Book a Discovery Call
Back to Resources
Glossary

TrustedForm certificate

What a TrustedForm certificate is, what the Certify script records, the difference between a certificate being created and a buyer retaining it, and why a certificate is evidence of a form submission rather than verification of the person who filled it in.

VisionXLab 2 min read

A TrustedForm certificate is a record of the web session in which a consumer submitted a lead form. ActiveProspect's Certify script runs on the page and writes a certificate URL into a hidden field in the form, so the URL travels with the lead data. The URL is the certificate. It points at a record hosted by ActiveProspect at cert.trustedform.com, not at a file the buyer holds.

What the certificate records

ActiveProspect lists what a certificate holds: a time stamp, a session replay, an event log, the page URL and the consent language the consumer was shown. Certify issues one certificate for each page a consumer lands on that is running the SDK, and a single-page form flow is recorded as one certificate rather than several.

Created at submission, retained by the buyer

A certificate is created when the consumer submits the form. Retaining it is a separate, later step: the buyer sends an authenticated request to the certificate URL through ActiveProspect, which checks the certificate is genuine and stores a copy under the buyer's own account. A certificate nobody retains is deleted once its availability window closes, and the link then resolves to nothing.

What it proves, and what it does not

A certificate is evidence about a form submission: that a session happened, when it happened, what the page said, and what the person did on it. It proves nothing about the person. It is not identity verification, it does not confirm income or employment, and no credit bureau is touched. Every figure the consumer typed is still a self-reported answer.

What it changes when a consumer disputes the call

If a consumer later says they never asked to be contacted, the certificate is the contemporaneous record of the opposite: the page they were on, the wording of the consent they were shown, and the timing of the submission. It only helps if the buyer retained it. An unretained link produced at that point is not evidence.

Two questions settle whether a certificate on an invoice is worth anything. Ask whether the certificate covers the form the lead actually came from, and ask who retained it. A certificate generated by one party and never retained by anyone is a URL, not a record.

Source: ActiveProspect developer documentation, Implementing TrustedForm Certify, read 20 September 2026, for certificate generation per page, the hidden field the SDK writes, and the cert.trustedform.com certificate URL · ActiveProspect, TrustedForm product page, for what a certificate holds: time stamp, session replay, event log, page URL and consent language · ActiveProspect developer documentation, Claiming Certificates, for the authenticated claim request by an account holder receiving certified leads, which verifies the certificate and stores it for future reference.

Questions this page answers

No. A TrustedForm certificate is evidence about the submission, not about the submitter. It records that a session took place on a specific page, at a specific time, with specific consent wording on screen. It does not verify identity, it does not confirm income or employment, and it involves no credit bureau. Income, property value and credit range on a lead form remain the consumer’s own typed answers and still have to be checked in underwriting.

Creation happens on the page where the consumer submits the form, automatically, wherever ActiveProspect’s Certify script is installed. Retention is a deliberate act by a party holding the lead: an authenticated request sent to ActiveProspect, which verifies the certificate and stores it under that party’s own account. Until someone retains it, a certificate is only available for a limited window, after which it is deleted and the URL stops resolving.

Either can, and they retain into different accounts. A lead generator retains certificates for the leads it produces. A buyer retains the certificates attached to the leads it purchases, which puts the record under the buyer’s own control instead of leaving it dependent on the seller’s account. If consent is disputed later and the buyer never retained the certificate, the buyer holds a link rather than a record. Ask a vendor which certificates come with the lead and whether you can retain them yourself.

Buying questions rather than research ones are answered on the FAQ, and anything that is not there gets asked on a call.

More in Resources

Find out whether we cover your states and products

A short call. We look at the states you are licensed in and the products you want, and tell you whether we have coverage before anybody talks about an order. One lead goes to exactly one client.