One published root. Every seal chains to it.
A Let's Seal document is authentic because its seal chains to this one root certificate, and its date is anchored to a public ledger. Both are published and fixed, so anyone can verify a document against a known anchor, independently, with nothing of ours running.
Let’s Seal Root CA
This is the public root certificate, the cert, never the private key. It is deliberately notin any operating-system or Adobe trust store (that’s the point: no pay-to-play trust list). Instead you pin it here and verify against it directly.
- Subject
- CN=Let's Seal Root CA, O=Let's Seal, C=GB
- Valid
- 8 Jul 2026 → 3 Jul 2046
- Root SHA-256
02:68:6D:EE:20:67:31:C4:59:C1:7A:9F:58:36:7B:0B:0B:BA:5D:24:C6:85:D8:6D:1F:74:49:86:2D:C0:FE:BE- Intermediate SHA-256
CD:7D:88:96:CB:F4:96:B0:0D:C6:2B:A1:4C:9C:A0:3D:E3:4A:E5:20:C0:08:DA:59:19:96:63:E4:64:85:D1:AF
The root signs one intermediate, which signs each business’s signing certificate. When you verify a document, its PAdES signature is checked up that chain to this root. A valid chain means the seal was issued through Let’s Seal and the file is byte-for-byte intact. It does notassert the issuer’s real-world identity.
Show the PEM
-----BEGIN CERTIFICATE----- MIIB4zCCAYmgAwIBAgIUATVQI6DoAl9fR1Pz/qKcw8P6TKAwCgYIKoZIzj0EAwIw PzEbMBkGA1UEAwwSTGV0J3MgU2VhbCBSb290IENBMRMwEQYDVQQKDApMZXQncyBT ZWFsMQswCQYDVQQGEwJHQjAeFw0yNjA3MDgxNTU5MjVaFw00NjA3MDMxNTU5MjVa MD8xGzAZBgNVBAMMEkxldCdzIFNlYWwgUm9vdCBDQTETMBEGA1UECgwKTGV0J3Mg U2VhbDELMAkGA1UEBhMCR0IwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAATFa+q0 LI7qV4N6b5T7Xuzcy4v6IengyFN8ZWAGsNrF1mHptXIMEUCXUEr1GQpD1FTrfgQO 6HVgXPT2IP2jTJqfo2MwYTAdBgNVHQ4EFgQUEWlQwM1fR/iBgTKigc39MweT+W0w HwYDVR0jBBgwFoAUEWlQwM1fR/iBgTKigc39MweT+W0wDwYDVR0TAQH/BAUwAwEB /zAOBgNVHQ8BAf8EBAMCAQYwCgYIKoZIzj0EAwIDSAAwRQIhAN5l2xxn8QypEGK1 VZyHj7fpLRM+79zXT/ujRuUnKkq3AiB+mGJMM3EeeTS0tAhBkskqqv7wnAP9sUqv KRxDgmn9IQ== -----END CERTIFICATE-----
Check a document without relying on us
The portal is a convenience, not the source of truth. With the file, its .ots proof, and this root cert, you can confirm both claims offline:
Validate the PDF’s PAdES signature against the downloaded root with any standard X.509/PAdES validator. A valid chain + full-file coverage = byte-for-byte the document that was sealed.
Run the stock OpenTimestamps client against the public ledger, no Let’s Seal server involved:
ots verify your-file.pdf.ots
Most recent proof anchored in block #964,006.