DAPI Certification
DAPI Certification

Legal validity of DAPI certification

DAPI offers two certification paths designed to create a verified, temporally documented baseline of identity and digital content, usable as a reference in cases of impersonation, deepfake, or manipulation. Both use forensic methodology, cryptographic hashes, and eIDAS qualified timestamps to create a structured, verifiable documentary package.

Two paths

Two certification paths

Private baseline or public certification of content

Private path

DAPI-IDS (Private certification of the verified identity baseline)

Establish your verified identity baseline with a completely private technical documentary package. No public exposure: only you receive the certificate.

  • Verified identity baseline
  • SHA-256 cryptographic hashes
  • eIDAS qualified timestamp
  • Technical documentation
  • Completely private

Ideal for: preventive protection, deepfake defense, impersonation disputes

Public path

DAPI-PUB (Public certification of identity and certified content)

Verified identity baseline plus public certification of the content submitted for certification. Each certified item of content gets a publicly consultable verification record.

  • Everything included in DAPI-IDS
  • Public verification listings
  • Per-publication certificate
  • DAPI protection badge
  • QR code for verification

Ideal for: content creators, public figures, copyright protection, anti-manipulation

DAPI-IDS

DAPI-IDS (Private certification of the verified identity baseline)

Private baseline, cryptographic hashes, qualified timestamp

What DAPI-IDS certifies

  • Identity baseline integrity: identity documents, photographs, voice recordings, and other materials used for the baseline are cryptographically hashed, creating verifiable references to their existence and integrity at the time of certification.
  • Time evidence: the eIDAS qualified timestamp establishes the moment of certification, providing a time reference in case of subsequent disputes.
  • Technical documentation: a documented process of acquisition, handling, and preservation of digital elements, inspired by the principles of ISO/IEC 27037.
  • Privacy by design: no public registry, no online profile, no searchable database. Your certified materials remain private: only you receive the documentary package.

What you receive

  • DAPI certificate (PDF): a document with your identity, the certified files, the cryptographic hashes, the timestamp, the methodology, and the expert's digitally signed declaration.
  • SHA-256 hashes for all files: cryptographic fingerprints allowing independent verification of correspondence with the certified originals.
  • Qualified timestamp certificate: RFC 3161-compliant, issued by an eIDAS-qualified provider.
  • Technical documentation: a report on the documented process of acquisition, handling, and preservation of the files, hash generation, and verification protocols.
  • Usage guide: operational guidance for platform reports, GDPR complaints, criminal reports, and proceedings.
  • Verification guide: instructions for third parties to independently confirm file integrity using the hashes provided.

DAPI-IDS use cases

Impersonation and identity abuse

Document what your identity materials were before improper use or profile cloning, supporting takedown requests and reports.

Deepfake defense

Certified reference materials for technical comparison. Certified photos and voice recordings act as a baseline for analysis of disputed content.

Preventive protection

Certify before problems arise. Particularly useful for public figures, executives, and politicians exposed to impersonation risk.

Voice cloning and CEO fraud

Establish a certified voice baseline before phone scams or business email compromise attacks, supporting investigations and insurance claims.

DAPI-PUB

DAPI-PUB (Public certification of identity and certified content)

Public verification of content, badge, and QR code

In addition to your private identity baseline, each item of online content you submit for certification can get a public verification record linking your verified identity to the specific content submitted for certification.

What DAPI-PUB adds

  • Public verification listing: each certified publication gets a dedicated page on verify.dapi-certification.com showing the content, the certification date, and the DAPI number.
  • Identity-content association: documents the association between the verified identity and the content declared and submitted for certification (video, posts, articles, documents).
  • Temporal anteriority: attests when that specific content was certified, providing a useful time reference in case of disputes.
  • Reference in case of disputes: if content is altered or republished by third parties, your certification provides a verifiable time and cryptographic reference.
  • Public badge system: each profile gets an automatically generated badge to display on websites, social media, video, and documents.

What you receive in addition to DAPI-IDS

  • Public profile page: on verify.dapi-certification.com, with all your certified publications and their verification details.
  • Individual listings: each certified item of content gets its own verification page with a DAPI number, date, QR code, and description.
  • Per-publication certificate: a separate PDF for each item of content, with a hash, timestamp, and link to the public listing.
  • DAPI protection badge: an automatically generated SVG file, linked to your verification page, ready to be embedded on websites or content.
  • QR code: for each publication, for quick verification from a smartphone.
  • Embed codes: HTML ready to add the badge to websites, email signatures, and social profiles.

Example verification listing

A real example of what certified publications look like:

DAPI-PUB use cases

Content authentication and copyright disputes

Document the existence, integrity, and time certification of specific content, providing technical elements usable in support of takedown requests and disputes relating to ownership or use of the content. DAPI does not autonomously determine ownership of rights.

Creator protection

Display the DAPI badge on videos and posts as a deterrent against content theft. The public listing allows anyone to verify the record via QR code or link.

Timeline and proof of anteriority

Attests when content existed in a specific form: useful in disputes over temporal priority, trade secrets, or creative works.

Anti-manipulation and deepfake defense

If someone creates altered versions of the content, the certified content provides a verifiable cryptographic and time reference, usable for comparison with disputed versions.

Public verification for stakeholders

Media, clients, and partners can publicly verify the DAPI record associated with your content, without needing to contact you or DAPI directly.

Comparison

Detailed comparison

What each certification path includes

Feature DAPI-IDS DAPI-PUB
Verified identity baseline certification
SHA-256 cryptographic hashes
eIDAS qualified timestamp
Technical documentation (inspired by ISO/IEC 27037 principles)
Expert methodology and digital signature
Usage guide
Completely private (no public listing)
Public verification listings
Per-publication certificate
DAPI protection badge
QR code for public verification
Public profile page
Identity-content association
Technical foundation

Technical foundation (both paths)

Cryptographic hashes and qualified timestamp

Why SHA-256 hashing is technically useful

The technical foundation of digital evidence

A SHA-256 hash is a unique digital fingerprint of a file. If even a single byte changes, the fingerprint changes completely. This mathematical property makes hashing one of the most robust practical tools for integrity verification and for confirming that a file presented subsequently is identical to the file certified at a given point in time.

How hash verification works

  1. At the time of certification: DAPI generates SHA-256 hashes of your original files and includes them in the certificate with a qualified timestamp.
  2. When you need to prove integrity: you present both the certificate (with the hashes) and your original files to a third party (court, platform, expert).
  3. Independent verification: the third party recalculates the hashes of your files and compares them with the certified ones. A match allows verification that the files correspond to those certified and have not been altered since certification.

Timestamp verification

Every DAPI certificate includes a qualified electronic timestamp compliant with the eIDAS Regulation, attesting when certification took place. This timestamp can be independently verified using RFC 3161 validation tools.

Verify your timestamp certificate

DAPI uses qualified timestamp services compliant with eIDAS Regulation (EU) No. 910/2014. You can independently verify your timestamp certificate using the public verification tool.

DAPI + EVIDE

DAPI + EVIDE: from verified baseline to evidentiary preservation

Two distinct levels for verified identity and evidentiary accountability

DAPI creates a verified baseline of identity and digital content through technical elements such as cryptographic hashes, time references, and structured documentation.

When it becomes necessary to preserve over time declarations, context, declared authority, and evidentiary references relating to a decision or an event, the DAPI package can be used within EVIDE as a verified identity element and as a documentary reference.

EVIDE operates on a distinct level: it does not determine identity, does not automatically attribute authority, and does not establish the legal validity of a declaration. Instead, it preserves structured and verifiable elements so that they can subsequently be reconstructed and assessed in their context.

Distinct roles, complementary use

DAPI provides the verified identity baseline. EVIDE can use that reference within structured evidentiary records, keeping identity verification, declared authority, and context preservation separate.

How to use it

How to present DAPI certification

Practical guidance for the most common contexts

Platform reports and takedown requests

When to use it: fake profiles, unauthorized use of images, impersonation on social platforms.

Which package: both work; DAPI-PUB strengthens the request with a public verification listing.

  1. Submit the platform's standard abuse report through the official channels.
  2. Attach the DAPI certificate PDF as supporting evidence.
  3. Reference the certificate: "DAPI certification attached (DAPI-[your code])".
  4. With DAPI-PUB: include the link to your profile on verify.dapi-certification.com for third-party review.
  5. If the platform requires additional verification, provide the original files together with the certificate for hash comparison.

Legal proceedings and reports

When to use it: deepfake defamation, identity theft, fraud, revenge porn, voice cloning scams, copyright disputes.

Which package: DAPI-IDS for identity disputes; DAPI-PUB for disputes relating to content, temporal anteriority, use, or declared ownership of rights.

  1. Provide the complete certified DAPI package to your lawyer.
  2. Include it in formal reports to law enforcement (Postal Police, FBI IC3, Europol).
  3. Submit it as documentation in civil or criminal proceedings, together with the original files for hash verification.
  4. With DAPI-PUB: reference the public verification listing as an additional corroborating element.
  5. Provide the timestamp verification instructions for independent validation.

Content authentication and copyright

When to use it: content theft, plagiarism, unauthorized republication, copyright disputes.

Which package: DAPI-PUB required (provides public verification and per-content certificates).

  1. Submit a DMCA takedown with the certificate for the specific publication.
  2. Reference the public verification listing (verify.dapi-certification.com) as a supporting element.
  3. The timestamp documents that the certified content existed in the form submitted for certification by the time attested by the timestamp, providing a chronological reference for comparison with subsequently disputed content.
  4. The DAPI badge on the original content acts as a visible deterrent.
  5. The QR code allows verification by platforms, clients, and partners without direct DAPI involvement.

GDPR and privacy protection

When to use it: unauthorized data processing, erasure requests, personality rights violations.

Which package: both work; DAPI-PUB adds a further public reference.

  1. Submit a GDPR complaint under Art. 17 (right to erasure) to the platform or website.
  2. Include the DAPI certificate as supporting documentation of your identity.
  3. If the complaint goes unanswered, consider forwarding it to the Data Protection Authority.
  4. Reference the certificate as an element supporting your legitimate interest.
FAQ

Frequently asked questions

On the legal validity of DAPI certification

Is DAPI certification admissible in court?

DAPI certification uses a methodology inspired by forensic standards (ISO/IEC 27037) and eIDAS qualified timestamps. Admissibility, weight, and evidentiary effects depend on the specific case, jurisdiction, and how the evidence is presented, and are determined by the competent authority according to applicable rules. We recommend consulting a lawyer for the correct introduction of the evidence in your proceeding.

Which package do I need for a platform takedown request?

DAPI-IDS is generally suitable to support reports of impersonation and fake profiles. DAPI-PUB strengthens the request by providing a public verification listing that the platform can consult directly.

Which package do I need for content copyright protection?

DAPI-PUB is the relevant package. DAPI-IDS certifies your identity baseline but does not link specific content to you. DAPI-PUB creates per-content certificates with a public verification record, timestamp, and DAPI badge.

Can I upgrade from DAPI-IDS to DAPI-PUB later?

Yes. The already certified DAPI-IDS baseline can be used as a reference to later add DAPI-PUB, unless it needs updating because the identity materials are no longer representative or up to date.

What happens if I lose my original files?

The DAPI certificate contains only cryptographic hashes, not the files themselves. If you lose the original files, the certificate alone is not sufficient for verification, because third parties need to compare your current files against the certified hashes. For this reason, we recommend keeping the original files in multiple secure locations.

Are DAPI-PUB publications publicly searchable?

With DAPI-PUB, each certified publication gets a dedicated listing on verify.dapi-certification.com, accessible via direct link, QR code, or DAPI badge. These listings are not indexed by search engines and contain only the information you have explicitly certified. With DAPI-IDS, there is no public listing at all.

How long does DAPI certification remain valid?

Hashes and timestamps constitute technical references to the certification performed. Their verifiability over time also depends on the preservation of the artifacts, certificates, and information necessary for validation. The practical validity of the baseline also depends on the identity materials remaining representative and up to date: if the identity document expires or the person's appearance changes significantly, it may be advisable to update the certification.

Can a platform reject DAPI certification?

Platforms retain discretion in their own moderation decisions. Structured technical documentation nonetheless provides verifiable elements that can be taken into account when assessing the request.

Disclaimer

Important legal disclaimers

To read before using the certification

  • DAPI provides technical documentation, not legal guarantees. The certification creates a structured documentary package with forensic methodology and a qualified timestamp. It does not guarantee specific outcomes in legal proceedings, platform moderation, or law enforcement investigations.
  • Legal advice is recommended for complex disputes. Many people use the DAPI certificate independently for reports and informal disputes, but complex legal matters require professional guidance.
  • DAPI-PUB creates public listings. If you choose DAPI-PUB certification, the certified content will have a public verification listing on verify.dapi-certification.com. Only certify content you are willing to make publicly verifiable.
  • You must keep your original files. The DAPI-IDS certificate contains only cryptographic hashes, not the files themselves. For legal or platform use, you must present both the certificate and the original files, so third parties can verify that the hashes match.
  • Outcomes depend on jurisdiction and circumstances. DAPI uses recognized technical standards (RFC 3161, SHA-256, methodology inspired by ISO/IEC 27037 principles), but legal systems vary. eIDAS qualified timestamps produce the effects provided for by the regulation within the European Union; use in other jurisdictions must be assessed according to their respective rules.
  • DAPI-IDS is private by design. Unlike DAPI-PUB, DAPI-IDS does not create public profiles, does not publish data online, and does not maintain a searchable database. Your certified materials remain private: only you receive the documentary package.
  • The timestamp is independently verifiable. All DAPI timestamps can be verified using public RFC 3161 validation tools, available at tsr-viewer.certifiedpressreleases.com.

Choose your certification path

Establish your verified baseline with DAPI-IDS or add public verification with DAPI-PUB. Don't wait for identity abuse to occur: certify today.

Forensic methodology · eIDAS qualified timestamp · Expert certification · Choose your privacy level