Root of trust

One published root. Every seal chains to it.

A Let's Seal document is authentic because its seal chains to this one root certificate, and its date is anchored to a public ledger. Both are published and fixed, so anyone can verify a document against a known anchor, independently, with nothing of ours running.

The certificate

Let’s Seal Root CA

This is the public root certificate, the cert, never the private key. It is deliberately notin any operating-system or Adobe trust store (that’s the point: no pay-to-play trust list). Instead you pin it here and verify against it directly.

Subject
CN=Let's Seal Root CA, O=Let's Seal, C=GB
Valid
8 Jul 2026 → 3 Jul 2046
Root SHA-256
02:68:6D:EE:20:67:31:C4:59:C1:7A:9F:58:36:7B:0B:0B:BA:5D:24:C6:85:D8:6D:1F:74:49:86:2D:C0:FE:BE
Intermediate SHA-256
CD:7D:88:96:CB:F4:96:B0:0D:C6:2B:A1:4C:9C:A0:3D:E3:4A:E5:20:C0:08:DA:59:19:96:63:E4:64:85:D1:AF
Download root certificate
How the chain works

The root signs one intermediate, which signs each business’s signing certificate. When you verify a document, its PAdES signature is checked up that chain to this root. A valid chain means the seal was issued through Let’s Seal and the file is byte-for-byte intact. It does notassert the issuer’s real-world identity.

Show the PEM
-----BEGIN CERTIFICATE-----
MIIB4zCCAYmgAwIBAgIUATVQI6DoAl9fR1Pz/qKcw8P6TKAwCgYIKoZIzj0EAwIw
PzEbMBkGA1UEAwwSTGV0J3MgU2VhbCBSb290IENBMRMwEQYDVQQKDApMZXQncyBT
ZWFsMQswCQYDVQQGEwJHQjAeFw0yNjA3MDgxNTU5MjVaFw00NjA3MDMxNTU5MjVa
MD8xGzAZBgNVBAMMEkxldCdzIFNlYWwgUm9vdCBDQTETMBEGA1UECgwKTGV0J3Mg
U2VhbDELMAkGA1UEBhMCR0IwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAATFa+q0
LI7qV4N6b5T7Xuzcy4v6IengyFN8ZWAGsNrF1mHptXIMEUCXUEr1GQpD1FTrfgQO
6HVgXPT2IP2jTJqfo2MwYTAdBgNVHQ4EFgQUEWlQwM1fR/iBgTKigc39MweT+W0w
HwYDVR0jBBgwFoAUEWlQwM1fR/iBgTKigc39MweT+W0wDwYDVR0TAQH/BAUwAwEB
/zAOBgNVHQ8BAf8EBAMCAQYwCgYIKoZIzj0EAwIDSAAwRQIhAN5l2xxn8QypEGK1
VZyHj7fpLRM+79zXT/ujRuUnKkq3AiB+mGJMM3EeeTS0tAhBkskqqv7wnAP9sUqv
KRxDgmn9IQ==
-----END CERTIFICATE-----
Verify independently

Check a document without relying on us

The portal is a convenience, not the source of truth. With the file, its .ots proof, and this root cert, you can confirm both claims offline:

1 · The seal (integrity + issuer chain)

Validate the PDF’s PAdES signature against the downloaded root with any standard X.509/PAdES validator. A valid chain + full-file coverage = byte-for-byte the document that was sealed.

2 · The date (independent timestamp)

Run the stock OpenTimestamps client against the public ledger, no Let’s Seal server involved:

ots verify your-file.pdf.ots
Anchored to a public ledger, live

Most recent proof anchored in block #964,006.

Verify a document