TrustedForm certificate
What a TrustedForm certificate is, what the Certify script records, the difference between a certificate being created and a buyer retaining it, and why a certificate is evidence of a form submission rather than verification of the person who filled it in.
A TrustedForm certificate is a record of the web session in which a consumer submitted a lead form. ActiveProspect's Certify script runs on the page and writes a certificate URL into a hidden field in the form, so the URL travels with the lead data. The URL is the certificate. It points at a record hosted by ActiveProspect at cert.trustedform.com, not at a file the buyer holds.
What the certificate records
ActiveProspect lists what a certificate holds: a time stamp, a session replay, an event log, the page URL and the consent language the consumer was shown. Certify issues one certificate for each page a consumer lands on that is running the SDK, and a single-page form flow is recorded as one certificate rather than several.
Created at submission, retained by the buyer
A certificate is created when the consumer submits the form. Retaining it is a separate, later step: the buyer sends an authenticated request to the certificate URL through ActiveProspect, which checks the certificate is genuine and stores a copy under the buyer's own account. A certificate nobody retains is deleted once its availability window closes, and the link then resolves to nothing.
What it proves, and what it does not
A certificate is evidence about a form submission: that a session happened, when it happened, what the page said, and what the person did on it. It proves nothing about the person. It is not identity verification, it does not confirm income or employment, and no credit bureau is touched. Every figure the consumer typed is still a self-reported answer.
What it changes when a consumer disputes the call
If a consumer later says they never asked to be contacted, the certificate is the contemporaneous record of the opposite: the page they were on, the wording of the consent they were shown, and the timing of the submission. It only helps if the buyer retained it. An unretained link produced at that point is not evidence.
Two questions settle whether a certificate on an invoice is worth anything. Ask whether the certificate covers the form the lead actually came from, and ask who retained it. A certificate generated by one party and never retained by anyone is a URL, not a record.
Source: ActiveProspect developer documentation, Implementing TrustedForm Certify, read 20 September 2026, for certificate generation per page, the hidden field the SDK writes, and the cert.trustedform.com certificate URL · ActiveProspect, TrustedForm product page, for what a certificate holds: time stamp, session replay, event log, page URL and consent language · ActiveProspect developer documentation, Claiming Certificates, for the authenticated claim request by an account holder receiving certified leads, which verifies the certificate and stores it for future reference.Questions this page answers
No. A TrustedForm certificate is evidence about the submission, not about the submitter. It records that a session took place on a specific page, at a specific time, with specific consent wording on screen. It does not verify identity, it does not confirm income or employment, and it involves no credit bureau. Income, property value and credit range on a lead form remain the consumer’s own typed answers and still have to be checked in underwriting.
Creation happens on the page where the consumer submits the form, automatically, wherever ActiveProspect’s Certify script is installed. Retention is a deliberate act by a party holding the lead: an authenticated request sent to ActiveProspect, which verifies the certificate and stores it under that party’s own account. Until someone retains it, a certificate is only available for a limited window, after which it is deleted and the URL stops resolving.
Either can, and they retain into different accounts. A lead generator retains certificates for the leads it produces. A buyer retains the certificates attached to the leads it purchases, which puts the record under the buyer’s own control instead of leaving it dependent on the seller’s account. If consent is disputed later and the buyer never retained the certificate, the buyer holds a link rather than a record. Ask a vendor which certificates come with the lead and whether you can retain them yourself.
Buying questions rather than research ones are answered on the FAQ, and anything that is not there gets asked on a call.
More in Resources
A2P 10DLC
Why business texts go missing without an error, who actually sets that rule, and why meeting it has nothing to do with meeting the law. The term is not in the industry document it comes from.
GlossaryAbandoned call
The FTC test that decides when a dialer has left a consumer holding an empty line, the allowance a caller is given for it, and the denominator most dialer dashboards do not use.
GlossaryCaller ID authentication
What STIR/SHAKEN signs, which is the number and not the intent, whose obligation it is, and why a legitimate first call can still arrive on the handset under a warning.
GlossaryCalling time restrictions
The window both the FTC and the FCC set, whose clock it runs on, and the thing neither rule says about how you are supposed to know where the person actually is.
GlossaryDo Not Call safe harbor
The defence a company has after calling a registered number by mistake, which is a list of things that had to exist before the call, and the one interval the FTC and the FCC agree on.