What is the difference between a certification portal and an LMS?
An LMS manages learning material, progress and, where relevant, an examination. A certification portal manages the formal issuance: registration, identity verification, payment, assessment by independent reviewers, issuance with legal status (eIDAS QES), public register, renewals and the revocation workflow. The two can complement each other; for training institutions we often build a combination of both.
Do you replace an existing certification package or audit management system?
For a small certification, usually not. We come into the picture when your schema, integrations or publication requirements are so specific that a standard package only works with costly customisation. During intake, we weigh your current licence and customisation costs against the custom development trajectory. Some clients keep their audit management system in-house and only have us build the client and register portal.
How do you technically safeguard the independence of assessors?
Conflict-of-interest detection runs automatically on employer, previous relationship and region, and blocks assignment as soon as a match is found. Reviewers work blind: they cannot see each other's scores before submitting their own judgement. In the event of a discrepancy, the application escalates automatically. Every assessment is traceable in the audit trail.
Which eIDAS providers do you integrate with?
Signhost (Evidos), ValidSign, KENA, Adobe Sign, DocuSign and, for specific domains, domain-specific QTSPs. For QES, we work with QTSPs that have a valid status on the EU Trusted List. Which provider fits depends on the schema, cost per issuance and your contractual situation; we advise on that.
How secure is the public register against misuse or scraping?
We build rate limiting, CAPTCHA for abnormal patterns, and a structured API for parties who need high volumes (with API keys, contracts and logging). Bulk export runs through a formal arrangement, not scraping. For sensitive schemes, we can restrict search to exact match on certificate number only.
How do you handle the right to be forgotten for revoked certificates?
A revocation keeps the certificate visible with the status 'revoked' and the date, as that is precisely the reason for publication. Personal data of an applicant who was never certified is destroyed after the retention period. For revoked certificates, you often have a legal retention obligation; we build that trade-off as an explicit workflow with a final check by your DPO.
Do you work alongside our current IT provider or our in-house IT team?
More often than not, yes. We deliver the codebase, build instructions, architecture overview and runbook so that an external managed service provider can take over. This is a deliberate design choice to avoid vendor lock-in. Some clients have us continue under a maintenance contract; others hand management to their own team.
Can a certification portal run on-premises, or does it have to be in the cloud?
Both are possible. For government or accreditation-sensitive environments, we run the stack in a Dutch single-tenant private cloud or your own data centre. For other contexts, an EU-based cloud by arrangement. Encryption keys remain with you in both scenarios.
What if we want to add an extra scheme along the way?
That is why we build the scheme engine as data, not as code. A new scheme or a new version can be set up by a scheme administrator themselves through an editorial interface. For schemes with entirely new technical requirements, we run a short further-development sprint.
What determines the cost?
The biggest cost drivers are the number of schemes, the complexity of the assessment process, the depth of integrations (payment, accounting, external registers, accreditation reporting), the requirements around eIDAS QES and publication, and the migration of existing certificates. We work with fixed sprint budgets so that you can adjust scope from sprint to sprint.