Embeddable verify badge

Put the proof where buyers already look.

You have a signed evidence report. Now make it findable. The kolm verify badge sits on your site, docs, or README (a project's front-page text file)A README is the front-page document of a code repository on a host like GitHub, the first thing a visitor reads. and links straight to your Trust Link (your public evidence page)Your Trust Link is the public page kolm hosts for your signed report, for example kolm.ai/v1/trust/your-slug. Anyone with the link can open and check it., where anyone checks your report offline against kolm's published key. The click lands on proof, not a marketing page.

Links to your Trust Link Verified offline, no account ASCII-clean, self-contained SVG
01 / What it does

A link, not a logo wall.

Most trust badges are decoration: an image that asserts something with nothing behind it. This one is a doorway. It opens your Trust Link, and the report there is checkable by the person looking at it.

Points to your evidence

Straight to your Trust Link

The badge links to kolm.ai/v1/trust/your-slug, the public page for your signed evidence report. One click, no search, no sign-in wall.

Verifiable at the click

The math runs in their browser

At your Trust Link the Ed25519 signature is checked against kolm's published issuer key, offline. Edit a finding or inflate a score and the seal reads VOID.

Nothing to trust on faith

No account, no kolm server

A reviewer needs no kolm login and uploads nothing. The report carries the key it was signed with, so the check needs nothing from us.

VERIFY BADGE / ANATOMYlive
kolm verifiable evidence 01brand mark 02the claim 03links out
  1. 01The three-bar mark tells a reviewer this is a real kolm badge, not a look-alike image.
  2. 02Verifiable evidence is the only claim the badge makes: signed and checkable, never certified secure.
  3. 03The whole badge is a link to your Trust Link, where the signature is checked in the visitor's browser.
ONE LINK brand mark, the claim, the link target verifiable evidence

The badge is a signpost. The proof is the signed report it points to. See the anatomy of a report.

02 / Copy and paste

Three snippets. Pick the one your platform speaks.

Each one renders the same badge and links to your Trust Link. Replace your-slug with the slug from your Trust Link, paste, and publish.

a / HTML, inline SVG
<a href="https://kolm.ai/v1/trust/your-slug" target="_blank" rel="noopener"
   aria-label="kolm verifiable evidence: open the signed Trust Link">
  <svg xmlns="http://www.w3.org/2000/svg" width="300" height="40" role="img"
       aria-label="kolm: verifiable evidence">
    <title>kolm verifiable evidence: signed and offline-verifiable</title>
    <clipPath id="kolm-badge-clip"><rect width="300" height="40" rx="8"/></clipPath>
    <g clip-path="url(#kolm-badge-clip)">
      <rect width="118" height="40" fill="#0E1310"/>
      <rect x="118" width="182" height="40" fill="#11875A"/>
      <g transform="translate(16 10) scale(0.62)" fill="#45D98E">
        <rect x="4" y="6" width="4.5" height="20" rx="0.4"/>
        <rect x="13" y="9" width="4.5" height="14" rx="0.4"/>
        <rect x="22" y="12" width="4.5" height="8" rx="0.4"/>
      </g>
      <text x="42" y="25.5" font-family="Segoe UI,Helvetica,Arial,sans-serif"
            font-size="15" font-weight="700" fill="#ECEFEA">kolm</text>
      <path d="M135 20.5l4 4 8-8.5" fill="none" stroke="#FFFFFF" stroke-width="2.4"
            stroke-linecap="round" stroke-linejoin="round"/>
      <text x="154" y="25.5" font-family="Segoe UI,Helvetica,Arial,sans-serif"
            font-size="13.5" font-weight="600" fill="#FFFFFF">verifiable evidence</text>
    </g>
  </svg>
</a>

Best for your own site or hosted docs. Self-contained: no external request, no third-party service, exact brand mark. The SVG is ASCII-only.

b / Markdown, for READMEs
[![kolm: verifiable evidence](https://img.shields.io/badge/kolm-verifiable_evidence-11875A?labelColor=0E1310)](https://kolm.ai/v1/trust/your-slug)

Best for GitHub, GitLab, and other READMEs, which strip inline SVG. This renders a flat badge in kolm's colors through the third-party shields.io service. Prefer zero third-party calls? Host the SVG above yourself, or use snippet a on a platform that allows HTML.

c / Image, self-contained
<a href="https://kolm.ai/v1/trust/your-slug" target="_blank" rel="noopener">
  <img width="300" height="40"
       alt="kolm: verifiable evidence, signed and offline-verifiable"
       src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIzMDAiIGhlaWdodD0iNDAiIHJvbGU9ImltZyIgYXJpYS1sYWJlbD0ia29sbTogdmVyaWZpYWJsZSBldmlkZW5jZSI+PHRpdGxlPmtvbG0gdmVyaWZpYWJsZSBldmlkZW5jZTogc2lnbmVkIGFuZCBvZmZsaW5lLXZlcmlmaWFibGU8L3RpdGxlPjxjbGlwUGF0aCBpZD0iciI+PHJlY3Qgd2lkdGg9IjMwMCIgaGVpZ2h0PSI0MCIgcng9IjgiLz48L2NsaXBQYXRoPjxnIGNsaXAtcGF0aD0idXJsKCNyKSI+PHJlY3Qgd2lkdGg9IjExOCIgaGVpZ2h0PSI0MCIgZmlsbD0iIzBFMTMxMCIvPjxyZWN0IHg9IjExOCIgd2lkdGg9IjE4MiIgaGVpZ2h0PSI0MCIgZmlsbD0iIzExODc1QSIvPjxnIHRyYW5zZm9ybT0idHJhbnNsYXRlKDE2IDEwKSBzY2FsZSgwLjYyKSIgZmlsbD0iIzQ1RDk4RSI+PHJlY3QgeD0iNCIgeT0iNiIgd2lkdGg9IjQuNSIgaGVpZ2h0PSIyMCIgcng9IjAuNCIvPjxyZWN0IHg9IjEzIiB5PSI5IiB3aWR0aD0iNC41IiBoZWlnaHQ9IjE0IiByeD0iMC40Ii8+PHJlY3QgeD0iMjIiIHk9IjEyIiB3aWR0aD0iNC41IiBoZWlnaHQ9IjgiIHJ4PSIwLjQiLz48L2c+PHRleHQgeD0iNDIiIHk9IjI1LjUiIGZvbnQtZmFtaWx5PSJTZWdvZSBVSSxIZWx2ZXRpY2EsQXJpYWwsc2Fucy1zZXJpZiIgZm9udC1zaXplPSIxNSIgZm9udC13ZWlnaHQ9IjcwMCIgZmlsbD0iI0VDRUZFQSI+a29sbTwvdGV4dD48cGF0aCBkPSJNMTM1IDIwLjVsNCA0IDgtOC41IiBmaWxsPSJub25lIiBzdHJva2U9IiNGRkZGRkYiIHN0cm9rZS13aWR0aD0iMi40IiBzdHJva2UtbGluZWNhcD0icm91bmQiIHN0cm9rZS1saW5lam9pbj0icm91bmQiLz48dGV4dCB4PSIxNTQiIHk9IjI1LjUiIGZvbnQtZmFtaWx5PSJTZWdvZSBVSSxIZWx2ZXRpY2EsQXJpYWwsc2Fucy1zZXJpZiIgZm9udC1zaXplPSIxMy41IiBmb250LXdlaWdodD0iNjAwIiBmaWxsPSIjRkZGRkZGIj52ZXJpZmlhYmxlIGV2aWRlbmNlPC90ZXh0PjwvZz48L3N2Zz4=">
</a>

Best for places that allow an image tag but not raw SVG, such as a help center, a status page, or an email signature. One tag, no external request: the whole badge travels inside the data URI.

Replace your-slug in every snippet with the slug from your Trust Link, for example kolm.ai/v1/trust/acme-support-agent.

03 / A badge that can go stale

Want the badge itself to tell the truth? Point it at the live route.

The three snippets above are fixed artwork: a permanent link to your Trust Link, where the report's real state always shows. If you would rather the badge image change on its own as the evidence ages, embed the live status badge instead. It reads the same signals the verifier reads, rendered as a small pill.

d / Live status badge
[![kolm agent security](https://kolm.ai/v1/trust/your-slug/badge.svg)](https://kolm.ai/v1/trust/your-slug)

Best when you want the pill to reflect the current report without re-embedding. The image is served from your Trust Link, so it stays a pure link on your side and changes only as your evidence does. Cached about five minutes.

Fresh, signed, in date

Green: N% ready

A report generated within the last 30 days shows its readiness rollup, colored by band: green at 80 and up, amber from 50, red below 50.

Older than 30 days

Grey: stale (Month YYYY)

Past 30 days the pill loses its color and names the month it was generated. The report stays verifiable; the badge stops vouching for its freshness. A continuous plan re-signs on a schedule, so the pill stays current instead of greying out.

Issuer key revoked

Grey: report revoked

If kolm revokes the key a report was signed with, revocation outranks everything: the pill reads revoked and never shows a readiness number, because the signature can no longer be trusted.

Slug not found

Grey: unknown

A slug that fits the link format but matches no report degrades to a neutral grey unknown pill rather than a false green, so a mistyped link never vouches for a report that is not there.

At the Trust Link the same evidence reads in full words: a report is CURRENT up to 30 days, AGING from 30 to 90, STALE past 90, and VOID if the key is revoked. The live badge collapses that into one conservative pill that greys out at 30 days.

04 / At the click

Where the badge leads, the math takes over.

The badge is the easy part. What makes it worth embedding is what happens after the click: the same offline verification that runs on this site, in the visitor's own browser.

01 · Click The badge opens your Trust Link

A visitor clicks the badge and lands on your public Trust Link, kolm.ai/v1/trust/your-slug, with your latest signed evidence report.

02 · Check Ed25519, in their browser

The signature is verified against kolm's published issuer key, offline. The signature covers the canonical bytes, so any edit breaks it in front of the reviewer.

03 · Read A result they can stand behind

A green seal and the scoped findings, mapped to the frameworks a reviewer cites. Their own browser ran the check against the published key; the report supplied everything else.

05 / Use it well

A few rules so the badge keeps meaning something.

The badge is only as good as the link behind it. Keep it pointing at your own evidence and it stays a real signal.

Link to your own Trust Link

The badge must point at the Trust Link for your account. Do not link it to the sample, to another vendor's slug, or to a page that is not your signed report.

required

Do not assert a result the report does not

The badge says the evidence is signed and verifiable, not that an agent is certified secure. Let the report state the findings and the scope. The signature is the claim.

scoped, not a warranty

Keep it current

On a continuous plan your Trust Link is re-signed on a schedule, so a pinned badge always opens your latest evidence. See continuous plans.

re-attested

Use the mark as published

Use any of the three snippets as given. Keep the three-bar mark and the link intact rather than rebuilding a look-alike, so a reviewer recognizes a real kolm badge.

consistent

06 / Questions

Common questions

Does a visitor need an account to verify?

No. Clicking the badge opens your Trust Link, where the signed report is verified in the browser against kolm's published issuer key. No account, no upload, no kolm server in the trust path.

What does the badge prove?

The badge itself is a link. The proof lives at your Trust Link: an Ed25519-signed report whose signature covers the exact bytes, so a reviewer can confirm it was not altered and was signed by the key they expect. Try it on the sample.

Where does my Trust Link come from?

A live Trust Link ships with the continuous plans. Start a free scan, then move to a plan that keeps the evidence current. See pricing.

What happens when my report is re-attested?

On a continuous plan the Trust Link stays current as the report is re-signed. The badge keeps pointing at the same link, so it always opens your latest signed evidence.

What if my report goes stale or its key is revoked?

The static badge stays a link, so it always opens your Trust Link, where the state shows plainly. For a badge that changes on its own, embed the live status badge: it greys to stale (Month YYYY) after 30 days and to report revoked if kolm revokes the signing key. A continuous plan re-signs on a schedule, so it stays current.

Will the Markdown badge work on GitHub?

Yes. READMEs strip inline SVG, so snippet b renders a flat badge in kolm's colors through shields.io. For a zero-dependency badge, host the SVG yourself or use snippet a where HTML is allowed.

Is the badge artwork ASCII-only?

Yes. The SVG uses plain ASCII characters and embeds the kolm three-bar mark, so it pastes cleanly into any editor and renders the same everywhere.

Already a customer? Find your Trust Link in your dashboard.

Get a Trust Link. Wear the badge.

A signed report your buyer verifies in their own browser, and a badge that takes them straight to it.

Ed25519-signed Offline-verifiable Sample report

Caveats: Scope is contractual. Permission posture, redaction and audit-trail integrity are assessed. Injection is tested and reported, not warranted.