1. Fundamental Principles of the Seal
The seal and its dynamic parameters are immutable; any URL tampering immediately invalidates verification.
Every dynamic seal links directly and publicly to the audited business record in the Public Registry.
Every invocation, validation, or anomaly generates an immutable, serialized transaction log.
2. Official Seal States
The Digital Trust Badge can strictly assume one of six normative states:
| State | Normative Meaning | Public Interface Effect |
|---|---|---|
| Active | Evaluation passed successfully; active certification. | Interactive green dynamic seal active; listed in directory. |
| Suspended | Grace period active due to uncorrected minor technical observations. | Seal displays warning alert; public notice details resolution grace period. |
| Revoked | Permanent withdrawal due to serious breach or expired grace period. | Seal disabled permanently; historical resolution archived publicly. |
| Expired | Annual validity period ended without renewal submission. | Inactive certificate; prompts merchant for renewal audit. |
| Under Review | Technical audit or evidence re-inspection in progress. | Public record accessible in processing state. |
| Pending | Application filed without completed audit. | No active seal rendering or public certificate. |
3. Validation Scope & Exclusions
What the Seal Validates: Active SSL/HTTPS encryption, local commercial and fiscal presence in Querétaro, verified RFC status, real customer support channels, and compliant Privacy Notices.
Exclusions: The seal does not audit product quality, individual purchase satisfaction, pricing disputes between parties, nor does it replace ISO certifications or financial bonds.
4. Multilayer Protection Architecture (AVM-QRO)
The seal verification is protected by five independent security layers: Context Validation (Layer 1), Cryptographic Validation (Layer 2), Access Control (Layer 3), Traceability & Audit (Layer 4), and Continuous Monitoring (Layer 5).