flagged.

Every certificate, one page

A recipient types their email and gets a link to everything you issued them. No account.

A real seal

Upload a JPEG or plain PNG and it is embedded in the PDF as it is, never stretched.

Expiry tracking

Give a template a validity period and each certificate carries an expiry date. The verify page shows expired as expired.

Templates with merge tokens

Title, body, recipient, course, date and issuer tokens, a signatory line and orientation.

Issued register

Search every certificate, revoke or reinstate, and export the register as a formula-safe CSV.

PDFs with no dependencies

Each certificate renders as a PDF with no external libraries or services. It carries a QR code of its verify link once your verify address is set.

Also: CSV recipient import, expiring-soon counts on the dashboard, a phone install from the browser, and an API and MCP endpoint for your own agent.

Self-hosted without the assembly

The other answer to “self-hosted” is a repository: clone it, read the compose file, provision a database, wire up mail, then keep it patched yourself. That is a fair answer when running infrastructure is already your job, and we would rather say so than pretend otherwise. This is the other kind. It is bought once at $79.00, the full PHP source is in the download, and the web installer finishes on ordinary shared hosting in about two minutes. No Composer, no Node, no build step, nothing to compile, and nothing that phones home.

Is it right for you?

What Certora deliberately doesn’t do.

  • Not a PKI/digital-signature system — verification is a database lookup on your server: the code resolves to the record you issued, or it does not. Provenance, not cryptography.
  • Email goes through your own SMTP; certificates are delivered as a private link, never as an attachment, and delivery is off until you switch it on.
  • A seal or logo on the certificate must be a JPEG or a plain 8-bit PNG (no transparency, interlacing or palette) — the PDF is written without an imaging library on purpose.
  • Single-tenant: one issuing organization per installation.

What renting costs instead

CertifierProfessional $89/month billed monthly, $76/month billed annually, at the page's default position of its volume slider; Advanced $399/month ($339 billed annually); Starter "$0 / free forever" with an annual issuing limit of 250 certificates/badges; Enterprise "Contact sales"

1 month of Certifier costs what Certora costs once.

Read Sep 24, 2026 · source

The full comparison: every rival, what each does better, and who should stay with them →

Replacing one of these? Certifier alternative · Sertifier alternative · Accredible alternative

Release history

Own It 4.1Client installations and your other toolsOct 4, 2026

For Certora, 4.1 makes two changes that every app gets. What’s new in 4.1 →

Own It 4.0It updates and backs itself upSep 29, 2026

For Certora, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and… What’s new in 4.0 →

Own It 3.3A set of certificates in one runSep 27, 2026

3.3 lets one run issue a set. What’s new in 3.3 →

Own It 3.2A certificate that travelsSep 26, 2026

3.2 took each certificate beyond the PDF.

Own It 3.1It writes to the people you serveAug 20, 2026

The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar…

Own It 3.0Works for your AI, not just for youAug 9, 2026

Six MCP tools let an agent list templates, read the register, issue a batch, verify a code and pull the expiry report — with the write tool on the same code path as…

Own It 2.0API, 2FA, backups, dark modeAug 6, 2026

The owner layer every Ownware app carries.

What’s in the zip

The tree as the zip ships it — the working leftovers the packager deletes are not listed

  • .htaccess
  • API.md
  • Dockerfile
  • LICENSE.txt
  • QUICKSTART.txt
  • README.md
  • assets/
  • bin/
  • config.sample.php
  • controllers/
  • deploy/
  • index.php
  • install/
  • manifest.json
  • offline.html
  • router.php
  • src/
  • sw.js
  • tests/
  • views/
src/Qr.php: a real module, the first 24 of 441 lines

Chosen as the largest module in src/ that is not one of the shared cores — this product's own logic, not a file every product carries.

<?php
/**
 * Qr.php — a QR Code encoder, byte mode, error-correction level M, versions 1..10.
 *
 * CERTORA (3.1.4): copied unchanged from Assetora, where it was written and proved for
 * printed asset labels. Here it puts the certificate's /verify link on the PDF as a QR code, so an
 * employer scans instead of typing a 12-character code. tests/qr_check.php (copied with it) reads
 * every symbol back with an independent decoder and checks the Reed-Solomon parity. The notes
 * below are Assetora's and still describe the encoder exactly.
 *
 * WHY THIS EXISTS AT ALL. The 3.0 signature feature is a printable label sheet: one QR per asset
 * that opens that asset's page. A label sheet that does not scan is worse than no label sheet —
 * somebody sticks four hundred of them onto four hundred machines before anyone finds out. So the
 * encoder is written from ISO/IEC 18004 rather than approximated, and the suite checks it against
 * an independent reference implementation, matrix for matrix, not by eye.
 *
 * WHY NOT A SERVICE OR A LIBRARY. A QR image endpoint would send the customer's asset URLs to a
 * third party on every label print, and this product is sold on the promise that it talks to
 * nobody. There is no Composer dependency either: the whole apps is drop-in-and-run PHP.
 *
 * SCOPE, deliberately. Byte mode only (a URL is bytes), level M (~15% recovery — the right trade
 * for a label that will be scuffed but is not on a foundry floor), versions 1..10, which carries a
 * 213-byte URL (version 10-M holds 216 data codewords, less the 4-bit mode indicator and the
 * 16-bit character count that versions 10 and up use). Beyond that encode() refuses loudly rather

Runs on: 2-minute web installer, plain PHP 8.1+ with MySQL (or SQLite for a trial), no Composer or build step — Docker image included. Tested on PHP 8.3. Or run it in Docker: the Dockerfile is in the zip.

Technical owners can install it with one line and their license key: curl -fsSL https://ownware.io/install.sh | sh -s -- certora <your license key>

Nothing is obfuscated or encoded; what you read is what runs. Manual · API · the test run

Which license do I need?

It comes down to how many installations you need. Running your own business on one site is the Single license. A second domain of your own, or sites you build or run for other people, is the Extended license.

Single license$79
One (1) domain or subdomain · One business, running it on one site.
  • Install it on one domain or subdomain you own or operate
  • Change the source however you like for that installation
  • Run your own business on it commercially, client work included
  • Re-download the current build any time from your buyer portal
  • A second site, or an installation you hand to a client as theirs, needs the Extended license
  • No reselling, redistributing or sublicensing the source
  • Not for offering it to other people as a hosted service
Buy the Single license, $79
Extended license$179
Unlimited sites you own or operate, plus up to 10 client installations (white-label included) · Agencies, and anyone running it on more than one site.
  • Everything the Single license grants
  • Install it on as many domains as you own or operate — no cap on the number
  • Up to ten client installations, one per client project, handed over or hosted for each client; for more, buy another Extended license
  • White-label: remove or replace the product name and logo in the screens of client installations
  • Still no reselling or redistributing the source itself
  • Running it as a multi-tenant service others sign up for needs a SaaS agreement
Buy the Extended license, $179

Every download carries the full terms as LICENSE.txt. The complete wording is on the terms page.

After you buy

Updates

The app’s Updates page installs a new release with your license key, with the release’s signature checked and a backup taken first. Your download link always serves the current build. Download again any time from your order page or the buyer portal; there is no renewal fee.

Help

Email support for installation and for defects in the code as delivered: a person reads and answers every message. It does not cover custom development or server administration. What support covers

If it isn’t right

Refunds are handled by Lemon Squeezy as merchant of record, case by case. EU consumers keep the statutory 14-day right until delivery starts. Refund terms

If we disappear

It keeps running: your server, the full PHP source, no license check that can fail. If no stable release is published for 365 days, the domain limit lifts; after three such years your copy becomes MIT-licensed. The terms have the exact wording: continuity.

Questions

Is the verification cryptographic?
No, and it doesn't need to be — a verification code is a random, database-unique lookup token. Verification is a lookup against your own register, not a signature check. Nothing is signed or encrypted.
Can verification codes collide?
No — codes are random and enforced unique at the database level; batch generation is tested collision-free at 1,000 certificates.
What stops someone brute-forcing the verify page?
The verify endpoint has a honeypot, per-IP rate limiting, and returns 404 on a miss — and a code exposes nothing beyond what's on the certificate face.
Can I revoke a certificate?
Yes — revoke or reinstate any issued certificate from the register; the public verify page reflects it immediately.
Do certificates expire?
If you want them to — set a validity in months on the template (0 = never expires). Each certificate snapshots its expiry at issue; it stays valid through the expiry date itself, and a revoked certificate always shows revoked, expired or not.
Will it run on shared hosting?
Yes — PHP 8.1+ with PDO, MySQL/MariaDB or SQLite, a 2-minute web installer, no Composer packages, no API keys.
Can it email certificates to recipients?
Yes — switched off until you enable it. Each certificate carries a private link to its own PDF (no account needed); batch delivery works in bounded slices with per-recipient outcomes, refusals report as skipped rather than failed, and nobody is ever emailed twice.
Is Certora a subscription?
You buy it once and own that copy. There is no subscription, no per-user fee and nothing that renews — the license tier decides how many sites you may run it on, not how many people use it. A verification page has to outlive the certificates it verifies, which is a poor fit for a service that can be withdrawn at renewal.
What exactly do I get for the money?
The download is the complete PHP source with the database schema. Read it, change it, keep it. If we vanished tomorrow the copy on your server keeps working, because nothing in it phones home to us.
Can I get the certificate records out?
Yes. Certificates export as CSV, the audit trail as CSV, and each recipient's own record as JSON for a data request. The verification codes travel with them, so a register you host elsewhere can keep answering the same codes.

Covered in these guides

More about Certora

Self-hosted certificate verification for training providers and awarding bodies: every certificate carries a unique code an employer can check on a verify page you host yourself.

The problem it solves

If you want a self-hosted certificate generator with verification — issue certificates in bulk, and give employers a verify page you host rather than a credential platform that bills per certificate — that is exactly what Certora is: $79 one-time, full PHP source, unique verify codes, expiry tracking, and shared hosting is enough.

Training providers, course creators, event organizers, and HR teams all hit the same wall: fifty (or five hundred) people finish, and each needs a certificate — plus a way for an employer to check it's real, years later. Doing it by hand means mail-merging documents one at a time and answering verification emails forever. Certificate SaaS charges per certificate, per recipient or per month, and the verify page lives on someone else's domain, on their terms.

  • One PDF per recipient, generated by hand, every cohort
  • "Can you confirm this certificate?" emails, indefinitely
  • A verification URL on someone else's domain, on their terms

Every feature

  • Certificates reach the people who earned them. Each recipient gets a private link to their own PDF — no account, no login, the token is the credential. Batches send in bounded slices (a cohort of 500 can never time out halfway), every skip states its reason, and nothing sends twice.
  • A real seal on the certificate. Upload a JPEG or plain PNG and it is embedded into the PDF byte-for-byte — no imaging library, no re-encoding — centered, scaled to fit, never stretched. Certificates without a seal stay byte-identical to before.
  • Certificate templates. Design templates with title, body, merge tokens ({recipient}, {course}, {date}, {issuer}, {code}), signatory line, orientation, and optional logo/seal text.
  • CSV recipient import. Import recipients from CSV with columns matched by header name, or add them manually.
  • One-click batch generation. Template × recipient list → one certificate each, with a random database-unique verification code and issue date — collision-free even at a 1,000-certificate batch.
  • Dependency-free PDFs. Each certificate renders as a PDF with no external libraries or services: positioned text in a monospaced typeface (Courier), a double border, a centered layout and, when your public verify address is set, a QR code of its verify link.
  • Public verify page. Anyone can confirm a certificate at /verify/{code}: recipient, course, issuer, issue date, and validity — with a honeypot, per-IP rate limiting, and a plain not-found on a miss.
  • Expiry tracking. Give a template a validity period and every certificate issued from it carries an expiry date (snapshot at issue, month-end clamped). The public verify page shows expired certificates as expired, the register and CSV carry the expiry, and the dashboard counts expiring-soon and expired.
  • Issued register. Search every issued certificate, revoke or reinstate, and export the register as a formula-injection-hardened CSV.
  • Installable mobile app (PWA). Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is not stored offline on the device; what you see is read live.
  • Add to LinkedIn in one click. Recipients add the certification to their LinkedIn profile from the verify page or their email, with name, dates, code and your verify link filled in.
  • See that your certificates are checked. Every lookup on your verify page is counted: by certificate, by template, and the codes that matched nothing, with near-misses on a real code flagged.
  • Open Badges on your own domain. Switch on hosted Open Badges 2.0: each certificate gets a badge whose data lives on your server, with the recipient's email hashed.
  • Every certificate, one private page. A recipient types their email and gets a link to everything you issued them. No account.
  • A set of certificates in one run. Tick more than one template and each person gets one certificate from each, for example a course completion and a CPD record, each with its own code and verify page (and its own badge, with badges on).
  • Updates from inside the app. The Updates page installs a new release with your license key: Ownware's signature is checked, a backup is taken first, and the app puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. It never checks by itself.
  • Backups by themselves. Automatic backups, an optional copy to S3-compatible storage you own, and a weekly check that the latest backup reads back. The Health page names anything that needs attention.
  • Own It 4.0.1 — fixes and an up-to-date manual. For Certora, 4.0.1 fixes an installer that had lost its styling and a command-line update that ended in an error after putting the previous version back. Its manual, FAQ and QUICKSTART now cover everything 4.0 added, including two Nginx rules that keep the data folder private. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
  • Own It 4.0.2 — the installer opens on every host. For Certora, 4.0.2 fixes a fresh install on an Apache host: the one-page setup at /install/ looped back to itself and never opened, and now it opens. Your license covers it: press Check for updates on the Updates page, or download it from your order page.

Release notes in full

  • Own It 4.1: client installations and your other tools. For Certora, 4.1 makes two changes that every app gets. An Extended license bought from October 4, 2026 covers up to ten client installations, one per client project: hand each one over to the client or host it for them, with the client's logo and colors from the app's branding settings. The API reference now shows how to connect Certora to Zapier, Make or n8n, using its own webhooks and API key. Your license covers the update: press Check for updates on the Updates page, or download it from your order page.
  • Own It 4.0: it updates and backs itself up. For Certora, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. A new install can start with a sample business and remove it in one click; backups run by themselves, with an optional offsite copy and a weekly check that the latest one reads back; and the Health page says whether the install is looking after itself.
  • Own It 3.3: a set of certificates in one run. 3.3 lets one run issue a set. Tick more than one template and each person gets one certificate from each, for example a course completion and a CPD record, each with its own code and verify page.
  • Own It 3.2: a certificate that travels. 3.2 took each certificate beyond the PDF. Recipients add it to LinkedIn in one click, hosted Open Badges 2.0 can live on your own domain, and a recipient gets one private page of everything you issued them. You also see that your certificates are checked: every lookup on your verify page is counted, with near-misses on a real code flagged.
  • Own It 3.1: it writes to the people you serve. The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Each outbound feature ships switched off and runs on your own credentials; a failed send is recorded, and the action that triggered it stands. What this app gained is listed at the top of this section.
  • Own It 3.0: works for your AI, not just for you. Six MCP tools let an agent list templates, read the register, issue a batch, verify a code and pull the expiry report — with the write tool on the same code path as the Generate screen, so an agent cannot mint a certificate the UI would refuse.
  • Own It 2.0: API, 2FA, backups, dark mode. The owner layer every Ownware app carries. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase.

Browse self-hosted: Compliance software · School & training-provider software · Driving-school software

Certora$79 once
Demo Buy