Certificates issued in Skillsive are digitally signed automatically — there is nothing to configure. By default the Skillsive platform key does it. An organization can upload its own signing certificate, and from then on new documents are finalized with that key.
Why certificates are digitally signed
A digital signature is a seal on the PDF. It lets the recipient — an employer, auditor or inspector — check two things: who issued the document, and whether the file was changed after it was issued.
- Proof of origin. The signature records who signed the document: the Skillsive platform or your organization.
- Tamper detection. Any edit to the finished file — a date, a name, a certificate number — invalidates the signature. A certificate cannot be "corrected" without verification showing it.
- Independent checking. The recipient verifies the document alone, without contacting your organization.
The signature is the last operation applied to the file, so it covers everything visible on it, including the QR code and the filled-in fields.
How a recipient verifies a certificate
There are two routes, and they check different things — the difference matters.
The QR code — checks the record
The QR code on the document opens a verification page with that certificate's record: who issued it, which training, the number, the issue and expiry dates, and whether it is Valid, Revoked, Expired or Not finalized. It also shows whether the certificate was signed with the platform key or the organization key.
So the QR code answers "was this certificate really issued, and does it still hold?". It does not inspect the PDF someone is holding — the data comes from the record, not from the file.
Uploading the PDF — checks the document itself
To confirm that the file was not touched, upload it to the signature verification page. The result is one of four answers:
- Authentic — signed by us, not modified.
- Invalid — the document was modified after signing. Such a file should not be treated as valid.
- No digital signature found — a printout re-saved as a PDF looks like this.
- Signed, but not by a Skillsive key.
In short: the QR code proves the certificate exists and is still valid; uploading the file proves that this particular PDF is the untouched original.
Screenshot placeholder
The verification page showing "Authentic — signed by us, not modified" after a certificate was uploaded.
When the certificate is signed
A certificate is finalized right after it is issued. If the template requires a trainee signature, finalization happens only once the trainee has signed — until then the document has no digital signature yet. The certificate registry shows whether a document was signed with the platform key or the organization key.
When to add your own key
You do not have to do anything for certificates to be signed — without your own file, the Skillsive platform key signs them. Add an organization signing certificate if:
- documents should be signed with a key owned by the organization,
- recipients should see the organization as the signing party,
- internal procedures require your own signing certificate.
Screenshot placeholder
Organization signing certificate card in security settings before uploading a file.
Upload the certificate
- 1Open Organization → Profile → Security.
- 2Find the organization signing certificate card.
- 3Upload a
.pfxor.p12file. - 4Enter the file password.
- 5Save.
After a successful upload, Skillsive shows certificate details, including subject, validity dates, and thumbprint.
Screenshot placeholder
Card after upload with thumbprint, validity date, and active status visible.
Watch the expiry date
An expired certificate cannot sign anything — finalizing new certificates starts failing until you upload a current file. The validity dates are shown on the certificate card.
Security
The certificate file is used to sign documents. Treat it as sensitive organization material and share it only with people who administer security. The uploaded private key is stored encrypted in Azure Key Vault and is never shared with other organizations.
Removing the certificate
If you remove the organization signing certificate, future finalizations use the default Skillsive platform key.
Do not assume that removing the key automatically changes PDFs that were already finalized and signed earlier.