The problem
Today, a degree is a PDF file.
A certificate is paper or a PDF, a seal and a signature. All of that could always be forged — it was simply slow, expensive and required real craft. That craft has disappeared: a convincing certificate with the right layout, seal and letterhead now takes minutes, for a few euros, with no skill at all.
The verification side has not moved at all: call, look, hope. Whoever checks a certificate can only believe the university they call — or the number printed on the forged document.
1 in 16
documents submitted for review is flagged as fraudulent (6%).
Inscribe, Document Fraud Report 2026
+244%
year-over-year increase in digital document forgeries.
Entrust Identity Fraud Report
5×
more AI-generated document fraud between April and December 2025.
Inscribe, Document Fraud Report 2026
7,600
fake nursing diplomas from three schools in a single case — untrained people in patient care.
“Operation Nightingale”, US Department of Justice
The status quo
Three answers — and why none of them holds.
Manual verification
A call to the registrar, a visual check, seals and watermarks. It checks exactly the features generative models now reproduce reliably — and it does not scale beyond a single cohort.
AI forgery detection
Spots artefacts and anomalies in files and layouts. Reactive by design: trained on yesterday's fakes. An arms race in which the defender is structurally behind.
A central verification portal
The university or a vendor runs a database. It only moves the problem: whoever controls the database controls the truth. If the operator disappears, the credential disappears with it.
The answer
A credential has to prove itself.
Verifiable independently of whoever issued it and whoever runs the software. Integrity, revocation, longevity and independent verifiability — take those four requirements seriously and you inevitably arrive at a trust anchor that belongs to none of the parties involved.
| University portal | A SaaS vendor | ProofLayer | |
|---|---|---|---|
| Verifiable without trusting the operator | No | No | Yes |
| Survives shutdown, insolvency, vendor change | Partly | No | Yes |
| Insider manipulation | Possible | Possible | Immediately visible |
| Verification without account or middleman | No | No | Yes |
| Can you run it yourself | Yes | No | Yes |
Trust owned by a single party is not trust — it is a dependency.
Trust is not claimed.
It is calculated.
Let us take one degree programme and show you. Four to six weeks, on the test network, with no production data.

Motseki Khoarai
Team Lead, Open Elements