Notary Geek · source review

NotaryCam’s Virginia claims: law, dates and evidence

The article contains demonstrably false Virginia law summaries and unsupported compliance assurances. KBA was expressly added in July 2024. Platform operation, company size and private certification do not establish that a notarial act satisfies the law. The related commercial presentation combines no-SSN charges and biometric assurances with NIST agency-logo trust signals; this audit addresses that combined reliance concern as well as each underlying representation.

Page reviewed: Online Notary Virginia. Displayed publication date ; retrieved .

Substantive article text, tables and FAQ available in the October 2 web extraction; repeated responsive text deduplicated. Adversarial rechecks used first-party indexed text after direct opens returned 403. Displayed date is not independently proven publication history. No raw HTML, complete versioned page capture or original-page hash was preserved.

What readers need to know

Scope of this review

This is a case study within Notary Geek’s broader investigation of platform assurances, identity methods and industry reliance across states, including Texas. Virginia matters here because the reviewed page uses its history and asserted flexibility to sell confidence. The audit assesses substantive legal, historical, operational and comparative propositions in the article text, tables and FAQ available in the October 2 extraction. It separately marks related-source findings and historical interpretation. This is not proof of exhaustive coverage of a preserved page version. It does not claim Virginia is inherently the problem or that another state’s workflow is compliant by default. The broader inquiry requires a dated claim, controlling law and actual method evidence for each state.

What these evidence limits do—and do not—mean

Each evidence limit applies to a particular question. Preserve both the established finding and its limit; do not use an unrelated uncertainty, hypothetical defense or credential to erase a documented contradiction. Revise a finding when relevant evidence answers it, and identify exactly what changed.

Treating an unobserved signing session as a reason to dismiss a documented public legal error.

No session inspection limits conclusions about a particular notary’s act. It does not undo the six source-backed contradictions identified in this review. Evaluate the published rule against the cited authority and date; evaluate a particular act against its separate record.

What this does not establish: The audit does not prove a particular act defective, and lack of that proof does not establish that the published assurance is correct.

Related findings: VA06; VA08; VA13; VA15; VA16; VA33

Turning a performed check into proof of law.

A provider may use KBA, fingerprints, a selfie or additional checks. Identify whether the governing law required that check, whether it qualifies as the claimed statutory method, and whether the complete process satisfied that method. Technical operation and legal sufficiency are different propositions. An optional authorized method need not be universally mandatory.

What this does not establish: A successful check, vendor name or assurance label alone proves neither statutory authorization nor compliance; voluntary additional checks are not thereby prohibited.

Related findings: VA16; VA17; VA19; PC05; PC08

Treating a possible earlier route as an established historical defense.

KBA was expressly added effective July 1, 2024. A provider asserting another earlier route must identify its then-applicable authority, adoption history and complete method evidence. The unresolved IMSAC chain is a research lead; mentioning KBA/biometrics in guidance does not establish that authority or the provider’s compliance.

What this does not establish: Do not replace the proven express-addition date with an assumption of unchanged law. This record also does not prove that every earlier KBA-assisted act violated the law.

Related findings: VA27; VA49

Using retroactive validation to claim that original duties were met or the criticism no longer matters.

The validation rule concerns legal effect and preserves stated challenges/remedies. It does not establish what method ran, what the historical law required, whether a duty was met or whether a marketed legal rule was accurate.

What this does not establish: Neither automatic invalidity nor automatic compliance follows. A commissioned notary’s method failure is not automatically an unauthorized-person case.

Related findings: VA49

Using MISMO review, IAL2, SOC 2 or a title-market requirement as legal approval.

Recognize the credential’s actual scope. MISMO performs standards review and excludes jurisdiction-specific legal verification; a named IAL2 level still needs version/configuration/assessment and statutory mapping. A procurement contract can require a credential without making it proof of the notarial method.

What this does not establish: A private assessment not obtained by this review is neither disproved nor presumed favorable evidence for the missing legal proposition. Standards compliance, company reputation and transaction compliance are not interchangeable.

Related findings: PC03; PC04; PC05; MS02; MS03; MS05

Letting a qualification elsewhere cure a contradictory categorical summary.

Preserve accurate conditions where the article states them. The body’s alternative-method discussion does not make a table’s universal CA/KBA rule accurate. Application/technology-description review does not become Secretary platform-compliance approval.

What this does not establish: This review does not call every sentence false or deny every administrative review. Neither concession answers the particular false assurance.

Related findings: VA15; VA16; VA17

Treating corrections to our draft or a count of supported entries as exoneration of the remaining findings.

The review corrected onboarding, workflow-policy and qualified document examples and acknowledged NotaryCam’s IAL2 statement. Those repairs apply to those entries. Assess each remaining false finding on its own evidence; supported propositions do not cancel unrelated contradictions.

What this does not establish: Seventy-seven entries are not seventy-seven errors, and there is no valid vote-count rule under which correct statements erase material false ones.

Related findings: VA14; VA20; VA25; VA37; VA38; VA40; PC05; VA15; VA16

Using incomplete page capture to call independently identified contradictions unsupported.

The missing original-page snapshot limits exhaustive version-specific coverage and publication-history claims. It does not erase the identified representations, including text supplied by the user and checked against retrieved first-party text, or their comparison with official authorities. A contrary dated capture should be examined proposition by proposition.

What this does not establish: No complete forensic capture is claimed. A later correction does not by itself show that the earlier representation was accurate, and an audit hash does not authenticate the original page.

Related findings: VA06; VA15; VA16

Using intent, company size or widespread practice to avoid answering a false assurance.

The source-quality objection concerns the accuracy of the assurance sold. It does not require a finding of criminal intent. Evaluate the representation and applicable law; familiarity, market share, early entry, commercial acceptance or the critic’s small size do not answer that question. Unknown intent does not establish either knowing deception or good faith.

What this does not establish: The audit does not establish every actor’s motive or every competitor’s historical effort. That limit is not a defense of the identified false statement, and calling the pattern theater does not answer it.

Related findings: VA15; VA16; MS04

Treating official handbook shorthand as permission to ignore enacted requirements.

The current handbook is relevant guidance and reliance context. When a summary conflicts with the controlling statute, identify and resolve the conflict rather than treating the summary’s official origin as proof that a statutory condition disappears.

What this does not establish: The handbook does not itself establish a provider’s actual method or cure its public assertion. This finding does not deny the evidentiary value of agency guidance.

Related findings: VA08; VA16; VA17

Dismissing the issue as a Virginia technicality or assuming a different state solves it.

Virginia is this provider-selected case study. A method condition can determine whether a marketed assurance is true. The same dated authority-and-method inquiry applies in Texas and other states; correct performance would remove the need to sell Virginia as a compliance shortcut.

What this does not establish: The record does not establish a fifty-state violation, Texas compliance, or another provider’s fitness. A broader research gap does not diminish this page’s established errors.

Related findings: VA10; VA15; VA16; VA26

Reducing a false compliance assurance to harmless wording because no injury or deliberate deception was proved.

The page presents legal rules and review/certification signals to guide platform selection. A source-backed contradiction in that guidance remains a substantive accuracy problem requiring correction. A possible editorial mistake, obsolete source or automated drafting process is an explanation to investigate, not proof the assurance was true.

What this does not establish: This audit does not establish an injured customer, actual buyer reliance, liability or how the article was authored. Those separate questions do not need to be resolved before identifying and correcting the false representation.

Related findings: VA15; VA16

Using possible logo permission, public-domain government works or possible conformity to dismiss the official-assurance concern.

Evaluate the observed trust presentation separately from authorization and technical conformity. General government-work reuse does not authorize agency-logo use. Possible permission is not obtained permission; actual permission does not create endorsement. NIST’s lack of a Digital Identity Guidelines certification program does not disprove an independent assessment. Neither the logo nor an assessment supplies the statutory identity method.

What this does not establish: The audit does not establish unauthorized logo use, a government enforcement decision or failed IAL2 conformity. Those limits do not turn the agency logo into proof of certification, approval or legal compliance.

Related findings: PC05; PCX05

Treating framework-derived practices, a confidential report or absence of a known breach as proof of the advertised security outcome.

Separate claimed practice, implemented control, scoped assessment and advertised outcome. Report confidentiality does not prove absence; it also does not permit inventing a favorable opinion or unlimited coverage. NIST is unspecified here, so do not silently select CSF 2.0 or IAL2 as the full security baseline. Recognize SOC 2’s assurance scope without reducing the objection to terminology. The overstatement can be corrected without first demonstrating a security incident.

What this does not establish: The audit does not establish a breach, ineffective encryption, nonexistent audits or failed conformity. Even established security-control effectiveness would not itself prove the statutory identity method or notarial-law compliance.

Related findings: PC04; PC05; PCX06; PCX07; PCX08

Weakening a NIST SHALL NOT to a preference, or using statutory KBA, terminology, an older revision or hypothetical extra checks as automatic conformity clearance.

Read the current identity-verification restriction together with the distinct fraud-management permission and documented tailoring process. The rule names both KBV and KBA; renaming the quiz does not avoid it. Historical analysis must include Revision 3’s FAQ excluding KBV as satisfying IAL2/IAL3 verification. Identify the actual qualifying verification method and any compensating-control evidence rather than inventing them. Preserve the distinction between state-law notarial duties and voluntarily claimed technical conformity.

What this does not establish: The baseline prohibition does not ban every use of knowledge questions or determine state-law validity. Permitted fraud checks and documented deviations do not by themselves prove the provider follows them, satisfy unmodified baseline verification, or authorize the NIST agency logo.

Related findings: PC05; PC07; PCX05; PCX09

Investigation context

Platform and industry assurances substituted for the applicable law and actual transaction evidence.

The provider selected Virginia’s history and purported flexibility as a commercial assurance. This case study tests that assurance.

Broader investigation scope

A broader research lead; this Virginia-page audit does not purport to resolve Texas law or particular Texas sessions.

Correct methods and technology under the governing law would remove the need to sell Virginia as a special compliance shortcut.

Company size and certification are not legal proof

Notary Geek is small. Our standard is to identify the transaction, controlling law, effective date, identity method and supporting evidence before recommending a route. Buyers should apply that same standard to every provider, including us. Repeated marketing, market share and early entry cannot answer a statutory-authority question. A false assurance remains a problem even without evidence of deliberate deception. Greg Lirette’s criticism of this confidence-selling pattern as a scam concerns the false assurance being sold; calling the same pattern compliance theater does not answer the defect. Attribution to Notary Geek does not reduce the cited statute or official disclaimer to competing preferences; resolve the proposition from the evidence rather than market size.

The dates matter

  1. — HB 2318 / chapter 731 approved; its out-of-state jurisdiction amendment removed the prior Virginia-recordation-purpose wording.
  2. — HB 2318 audio-video provisions effective. Early identity paths were personal knowledge, conforming antecedent in-person proofing, or qualifying certificate-based access; not today's five-item menu.
  3. — Secretary published Assurance Standard v 1.0, including explicit disclaimer of technology compliance determinations.
  4. — Emergency HB 2064 / chapter 78 introduced two-of-four structure, credential-analysis and identity-proofing definitions, adopted-guidance route, and in-state electronic-certificate location wording.
  5. — HB 1372 / chapter 832 approved.
  6. — KBA definition and expressly enumerated fifth method effective under ordinary effective-date rule. This is roughly two years before the article, not fourteen years of an unchanged CA/KBA law.
  7. — Chapter 832 makes only the § 47.1-20.1(B) validation provisions retroactive to earlier acts. It preserves challenges to records/transactions and other remedies, and excludes purported acts by unauthorized persons.
  8. — Recordkeeping requirement expanded to nonelectronic notarial acts, with five-year retention; proof-of-commission requirement for seal purchase also effective.
  9. — Future instruction/examination requirement effective: initial instruction four hours; recommission instruction two hours; within preceding six months. Recommission instruction recurs.

Claim-by-claim findings

83 findings: 67 article findings and 16 supplemental findings. Findings may examine different dimensions of the same statement; this is not a count of unique claims or errors. Classifications apply to each stated finding and review date.

Article findings

These findings examine statements in the reviewed article.

History and comparative claims

Supported within stated scope

2011 enactment

Source-based finding: HB 2318 / chapter 731 was approved March 26, 2011. Distinguish enactment from the later operational effective date.

Article location: Opening; quick answer

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Supported within stated scope

July 2012 effectiveness

Source-based finding: HB 2318's second enactment makes its audio-video provisions effective July 1, 2012.

Article location: Requirements table

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Supported within stated scope

First-state history

Source-based finding: Official Maryland legislative analysis identifies Virginia as the first state, effective July 1, 2012. This history does not establish current comparative reliability.

Article location: Title; opening; comparison

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Unsupported

Other-state influence

Source-based finding: Maryland's 2016 legislative note supports one concrete example. A claim about most states needs an identified population and state-by-state legislative evidence.

Article location: Opening

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Unsupported

Maturity establishes reliability

Source-based finding: Age does not establish fewer failures, errors, objections or re-executions. Comparative outcome claims need dated operational evidence; none is supplied by the legal sources.

Article location: Maturity sections; acceptance FAQ

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

False

Statutory section range

Source-based finding: The official Chapter 2 index includes § 47.1-6.1 then § 47.1-7. The cited 6.1-through-6.7 range does not exist.

Article location: Requirements table

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization. Lack of a transaction inspection does not weaken the documented contradiction in this published legal representation; it limits conclusions about particular completed acts.

Notary and signer location

Supported within stated scope

RON location

Source-based finding: Section 47.1-16(A) requires each Virginia electronic notarial certificate to identify the Virginia county or city where the electronic notary was physically located. Read with § 47.1-13(B), that specific provision supports the article’s location statement for electronic/RON acts. It should not be extended to traditional acts.

Article location: Location section; table; FAQ

Evidence boundary: This is the reading supported by the specific current certificate text. No judicial decision resolving the interaction with the broader extraterritorial language was obtained.

False

Traditional location

Source-based finding: § 47.1-13(B) permits Virginia notaries to perform compliant acts outside Virginia. The old Virginia-recording-purpose limitation was removed in 2011.

Article location: Comparison table

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization. Lack of a transaction inspection does not weaken the documented contradiction in this published legal representation; it limits conclusions about particular completed acts.

Supported within stated scope

Remote signer location

Source-based finding: Virginia's remote appearance framework permits separation between signer and notary; Title 47.1 imposes no located-in-Virginia requirement on the remote principal. Receiving-law and document requirements remain separate.

Article location: Location section; tables

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Unsupported

Foreign US nexus

Source-based finding: No categorical foreign-principal US-nexus condition was found in current Title 47.1. Require an actual Virginia authority or label it as a provider/recipient restriction. New York's express nexus condition must not be imported into Virginia.

Article location: Location section; tables

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Supported within stated scope

Florida/New York comparison

Source-based finding: Ordinary Florida online notaries and New York electronic notaries must be in their respective states. Florida separately addresses commissioners of deeds. This limited location comparison does not make the identity laws equivalent.

Article location: RON location section; FAQ

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Commissioning, education and platform review

Misleading

Additional notary credential

Source-based finding: The underlying additional authorization is real: an existing Virginia notary registers and is commissioned as an electronic notary. Use the official eNotary terminology rather than implying a distinct statutory remote-endorsement category.

Article location: Credential section; table; FAQ

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

False

Present training requirement

Source-based finding: As of the displayed publication date July 15, 2026 and review October 2, 2026, the new statutory education/exam requirement is future law, effective July 1, 2027. Provider training may be distinct.

Article location: Credential section; FAQ

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization. Lack of a transaction inspection does not weaken the documented contradiction in this published legal representation; it limits conclusions about particular completed acts.

Incomplete

One-time onboarding

Source-based finding: The body ties initial setup to the four-year commission cycle; preserve that qualification in the FAQ. Electronic-capability registration is resubmitted at renewal under Standard § 1.1(a). Updated technology requires notice within 90 days under § 47.1-7(C). From July 1, 2027, recommissioning instruction requirements also apply. Initial provider onboarding may occur once; recurring state duties remain.

Article location: Credential/onboarding body paragraph: commission-cycle qualification; FAQ about the additional Virginia electronic-notary credential: shorter onboarding description

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

False

State platform review

Source-based finding: The article’s platform-review quality inference is false. Virginia’s reviewed notary authorities do not establish an approved/supported-platform regime. Standard § 1.1(c) disclaims Secretary system-compliance determinations and places responsibility on the notary to use compliant technology. An individual notary’s application approval is not platform approval. The notary must select and use a lawful identity method and compliant technology for the act. This does not mean no agency ever examines technology for any administrative purpose. Administrative examination does not substantiate the advertised inference of system-compliance approval.

Article location: Credential section

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization. Lack of a transaction inspection does not weaken the documented contradiction in this published legal representation; it limits conclusions about particular completed acts.

Identity methods and the July 2024 change

False

Mandatory CA/KBA pairing

Source-based finding: The requirement/comparison tables and quick answer incorrectly present CA/KBA, with a no-SSN biometric alternative, as the Virginia identity rule. The body elsewhere correctly acknowledges other statutory methods; the summaries should agree with it. Current § 47.1-2 permits personal knowledge, an oath or affirmation from a qualifying credible witness, or at least two of five methods: (1) credential analysis of the specified unexpired government ID; (2) qualifying antecedent in-person proofing under the Federal Bridge Certification Authority specifications; (3) another method authorized by applicable adopted guidance, regulations or standards under § 2.2-436; (4) the specified valid digital certificate accessed by biometrics or interoperable PIV-card route; or (5) statutory KBA. Credential analysis plus KBA is one combination, not a universal requirement.

Article location: Virginia-requirements table: identity verification row; RON/traditional comparison table: identity verification row; Quick answer: identity-method summary

Evidence boundary: The false finding concerns the categorical summaries, not every paragraph. The body’s recognition of alternatives is relevant counterevidence, but does not cure contradictory prominent summaries. Lack of a transaction inspection does not weaken the documented contradiction in this published legal representation; it limits conclusions about particular completed acts.

Misleading

No-SSN biometric substitution

Source-based finding: Missing an SSN creates no separate statutory biometric exception. Clause (c)(4) concerns a valid signer certificate accessed by biometrics or the qualifying PIV route; clause (c)(3) requires applicable adopted authority. Generic selfie/liveness alone does not identify either method. The article’s body itself asks providers to identify the statutory method; its categorical summaries should preserve that requirement. The privacy notice describes document verification as well as face comparison, so it does not establish that credential analysis is absent.

Article location: Tables; FAQ; quick answer; platform advice

Evidence boundary: This challenges the advertised legal shortcut. It does not establish that every biometric feature is unlawful, that credential analysis is absent, or which complete method was used in a session.

Misleading

Credential-analysis independence

Source-based finding: Law specifies independent affirmation of a government credential using public/proprietary data and Secretary standards. A separate vendor is a common implementation, not the definition's exact organizational requirement; the (c)(1) credential must be unexpired and bear face photo and signature.

Article location: Credential-analysis section

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Provider claim

Credential security-feature checks

Source-based finding: The listed document security-feature checks describe a technical implementation claim. The statute does not prescribe that particular list, but that does not refute the description. Identify what the actual service examines and retains; this audit did not test those checks.

Article location: Credential-analysis section

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Provider claim

Credential-analysis timing

Source-based finding: Earlier credential analysis can be part of a compliant workflow. Identification must still bind the result to the principal appearing at the act. This review did not test that binding or establish that the provider treats an earlier result alone as sufficient.

Article location: Credential-analysis section

Evidence boundary: Pre-session processing itself is not evidence of a defect. The sequencing and binding remain operational substantiation questions.

Misleading

KBA public-record definition

Source-based finding: Statutory KBA may draw from public or private sources, with no prior answer supplied by the principal. It is not defined as exclusively US public records.

Article location: KBA section

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Supported within stated scope

KBA quiz numbers

Source-based finding: The article’s quiz minimum, score, timing and two further attempts within 48 hours align with the statute. The full minimum is five questions, at least five possible answers per question, 80% correct, two minutes, no more than two additional quizzes within 48 hours, and no more than 60% reuse of initial questions on later attempts. Statutory KBA can draw from public or private data; the principal must not have supplied the answers beforehand.

Article location: Requirements table; KBA section

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Supported within stated scope

Provider stricter KBA

Source-based finding: Providers may impose narrower service policies, but should label them provider policy. Such policy neither changes the state minimum nor proves that alternative statutory routes are unavailable.

Article location: KBA section; table

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Provider claim

KBA on-camera workflow

Source-based finding: The article expressly describes on-camera KBA timing as NotaryCam’s workflow. This is a provider implementation assertion; no signing session was tested. It should remain labeled as that provider’s process, rather than be generalized into a Virginia-wide legal rule.

Article location: KBA section

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Provider claim

KBA failure stops notarization

Source-based finding: A failed KBA result cannot satisfy the selected KBA route. Stopping that session may accurately describe a stricter provider policy; Virginia does not require the provider to offer every alternative. This is not a statewide rule excluding other independently satisfied identity routes.

Article location: KBA section

Evidence boundary: No completed failed session was observed. The legal existence of other routes does not disprove the provider’s stop-on-failure policy.

Misleading

US records and nationality

Source-based finding: Insufficient data can be a provider KBA eligibility issue; nationality and SSN status do not themselves select a Virginia legal method. Actual source coverage and provider support need separate evidence.

Article location: Biometric discussion; FAQ

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Incomplete

Longstanding biometric flexibility

Source-based finding: The early certificate/biometric route is real: it appeared in the 2011 enactment. That history does not establish generic selfie substitution. KBA became an expressly enumerated fifth method on July 1, 2024. That date alone does not decide whether an earlier workflow satisfied another then-authorized route, including qualifying antecedent proofing or, from 2021, an identity-proofing method authorized under § 2.2-436. Identify the dated authority and evidence for the complete method.

Article location: Biometric discussion; conclusion

Evidence boundary: The article’s narrower claim of longstanding certificate-based flexibility has support. Extending that history to an unspecified contemporary biometric workflow requires additional evidence. A possible earlier route is not an established defense; the applicable authority and actual method must be shown.

Unsupported

Most-states KBA generalization

Source-based finding: No dated denominator, state inventory or treatment of personal knowledge/credible-witness/other exceptions is supplied. Do not replace it with an equally unsupported opposite generalization.

Article location: Identity section; FAQ

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Unsupported

Biometrics improve completion

Source-based finding: This operational outcome needs data plus a demonstrated lawful method. Biometric capability or successful software completion alone does not establish statutory compliance.

Article location: Signer experience; platform advice

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Records, format and personal appearance

Supported within stated scope

Electronic record retention

Source-based finding: Electronic notarial records have a five-year minimum from transaction date. Preserve the distinction between required journal/conference records and an unsupported claim that every kind of platform data shares that retention rule.

Article location: Tables; retention FAQ

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Misleading

Journal per session

Source-based finding: § 47.1-14(C) requires a record for each notarial act, including prescribed particulars. A session containing multiple acts must not be reduced to an undifferentiated session-only record.

Article location: Tables; retention FAQ

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Supported within stated scope

Conference recording

Source-based finding: The required audio-video conference recording accompanies identification records for the remote act and five-year retention. The article's wording should not imply optional platform-only custody.

Article location: Tables; retention FAQ

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

False

Traditional journal optional

Source-based finding: Section 47.1-14(C) requires a record for each notarial act. Under subsection (D), records of nonelectronic acts performed on or after July 1, 2026 must be retained at least five years from the transaction date. The article’s traditional-record summary is wrong as of its displayed July 15 date.

Article location: Comparison table

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization. Lack of a transaction inspection does not weaken the documented contradiction in this published legal representation; it limits conclusions about particular completed acts.

Supported within stated scope

Electronic format and tamper evidence

Source-based finding: An electronic act involves an electronic document; § 47.1-16(D) requires independently verifiable signature/seal attachment that evidences subsequent changes. A seal graphic alone does not supply this property.

Article location: Comparison table

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Supported within stated scope

Physical appearance in-person

Source-based finding: For an ordinary in-person act, the signer appears physically before the notary. Remote appearance is the specifically authorized alternative; compare like-for-like without treating all electronic notarization as remote.

Article location: Comparison table

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Documents, execution and receiving requirements

Supported within stated scope

Permitted act types

Source-based finding: Acknowledgments, oaths/affirmations and copy certification are recognized acts. Copy certification is bounded: the statutory definition excludes public records and § 47.1-12 excludes court-custody documents.

Article location: Document eligibility introduction

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Supported within stated scope

Deeds and mortgages

Source-based finding: The document row is conditional and tells readers to confirm lender acceptance. Virginia supports compliant electronic land documents and notarizations; recordability still has content, format, fee and submission conditions. Those conditions are useful cautions, not a refutation of the qualified example.

Article location: Document table: deeds and mortgages row, including lender-confirmation qualification

Evidence boundary: Supported with conditions. Broad comparative acceptance claims are reviewed separately in PC09; they should not be imported into this qualified row.

Supported within stated scope

Loans and promissory notes

Source-based finding: The loan example is qualified by lender acceptance. An acknowledgment can be available; execution, negotiability and electronic-record rules still depend on the document and applicable law. The stated qualification should be preserved, and UETA should not be assumed to govern every instrument.

Article location: Document table

Evidence boundary: Supported as a conditional document example, not verification of every loan workflow or recipient decision.

Supported within stated scope

Corporate/affidavit/commercial examples

Source-based finding: These are plausible categories for authorized notarial acts, conditional on the actual act, execution, authority and receiving requirements. Corporate authority and truth of substantive claims are not established merely by notarization.

Article location: Document table

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Supported within stated scope

Powers of attorney

Source-based finding: The POA example directs readers to counsel and applicable requirements. Virginia permits acknowledgment of POA signatures under § 64.2-1603. Signing, recordability and recipient requirements remain separate conditions, not a contradiction of the qualified example.

Article location: Document table

Evidence boundary: Supported with the article’s counsel and document-specific qualifications; no particular POA was evaluated.

Misleading

Wills and trusts

Source-based finding: The row includes counsel/witness qualifications, which matter. Nevertheless, listing wills and trusts as a RON document category can blur notarial acknowledgment or self-proving affidavits with will execution. Section 64.2-403 governs execution/witnessing; UETA § 59.1-481(b)(1) excludes creation and execution of wills, codicils and testamentary trusts. RON authority alone does not resolve those separate requirements. Not every trust is excluded and not every will-related notarization is forbidden.

Article location: Document table

Evidence boundary: The misleading assessment concerns the insufficiently separated categories despite the stated caveats; it is not an allegation that the article promises every will can be executed remotely.

Supported within stated scope

USCIS supporting documents

Source-based finding: The article's conditional receiving-agency check is appropriate. It establishes no universal USCIS notarization requirement or acceptance of every remotely notarized submission.

Article location: Document table

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Not independently verified

Court wet-ink restrictions

Source-based finding: The article gives a conditional caution about court requirements, not a statewide prohibition. No named court, document or governing rule was established in this review. Check the applicable rule for the intended filing; do not assume either universal wet-ink requirements or universal RON acceptance.

Article location: Additional-review table

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Supported within stated scope

Foreign-government acceptance

Source-based finding: A Virginia-valid notarial act does not itself establish compliance with a foreign receiving authority. The article appropriately says to verify the receiving requirements, without proving any particular country result.

Article location: Additional-review table

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Misleading

I-9 as RON category

Source-based finding: I-9 completion by an employer's authorized representative is not a notarial act; USCIS says not to affix a notary seal. Remote document examination is a separate DHS-authorized procedure with eligibility conditions.

Article location: Additional-review table

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Supported within stated scope

State-law variations

Source-based finding: Virginia authority applies to the Virginia notary's act. Other states can have distinct identity, record and document rules; compliance, electronic execution, receiving-law recognition and commercial acceptance must remain separate questions.

Article location: Document-section note; disclaimer

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Administration and fees

Supported within stated scope

Regulating authority

Source-based finding: The Secretary commissions/registers electronic notaries and develops the relevant standards with VITA assistance. This administrative role does not imply state platform certification.

Article location: Requirements table

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Supported within stated scope

Electronic fee cap

Source-based finding: § 47.1-19(B) caps the listed electronic notarial acts at $25. Do not equate this automatically with a platform's total transaction price or use it to imply unlimited ancillary notary fees.

Article location: Requirements table

Evidence boundary: This is a review of the published representation, not a finding about a particular completed notarization.

Provider capabilities and commercial assurances

Conflicting statements

Network exclusions

Source-based finding: Current purchase page explicitly offers real-estate closings using the network. A product-lane distinction may exist, but the article does not explain one. Request reconciliation rather than asserting that all network products are identical. Provider service boundaries must be checked against the current product lane; the published real-estate network offer conflicts with the unqualified exclusion.

Article location: Notary Capacity; platform selection

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true.

Incomplete

Device compatibility

Source-based finding: The article’s broad device description should be reconciled with the FAQ’s desktop/laptop and Chrome guidance and the terms’ desktop/laptop and Chrome-or-Firefox wording. No tablet or mobile signing session was tested. Request the current browser/OS/device matrix for the applicable product; omission from the FAQ does not prove a device unsupported.

Article location: Signer Experience; platform selection

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true.

Supported within stated scope

MISMO certification

Source-based finding: Preserve this as a supported statement. MISMO certification is not Virginia approval or a determination that an individual session satisfies state law. NotaryCam is listed in MISMO’s certified RON directory; MISMO expressly limits the legal significance of its certification.

Article location: Platform selection

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true.

Not independently verified

SOC 2 assurance

Source-based finding: Provider pages repeat the representation. No report or assurance-period details were obtained. Lack of public report access is not proof that an audit does not exist. Request the current SOC 2 report, covered system, examination period and exceptions. Do not infer state-law compliance from the badge. The unavailable report also supplies no affirmative basis in this review to assume compliance or a favorable assessment; if obtained, evaluate what its actual scope proves. The related security FAQ also claims external audits and penetration testing; PCX06–PCX08 distinguish those asserted practices from the stronger outcome assurances.

Article location: Platform selection

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true.

Not independently verified

NIST badge

Source-based finding: The footer badge is generic, but NotaryCam’s software-licensing page separately names NIST IAL2. The claimed publication/revision, covered workflow/configuration and assessment/control mapping were not obtained. Neither a badge nor the named level establishes Virginia’s statutory identity route or government approval. The compliance assertion remains unverified, not disproved. Separate finding PCX05 records confirmed agency-logo use on the homepage and licensing page, its misleading official-assurance presentation and the unresolved authorization question. PCX09 adds the specific KBA/KBV restriction and requires reconciliation of the advertised IAL2 workflow with the applicable NIST revision.

Article location: Page footer badge

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true. Naming IAL2 corrects an omission in our draft; it does not verify the claim, prove Virginia-method compliance or weaken unrelated false-law findings.

Provider claim

Service models

Source-based finding: The product catalog advertises licensing and notary service capacity. Actual availability and contractual responsibilities need a product-specific agreement. Distinguish licensed software for a customer’s own notaries from the provider’s separately supplied notary service.

Article location: Platform selection

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true.

Provider claim

On-camera KBA

Source-based finding: Public terms describe KBA as a primary route, but do not verify the article’s on-camera sequence. To substantiate the representation, identify the KBA provider, product/state/workflow version, quiz start and end relative to the live video session, binding of the result to the signer, and pass/fail, retry, time and question-reuse controls. A documented demonstration or redacted audit example would test the claim; this review did not perform a signing session.

Article location: KBA section

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true.

Provider claim

Biometric workflow

Source-based finding: The privacy disclosure describes identity-document verification and facial comparison through Jumio/Persona; purchase pages offer no-SSN categories. These are meaningful disclosures, but do not establish the commissioned state or complete statutory method in a particular session. Ask which separate listed method supplies the other part of a two-method route, or whether personal knowledge or a qualifying credible witness applies. This review does not infer that credential analysis is absent.

Article location: Biometrics sections and signer experience

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true. Missing session evidence supports neither transaction-specific noncompliance nor affirmative compliance, and does not erase the public-law contradictions or clear the provider assessment.

Unsupported

Acceptance advantage

Source-based finding: The article supplies no comparative acceptance dataset, sampling method or institution-specific policy supporting the ranking. State-law recognition and recipient operational acceptance are separate questions. Confirm acceptance with the actual lender, title underwriter and recording office. A framework’s age is not acceptance evidence for a specific transaction.

Article location: Maturity discussion and FAQ

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true.

Unsupported

Operational advantage

Source-based finding: No controlled comparison or defined error/risk metrics establish a causal Virginia-wide performance advantage. Individual customer case studies cannot establish that general comparison. Evaluate measured completion times, failures, re-executions and escalation handling for the actual workflow.

Article location: Maturity discussion; operational benefits

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true.

Unsupported

Resolved edge cases

Source-based finding: No operational evidence demonstrates that current identity, retention, recording or document edge cases are resolved for each provider. Request current evidence for the failure scenarios that matter to the transaction.

Article location: Maturity discussion; conclusion

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true.

Not independently verified

Available capacity

Source-based finding: FAQ acknowledges busy periods and later appointment scheduling. No Virginia-specific staffing, queue or service-level evidence was obtained. Published hours and a mature market do not establish immediate notary availability.

Article location: Notary Capacity

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true.

Provider claim

Integration benefits

Source-based finding: Tagging and software offerings are advertised. The general benefit is plausible but no particular integration or quantified impact was tested. Request a demonstration using the required documents and record how corrections are handled.

Article location: Operational benefits; platform evaluation

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true.

Provider claim

Fraud reduction

Source-based finding: Multiple features and retained records are advertised. This audit did not measure fraud reduction, inspect session logs, or validate every retained field. Record the actual identity method and retain its supporting evidence; an audit-trail label alone does not establish it.

Article location: Audit trail and authentication discussion

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true.

Provider claim

Assignment controls

Source-based finding: Provider advertises trained, vetted staff, but no current Virginia assignment-control or commission-validation evidence was obtained. The notary’s commission, authority, actual location and session evidence remain relevant regardless of who handles scheduling.

Article location: Credentialing discussion and FAQ

Evidence boundary: Published product claims were reviewed; no private assurance report or transaction was inspected. Unsupported is not a finding that the opposite is true.

Additional table and workflow checks

Supported within stated scope

Commission term

Source-based finding: Section 47.1-21 provides a four-year ordinary commission, subject to the title’s exceptions, with expiration in the fourth calendar year on the last day of the notary’s birth month. This does not make electronic capability registration permanent.

Article location: Credential / remote endorsement section

Evidence boundary: Scope is the published statement and cited rule or product offering.

Incomplete

In-person identity

Source-based finding: The table’s shorthand omits the qualifying credible-witness route and the statutory limits on acceptable identity documents. Physical presence alone does not dispense with satisfactory evidence under § 47.1-2.

Article location: Comparison table

Evidence boundary: Scope is the published statement and cited rule or product offering.

Supported within stated scope

Traditional recording

Source-based finding: Title 47.1 imposes no general audio-video recording requirement for an ordinary traditional act. Keep this separate from the notarial-record requirement that became mandatory for nonelectronic acts on July 1, 2026.

Article location: Comparison table

Evidence boundary: Scope is the published statement and cited rule or product offering.

Provider claim

Multiple signers

Source-based finding: The provider FAQ advertises support for multiple signers, including separate signing appointments. That supports the product representation; no multi-signer session or appointment availability was tested.

Article location: Eligible-documents table: corporate resolutions and certifications

Evidence boundary: Scope is the published statement and cited rule or product offering.

Supplemental findings

These findings add chronology analysis or examine related provider, certification and industry materials. They are not all statements made in the reviewed article.

Identity methods and the July 2024 change

Incomplete

Historical continuity inference

Source-based finding: The article does not expressly say KBA was authorized in 2012. Its maturity narrative can nevertheless obscure material identity-law changes: audio-video authority from July 1, 2012; credential analysis and the two-of-four structure from March 11, 2021; express KBA addition as method five from July 1, 2024. RON’s age does not establish an unchanged CA/KBA framework. This chronology does not determine whether a particular earlier process independently qualified under another then-authorized route.

Evidence location: Historical/identity sections read together: reviewer inference, not a located express KBA-date statement

Evidence boundary: Supplemental historical analysis, not another literal false article quotation. No categorical earlier-act illegality or invalidity conclusion follows from the express-addition date; § 47.1-20.1(B) validation must be considered separately. The converse also does not follow: unresolved earlier-route evidence does not prove earlier compliance, and validation does not establish that original duties were met.

Related provider disclosures

Provider claim

Current no-SSN pricing

Source-based finding: Keep the real-estate $50 no-SSN add-on distinct from the other-document $79 no-US-SSN fee. Do not re-label the latter as an international-location fee or infer an unshown checkout total.

Evidence location: Related provider pages; contextual finding

Evidence boundary: Context from separately identified pages, not an additional quotation or assertion attributed to the Virginia article.

Provider claim

International coverage

Source-based finding: 145-country marketing describes geographic service reach. It does not establish document eligibility, recognition by every foreign recipient, or compliance with every destination’s execution law.

Evidence location: Related provider pages; contextual finding

Evidence boundary: Context from separately identified pages, not an additional quotation or assertion attributed to the Virginia article.

Provider claim

Historical international workflow

Source-based finding: The 2023 credit-union case study supports historical use and marketing of biometrics for international borrowers, with a negotiated price. It supplies no transaction-level commissioned state or identity-method evidence.

Evidence location: Related provider pages; contextual finding

Evidence boundary: Context from separately identified pages, not an additional quotation or assertion attributed to the Virginia article.

Provider claim

Provider retention promise versus state minimum

Source-based finding: Software licensing advertises ten-year minimum video/journal retention. Keep this separate from any Virginia minimum and verify contractual access and exit arrangements.

Evidence location: Related provider pages; contextual finding

Evidence boundary: Context from separately identified pages, not an additional quotation or assertion attributed to the Virginia article.

Misleading

NIST agency logo presented as a compliance trust badge

Source-based finding: NotaryCam’s homepage and licensing page place the NIST agency logo in a TRUST footer beside SOC 2 and MISMO badges, with the extracted image label NIST Compliant. Our assessment is that this combined presentation misleadingly suggests official assurance beyond a claim of conformity. Commerce DAO 201-1 requires outside-use approval and a written license, and specifically evaluates placement and proximity to other symbols for apparent improper endorsement. The NIST Digital Identity Group says it does not operate a certification program for these guidelines. Identify the authorization covering this display and separately the publication, revision, covered implementation and basis of any independent conformity assessment. A logo or IAL2 label establishes neither NIST certification nor notarial-law compliance. Permitted uses are specific: approved outside-use license terms may cover a defined NIST relationship or project attribution. A historical NIST documentary funding opportunity expressly required recipients to include logo credit but barred it on derivative works. Asset-specific editorial permissions and separate CMVP validation marks do not authorize this agency-logo trust display. Identify the authorization covering the exact use; following publications or using validated cryptography does not itself grant it.

Evidence location: Related homepage and software-licensing page: TRUST footer; not independently recaptured on the Virginia article in this supplement.

Evidence boundary: Misleading is an editorial inference from the combined presentation, not a quotation claiming NotaryCam literally says NIST certified. The image itself contains no certification text. No logo license or agency decision about this display was obtained: unauthorized use is not established. That uncertainty does not establish authorization, endorsement or certification. Actual IAL2 conformity remains unverified, not disproved. Independent assessment is possible; other NIST programs have distinct validation marks. Extracted image labels and link resolution were verified, not raw DOM alt/title attributes. Commerce’s outside-use policy is not treated here as a court ruling that every conceivable unlicensed editorial depiction is unlawful. The historical project and specific editorial image are examples of scoped permission, not evidence of NotaryCam permission.

Misleading

Framework-derived practices presented as ensuring the strongest security controls

Source-based finding: The passage moves from practices derived from NIST and SOC 2 to assurance that the service meets the most stringent controls. Derivation does not establish implementation, assessed effectiveness or a defined highest control baseline. NIST is not one identified control set; specify the publication, revision and applicable profile. CSF 2.0, if that is intended, describes risk-management outcomes without prescribing their implementation. SOC 2 concerns scoped assurance against Trust Services Criteria; naming it does not supply the report. Our misleading classification addresses the unsupported leap in assurance. Identify the control baseline, system boundary, assessment and meaning of the superlative, or replace it with a scoped statement.

Evidence location: Related Why NotaryCam page: security-measures FAQ

Evidence boundary: The passage does not literally claim NIST certification or identify CSF 2.0. A separate licensing page names IAL2; that does not identify the complete security baseline here. This review does not establish that practices were not derived from these sources, that no SOC 2 report exists or that every control is ineffective.

Unsupported

Encryption and testing presented as continuous security assurance

Source-based finding: The surrounding FAQ links encryption to security at all times and external audits/testing to data always being secure. The stated measures do not establish those unqualified outcomes. Define the protected assets, threat scope, assessment period and residual limits. A scoped report or successful penetration test cannot by itself substantiate an unlimited future-security assurance. Correct the guarantee language without waiting for a demonstrated breach. AICPA’s explanatory testimony expressly recognizes that even mature cybersecurity programs remain susceptible to breaches.

Evidence location: Related Why NotaryCam page: security-measures FAQ

Evidence boundary: No breach, exploitable defect, failed test or deficient encryption was observed. This finding concerns the unsupported breadth of the advertised assurance, not a determination that the platform is insecure. Marketing shorthand is not evidence of the asserted outcome.

Provider claim

Security measures, external audits and penetration testing

Source-based finding: Preserve the provider’s stated encryption, notary screening, training, monitoring, external auditing and penetration testing as representations. No implementation evidence or assessment report was inspected. Request the applicable control mapping and appropriately shared report or summary: assessor, date or period, covered system, criteria, exclusions, findings and remediation/retest status. Clarify which advertised audit is a SOC 2 examination; a generic external audit or penetration test is not interchangeable with one.

Evidence location: Related Why NotaryCam page: security-measures FAQ

Evidence boundary: A report may be confidential. Nonpublication does not establish absence or failure; it also supplies no affirmative evidence in this review for a favorable opinion, highest-controls ranking or continuous-security guarantee. No customer records, credentials, exploit details or sensitive penetration-test payloads are requested.

Incomplete

KBA marketing requires reconciliation with NIST and IAL2 assurances

Source-based finding: Current NIST SP 800-63A-4 section 2.5.1 expressly prohibits both KBA and KBV for identity verification; this is a baseline requirement, not merely a recommendation. Section 3.2.1 permits KBV for fraud management, and documented tailoring is addressed separately. Even Revision 3’s official FAQ says KBV cannot satisfy IAL2/IAL3 verification requirements, despite limited supplemental use. NotaryCam’s KBA descriptions, separate IAL2 claim and broader NIST assurances therefore require a revision-specific workflow explanation: which method performs baseline identity verification, or what specifically documented deviation and compensating controls are used, what role KBA serves, and what exact configuration is assessed? Identify any compensating controls, risk rationale, residual risk and DIAS disclosure, relying-party review and risk-acceptance determination. State-law authorization or requirement for KBA does not establish NIST approval, and NIST conformance alone does not establish a state-law notarial method.

Evidence location: Cross-source comparison: provider KBA descriptions, licensing IAL2 assurance and Why NotaryCam NIST-derived practices

Evidence boundary: The published sources establish a specific conformity question, not that every NotaryCam workflow fails. Generic derived-from-NIST language is narrower than full identity-guideline conformance; the separate IAL2 claim makes the identity requirements directly relevant. Additional fraud checks and documented tailoring are real possibilities but have not been shown for this provider. Do not silently invent another verification method or DIAS. Revision 4 is not applied retroactively; Revision 3 permitted tightly bounded supplementary KBV. A normal video notarization is not automatically NIST’s technically defined supervised-remote proofing.

Misleading

NIST trust presentation alongside paid no-SSN biometric assurances

Source-based finding: The commercial message must be assessed together: NotaryCam promotes a Virginia biometric alternative for international signers lacking a U.S. SSN, advertises no-SSN charges, and presents the NIST agency logo and IAL2 language as trust signals. Its categorical Virginia identity rule is false and the advertised SSN-based biometric shortcut is misleading: the statute creates no such exception, and an ordinary face match does not identify the complete authorized method. The purchase page lists a $50 no-SSN real-estate add-on and, separately, a $79 no-US-SSN fee in the other-document category. Our assessment is that combining the deficient legal assurance with agency-logo trust presentation invites buyers to rely on a paid route whose legal and technical basis has not been substantiated by that presentation. Identify the actual statutory method, NIST revision/configuration and logo authorization; correct the combined message rather than treating each badge, fee and assertion as unrelated.

Evidence location: Cross-source commercial presentation: Virginia article, purchase-page fee categories, homepage and licensing trust footers

Evidence boundary: The combined reliance concern is an editorial inference from identified public pages. No particular buyer’s reliance, payment or transaction outcome was observed. The fees are advertised by SSN status, not proven to be a nationality-only or foreign-location charge; the total or additive basis of the $79 fee remains unresolved. The fee itself is not classified as unlawful. No knowing intent, absent logo permission, universal workflow defect or agency finding is asserted. These limits do not cure the separately established false legal rule or substantiate the paid route.

MISMO and title-industry reliance: supplemental findings

Supported within stated scope

Certification history

Source-based finding: NotaryCam appears in MISMO’s current certified RON provider directory. The 2020 provider announcement and ALTA item are historical evidence of the certification announcement. Preserve the certification fact. Distinguish a private standards credential from government approval and transaction-specific legal proof.

Evidence location: Related certification and trade-publication material; contextual finding

Evidence boundary: The finding concerns the identified program materials, not proof of a particular completed act.

Supported within stated scope

Attestation and review

Source-based finding: The current program requires application material, questionnaire/attestations, supporting documentation and a system demonstration. MISMO reviews submissions and demonstration artifacts, allows remediation and makes the certification decision. Calling the entire program pure self-certification would misdescribe the published process. Applicant attestations are inputs to a private standards review; they are not the whole process. The existence or rigor of this standards review does not rebut the specific legal misstatements identified elsewhere or expand MISMO’s stated scope.

Evidence location: Related certification and trade-publication material; contextual finding

Evidence boundary: The finding concerns the identified program materials, not proof of a particular completed act. A real review process or applicant attestation supplies no jurisdiction-specific legal determination beyond the stated certification scope; absence of the private report is not evidence that it resolves the missing method.

Supported within stated scope

Legal scope exclusion

Source-based finding: MISMO expressly excludes verification of compliance with particular federal, state, county or other governing-body laws, rules and requirements. The program measures its RON standards. A MISMO result cannot establish that a Virginia no-KBA session used an authorized identity method. The applicable authority and session record must establish that separately.

Evidence location: Related certification and trade-publication material; contextual finding

Evidence boundary: The finding concerns the identified program materials, not proof of a particular completed act.

Misleading

Title-industry reassurance

Source-based finding: NotaryCam’s November 18, 2020 certification announcement attributes broad confidence in secure, compliant remote mortgage closings to founder Rick Triola; ALTA’s November 24 item republishes it. The context is certification against MISMO standards. The audit’s concern is the inference that readers may treat that assurance as sufficient legal confidence, not an express promise that every transaction is valid. A contemporaneous September 2020 interview with MISMO’s technology vice president already distinguished standards certification from explicit certification of jurisdictional legal compliance. ALTA’s publication proves circulation of the attributed assurance, not its independent legal adjudication or actual reliance by a title company.

Evidence location: Related certification and trade-publication material; contextual finding

Evidence boundary: This is an identified interpretive concern. The signed 2020 agreement, completed NotaryCam application, assessor work and transaction records were not obtained. The current disclaimer alone does not establish every historical review step. The criticism does not depend on intent. Uncertainty about this assurance’s implication and actual audience reliance does not make the separately documented statutory contradictions uncertain. ALTA’s republication adds no independent verification of those statements.

Supported within stated scope

Applicant state assertions

Source-based finding: The questionnaire asks applicants to identify states whose RON laws, rules and regulations their platform complies with, and asks about KBA providers/passing results and credential-analysis providers. That is applicant-supplied information. The current program disclaimer still limits what MISMO verifies. Do not collapse an applicant’s assertion of state compliance, MISMO’s private certification decision, state commissioning, and evidence of one completed transaction into one approval.

Evidence location: Related certification and trade-publication material; contextual finding

Evidence boundary: Only indexed portions of the questionnaire were available. No completed NotaryCam application or private assessor report was obtained. A real review process or applicant attestation supplies no jurisdiction-specific legal determination beyond the stated certification scope; absence of the private report is not evidence that it resolves the missing method.

Counterarguments and evidence that could change the assessment

You ignore alternative methods acknowledged in the article body.

The body’s qualifications are preserved. The objection concerns contradictory categorical tables and quick answers; those should state the same complete rule.

What would change this assessment

  • Consistent corrected wording across the body, summaries, tables and FAQ.

Related findings: VA16; VA17

Express enumeration in 2024 does not prove all earlier KBA-assisted workflows unlawful.

The express statutory addition is established. A provider’s earlier use of KBA does not prove that the law required it or that it satisfied a statutory method. A provider invoking a different earlier route must establish the authority then applicable and compliance with that complete method. Mention of a technology component in guidance is not that proof; the audit does not claim voluntary extra checks were prohibited. Unresolved adoption/applicability establishes neither affirmative authority nor a particular transaction defect. An optional authorized method need not be mandatory for every act.

What would change this assessment

  • Dated adopted instrument and supersession history.
  • Applicable trust/assurance profile and actual workflow mapping, including a second qualifying method where required.
  • For antecedent proofing, evidence of the qualifying in-person event and Federal Bridge conformity.

Related findings: VA17; VA27; VA49

The Secretary’s handbook supports our interpretation.

The current handbook is included as counterevidence and reliance context. It contains abbreviated and internally differing summaries; it does not amend controlling statutes or prove a session’s method. Possible reliance may concern separately established fault or remedy questions; it does not make a conflicting summary the controlling rule or erase the demonstrated discrepancy.

What would change this assessment

  • Applicable controlling authority resolving the discrepancy.
  • Complete method evidence connecting the guidance to the transaction.

Related findings: VA08; VA16; VA17

Virginia reviews the technology description in an eNotary application.

Yes. Individual application review and certification are meaningful administrative steps. Standard § 1.1(c) nevertheless disclaims system-compliance determinations, so platform operation alone does not establish the advertised quality approval.

What would change this assessment

  • An agency instrument identifying the reviewed system/version, date and actual compliance-review scope.

Related findings: VA15

The validation statute protects historical notarizations.

Section 47.1-20.1(B) broadly protects against invalidation solely for a Title 47.1 duty or requirement failure; Chapter 832 makes that subsection retroactive. It does not insert KBA into the earlier methods list. Compliance, validity, transaction enforceability and retained remedies are separate questions. A method failure is not automatically an unauthorized-person case. Validation does not show that the original duty was met or that the marketing statement was correct.

What would change this assessment

  • Transaction-specific facts and analysis before alleging invalidity or a preserved remedy.

Related findings: VA49

Our qualified examples and stricter workflow policies are being treated as universal legal promises.

The audit has corrected those overstatements. Initial onboarding, pre-session processing, stop-on-failure policy and conditional deed/loan/POA examples are preserved as such. Will execution and I-9 verification still need to be distinguished from notarial authority. Those corrections do not change the separate false-law findings VA06, VA08, VA13, VA15, VA16 and VA33.

What would change this assessment

  • Precise product policy and current device/workflow documentation.
  • Document-specific execution and receiving requirements.

Related findings: VA14; VA19; VA20; VA25; VA37; VA38; VA40; VA41; VA45

MISMO performs real review and matters to lenders and title companies.

Agreed: it is more than pure self-certification and may have contractual significance. Its stated standards-review scope does not supply state-law authority or prove an individual act. Request the actual procurement requirement and separate legal-method analysis. The existence of a real standards review and a commercial preference do not rebut a specific legal misstatement.

What would change this assessment

  • The specific written contractual requirement and covered product.
  • A separate dated statutory-method analysis and evidence for the act.

Related findings: MS02; MS03; MS05

You apply today’s MISMO disclaimer retroactively to our 2020 certification.

The September 2020 interview already states the standards-versus-law distinction. This supports the historical scope boundary without claiming to possess the signed agreement or completed provider assessment. The broad-assurance criticism remains an identified inference.

What would change this assessment

  • The operative 2020 agreement and documented assessment scope.
  • Evidence of the particular legal conclusion or actual buyer reliance claimed.

Related findings: MS04

Our identity vendors and IAL2 claim answer the biometric concern.

The audit acknowledges document verification, face comparison and the named IAL2 level. These do not by themselves identify the applicable statutory method, publication revision, configuration or transaction evidence. Extra safeguards may be useful without constituting an independently sufficient method.

What would change this assessment

  • Claimed NIST publication/revision and assessed configuration.
  • Dated legal mapping and evidence for each required method, or the separate personal-knowledge/witness route.

Related findings: VA17; PC05; PC08

You never observed a session, so you cannot say our KBA process is false.

Correct: the on-camera sequence is classified as an untested provider claim, not an observed operational failure. A public legal-summary contradiction can be established separately. Greg’s concern remains an explicit question that a documented demonstration could answer. That concession is limited to actual performance in an unobserved session; it is not a concession that the separately evidenced legal-summary contradictions are speculative.

What would change this assessment

  • Provider, product, commissioned state and workflow version.
  • Redacted or synthetic demonstration showing quiz/video timing, signer binding and result/retry controls.

Related findings: VA24; PC07

Without deliberate criminal fraud, your criticism of selling false assurance fails.

Greg’s stated usage concerns the false assurance sold; it does not turn on a claim of criminal intent. Test the representation against the applicable requirement. A separate legal cause of action may have its own elements; this audit does not claim to prove those or every participant’s motive. An unknown mental state supports neither knowing-fraud allegations nor a presumed-good-faith defense. Do not downgrade a supported false finding merely because the elements of a separate fraud claim have not been established.

What would change this assessment

  • A source or method record that resolves the identified representation, rather than a dispute about the label alone.

Related findings: VA15; VA16; MS04

Your count and capture suggest more certainty than the evidence permits.

The ledger counts review entries, including supported statements, overlapping checks and supplemental analysis. It does not count unique errors. A complete original-page version was not preserved; textual locators and the observation manifest disclose that gap. The capture gap does not erase identified representations or their statutory contradictions; it limits exhaustive version-specific claims.

What would change this assessment

  • A dated complete source capture with provenance and original-content hash.
  • A reconciled source-to-finding inventory before claiming exhaustive version coverage.

Related findings: VA14; VA24; PC07; VA49

The logo merely identifies the standards publisher; compliance is not a claim of NIST certification, and permission may exist.

The literal compliance label and possible independent conformity assessment are acknowledged. The criticism concerns the agency logo’s combined placement among commercial trust badges, which suggests official assurance beyond attribution. Commerce’s policy expressly considers placement and proximity. Permission was not established either way, and would not itself establish endorsement, NIST-operated digital-identity certification or notarial-law compliance. The identity FAQ rules out the NIST-operated certification inference for these guidelines, not independent assessment. Approved project attribution, specifically licensed editorial assets and distinct validation marks are real permitted-use examples. None automatically licenses the generic agency logo for a commercial compliance presentation.

What would change this assessment

  • A license covering the exact use, and clear presentation identifying the claimed standard, revision, scope and independent assessment would warrant reassessing the presentation finding.
  • Removing or correcting the misleading trust presentation; any revised conformity claim requires its own evidence.

Related findings: PC05; PCX05

This is ordinary marketing shorthand, and confidential audit reports could substantiate the security program.

Recognized practices and confidential examinations may support a real security program. That does not make a derived-practices statement evidence of a highest control baseline or a time-unlimited outcome. The FAQ names no specific baseline, comparative measure or assessment scope supporting those conclusions. The wording can be assessed without public access to sensitive reports or a demonstrated incident. A limited report can substantiate the proposition within its scope; it cannot be generalized into unlimited security or notarial-law compliance.

What would change this assessment

  • A specific baseline and scope, with relevant control and assessment evidence, can substantiate a correspondingly limited security claim.
  • Replace unqualified strongest-controls and continuous-security assurances with accurate, scoped wording; provide a non-sensitive assessment summary or controlled report access where appropriate.

Related findings: PC04; PCX06; PCX07; PCX08

KBA is required by state law, was permitted in older NIST guidance, is only an extra fraud check, or is covered by tailoring.

These are separate, testable propositions. State law does not rewrite a NIST conformity requirement. Revision 3 allowed constrained supplementary KBV, but NIST’s FAQ expressly says it cannot satisfy IAL2/IAL3 verification. Revision 4 bars KBA/KBV as baseline identity verification and separately permits fraud-management use. Its tailoring provisions require documented rationale, comparability, residual risk and relying-party disclosure, review, risk-acceptance determination and DIAS record. Show the baseline verification method or documented deviation and compensating controls, KBA role and any relevant DIAS; a hypothetical compliant configuration is not evidence that the advertised service uses it. Conversely, KBA’s presence alone does not disprove every workflow.

What would change this assessment

  • A dated workflow and scoped assessment identifying the baseline verification method, or the specifically documented deviation and compensating controls, and KBA’s actual purpose.
  • The applicable revision and any actual tailoring/DIAS record, including required disclosure and relying-party acceptance, with accurate public scope.

Related findings: PC05; PC07; PCX06; PCX09

Open verification questions

Does the actual NotaryCam KBA sequence match the article’s on-camera description?

Unverified; Greg raised a specific concern on 2026-10-02. No contrary signing-session observation is asserted.

Evidence needed

  • Applicable KBA provider, product, commissioned state and workflow version
  • Quiz start/end and live-video event timing
  • Result binding to the signer and statutory controls
  • Documented demonstration or redacted audit example without raw customer identity data

Related findings: VA24; PC07

Which earlier adopted identity-proofing instrument and complete method, if any, did the provider rely on?

Unresolved; official IMSAC materials identify a possible authority chain but do not establish provider compliance. Its possibility supplies neither affirmative authority nor evidence that a particular act was defective; it does not clear the public assurance.

Evidence needed

  • Final adoption, effective date and supersession history of the 2016/2017 guidance.
  • Applicable trust agreement and assurance profile.
  • Actual method mapping for the specified transaction date, including both methods where required.

Related findings: VA17; VA27; VA49

What authorization covers the NIST logo display, and what substantiates the separate conformity claim?

Display confirmed on the homepage and licensing page; logo license, agency determination and implementation assessment not obtained.

Evidence needed

  • Approval/license or other applicable authorization terms covering this exact NIST agency-logo trust display, its purpose, layout and period; unrelated project permission is insufficient
  • Exact NIST publication/revision and identity-service configuration covered by the conformity claim
  • Assessor identity, assessment scope/date and relevant control mapping; distinguish independent assessment from NIST certification
  • Actual role of KBA/KBV in the advertised IAL2 workflow and the method that satisfies identity verification
  • Any claimed compensating controls: documented rationale, comparability, residual risk, DIAS and relying-party disclosure, review, risk-acceptance determination and DIAS record; identify the revision and configuration

Related findings: PC05; PCX05; PCX09

What defined baseline and assessment support the security FAQ’s strongest-controls and continuous-security assurances?

Representations confirmed; applicable control baseline, comparative measure and scoped assessment evidence not obtained.

Evidence needed

  • Named publication/revision, applicable profile or control baseline and defined system boundary
  • SOC 2 report type, assessor, covered period, criteria and opinion/exceptions, through appropriate access or a non-sensitive summary
  • Audit and penetration-test scope/date plus remediation/retest status, without sensitive payloads or customer data
  • Corrected language explaining what the evidence establishes and its limits

Related findings: PC04; PCX06; PCX07; PCX08

Source inventory

Source types distinguish controlling law, official guidance, provider statements, and investigative records. Each finding identifies the sources used for that proposition.

  1. Virginia Code § 47.1-2

    official statute or enacted legislation · Checked

    current statute

  2. 2011 Acts ch.731 / HB 2318

    official statute or enacted legislation · Checked

    approved 2011-03-26; audio-video provisions effective 2012-07-01

  3. 2020 Acts ch.902 / HB 1222

    official statute or enacted legislation · Checked

    approved 2020-04-09

  4. 2021 Special Session I Acts ch.78 / HB 2064

    official statute or enacted legislation · Checked

    approved and emergency-effective 2021-03-11

  5. 2024 Acts ch.832 / HB 1372

    official statute or enacted legislation · Checked

    approved 2024-04-17; ordinary effective date 2024-07-01; enactment clause 2 retroactivity limited to § 47.1-20.1(B)

  6. Virginia Code § 1-214

    official statute or enacted legislation · Checked

    ordinary July 1 effective-date and emergency-act rules

  7. Virginia Code § 47.1-13

    official statute or enacted legislation · Checked

    current statute

  8. Virginia Code § 47.1-16

    official statute or enacted legislation · Checked

    current statute

  9. Virginia Code § 47.1-14

    official statute or enacted legislation · Checked

    current statute; paper-act record rule from 2026-07-01

  10. Virginia Code § 47.1-7

    official statute or enacted legislation · Checked

    current statute

  11. Virginia Electronic Notarization Assurance Standard v 1.0

    official agency guidance (not a substitute for the statute) · Checked

    published 2013-01-21; still linked by current Secretary eNotary page on 2026-10-02; printed page 4/PDF page 6 § 1.1(c); § 1.1(a) renewal/resubmission duty

  12. Secretary: Learn About Becoming an eNotary

    official agency guidance (not a substitute for the statute) · Checked

    current official application guidance

  13. Virginia Code § 47.1-5.2

    official statute or enacted legislation · Checked

    future law effective 2027-07-01

  14. Secretary 2026 Notary Spotlight

    official agency guidance (not a substitute for the statute) · Checked

    distinguishes 2026-07-01 journal/seal rules from 2027-07-01 education rules

  15. Title 47.1 Chapter 2 official index

    official statute or enacted legislation · Checked

    § 47.1-6.1 followed by § 47.1-7; no §§ 47.1-6.2 through 6.7

  16. Virginia Code § 47.1-19

    official statute or enacted legislation · Checked

    current $10 paper / $25 electronic notarial-act caps; limited agreed travel expense

  17. Virginia Code § 47.1-12

    official statute or enacted legislation · Checked

    current enumerated notarial powers

  18. Virginia Code § 64.2-403

    official statute or enacted legislation · Checked

    current will-execution rules

  19. Virginia Code § 64.2-452

    official statute or enacted legislation · Checked

    self-proving will affidavits distinct from execution

  20. Virginia UETA, especially §§ 59.1-481 and 59.1-483

    official statute or enacted legislation · Checked

    current scope exclusions and consent requirements

  21. Virginia Code § 64.2-1603

    official statute or enacted legislation · Checked

    power-of-attorney execution and acknowledgment

  22. Virginia Code § 55.1-662

    official statute or enacted legislation · Checked

    electronic land-record validity

  23. Virginia Code § 55.1-663

    official statute or enacted legislation · Checked

    clerk eRecording implementation and acceptance

  24. Virginia Code § 17.1-223

    official statute or enacted legislation · Checked

    recordation conditions; fallback paper-copy route

  25. Maryland DLS 2016 HB 1111 fiscal/policy note

    official legislative analysis · Checked

    dated 2016-03-02; official legislative historical description of Virginia as first RON state

  26. Virginia Code § 2.2-436

    official statute or enacted legislation · Checked

    current approval/publication framework for electronic-identity guidance

  27. Virginia Code § 19.2-3.1

    official statute or enacted legislation · Checked

    B 1-B 3 communication standards incorporated by § 47.1-2

  28. Florida Statutes § 117.265

    official statute or enacted legislation · Checked

    2026 text; online-notary location and alternate identity-method wording

  29. New York Executive Law § 135-c

    official statute or enacted legislation · Checked

    latest displayed revision 2023-07-07; current electronic-notary location; NY foreign-principal nexus clause

  30. USCIS Completing Section 2 Employer Review and Attestation

    official federal agency guidance · Checked

    official search content retrieved; direct open returned 403; I-9 authorized representative does not affix notary seal

  31. USCIS Remote Examination of Documents

    official federal agency guidance · Checked

    official search content retrieved; direct open returned 403; DHS alternative procedure and E-Verify conditions

  32. Current complete Virginia Notary Act

    official statute or enacted legislation · Checked

    searched full title for nexus/United States; no foreign-principal US-nexus condition located

  33. Secretary 2024 Notary Handbook

    official agency guidance (not a substitute for the statute) · Checked

    historical 2024 handbook; some journal and jurisdiction language does not match later/current statutes

  34. Virginia Code § 47.1-20.1

    official statute or enacted legislation · Checked

    current limited validation rule; preserve remedies and unauthorized-person exception

  35. Virginia Code § 47.1-6.1

    official statute or enacted legislation · Checked

    Secretary develops electronic-notary standards with VITA assistance

  36. Virginia Code § 47.1-8

    official statute or enacted legislation · Checked

    current and future 2027 versions explicitly separated

  37. NotaryCam Virginia article

    provider statement — evidence of representation · Checked

    Initial web-extracted text; adversarial rechecks via first-party index after direct 403. Textual section/row locators in findings; no retained original-page version.

    Provider article is evidence of its representations, not proof of legal or operational compliance. Extracted text repeats much of its body; do not count repetition as independent evidence.

  38. NotaryCam current purchase options

    provider statement — evidence of representation · Checked

    full page retrieved by web open

    Markets network real-estate closings from $199, service hours 7am–11pm Eastern, $35 single-seal option, $50 no-SSN add-on; other documents $25/seal with $79 no-US-SSN fee wording. The fee basis and whether the latter is additional are not resolved by this wording.

  39. NotaryCam frequently asked questions

    provider statement — evidence of representation · Checked

    full search-index result; direct open returned 403

    Requirements list desktop/laptop, webcam/audio, Chrome and reliable high-speed connection. General 24/7 availability is separated from real-estate agents available 7am–11pm Eastern daily. Multiple signers and separate signing appointments are described. Busy periods can require scheduling the next appointment.

  40. NotaryCam privacy policy

    provider statement — evidence of representation · Checked

    full relevant section in search result; direct open returned 403

    Section II names Jumio and Persona and describes identity-document verification plus selfie/ID facial comparison, vendor-held biometric data and provider access to results. This is a capability/data-handling disclosure, not proof of a commissioned state or statutory method in an actual transaction.

  41. NotaryCam terms of service

    provider statement — evidence of representation · Checked

    full relevant sections in search result; direct open returned 403

    Terms describe KBA as primary proofing and face-scan biometrics for some approved transactions, name Jumio/Persona, and describe consent and 30-day biometric retention instruction. Transaction-specific approval is not identified as Virginia government approval. Electronic-record consent specifies desktop/laptop and Chrome or Firefox, whereas the FAQ names Chrome.

  42. NotaryCam service offerings

    provider statement — evidence of representation · Checked

    full page retrieved by web open

    Provider markets full-service RON, international service and 145-country coverage, staff notaries and identity verification. Its legal-eligibility caveat should accompany the geographical marketing.

  43. NotaryCam software licensing

    provider statement — evidence of representation · Checked

    search result

    Software licensing supports in-house notaries and advertises no monthly minimum use, training access, tagging, billing and at least ten years of video/journal retention. These are product representations, not an independently tested operational service level.

  44. NotaryCam security representations

    provider statement — evidence of representation · Checked

    search snippets; direct open returned 403

    Public materials carry SOC 2 Type 2 and NIST compliance badges. This audit obtained no current independent SOC report, audit period, opinion, scope or controls mapping and no NIST profile/assurance mapping. Related licensing page separately names IAL2; see P-licensing. Do not claim no assurance level is publicly identified.

  45. MISMO certified RON provider directory

    private standards body — primary program source · Checked

    official search result; direct open returned 403

    Official certified RON providers directory includes NotaryCam.

  46. MISMO NotaryCam certification entry

    private standards body — primary program source · Checked

    official search result; direct open returned 403

    Official certification directory has a NotaryCam company entry. Some certification details are images, not extracted text.

  47. MISMO RON certification process and limits

    private standards body — primary program source · Checked

    full official text in search result

    Certification reviews information, documents and a system demonstration against MISMO RON standards. MISMO expressly excludes verification of compliance with laws or requirements of a particular federal, state, county or other regulator.

  48. NotaryCam credit-union case study (2023)

    provider statement — evidence of representation · Checked

    full search-result content

    Historical provider case study describes a negotiated $25 member signing price, a partnership beginning in 2021, international students, biometric proofing and customers without SSNs. It supports historical marketing of the workflow, but does not identify the commissioned states or session-level statutory methods. Do not treat its negotiated historical price as the current retail rate.

  49. MISMO RON Questionnaire, Attestations, and Requested Documentation

    certifier primary application material · Checked

    Indexed first-page text and demonstration/attestation snippets retrieved; direct PDF open 403. No claim of full PDF examination.

    No completed NotaryCam application or private assessor report obtained.

  50. NotaryCam Certifies Compliance with MISMO RON Standards for Real Estate Transactions

    provider primary announcement · Checked

    Full relevant indexed text retrieved.

    Displayed publication date: 2020-11-18

  51. ALTA: NotaryCam Receives MISMO RON Certification

    trade-association primary publication of the communication; provider quotation within it is attributable to the provider · Checked

    Full direct webpage retrieved.

    Displayed publication date: 2020-11-24

  52. Virginia Code § 47.1-21

    official statute · Checked

    Commission term and expiration

  53. Secretary 2026 Notary Handbook

    official agency guidance (not a substitute for the statute) · Checked

    Cover says revised July 1, 2026; filename includes July 14. Printed pages 5, 8–9, 23–24.

    Current handbook includes shorthand identity summaries and reproduces the two-of-five statute. Page 5 recognizes compliant out-of-state acts; page 9 retains a Virginia document-use limitation inconsistent with § 47.1-13(B). Reconcile both current agency summaries and controlling law.

  54. Virginia IMSAC Identity Proofing and Verification Guidance IPV 1.0

    official published guidance; adoption history unresolved · Checked

    Printed pages 14–16, particularly page 16 footnote 4; Town Hall guidance record 6009.

    Discusses knowledge-based tests and biometrics within broader attribute-verification processes and remote registration. Town Hall metadata lists May 2, 2016 but retains proposal language. This is a possible authority-chain lead, not proof that Virginia notary law required those checks or that an adopted instrument authorized a provider’s actual method. Final adoption, applicability and full method compliance remain unresolved. Unresolved applicability establishes neither provider authorization nor a particular transaction defect.

  55. Virginia Register volume 34 issue 16: identity-guidance listing

    official agency guidance listing · Checked

    Printed pages 1589–1590, Secretary of Technology; revised identity-proofing guidance dated December 1, 2017.

    Lists revised guidance conforming to NIST SP 800-63A. The linked revised VITA document was not obtained. Adoption, supersession and applicability require further verification before relying on it as transaction authority. Unresolved applicability establishes neither provider authorization nor a particular transaction defect.

  56. NotaryCam current software-licensing page

    provider statement — evidence of representation · Checked

    First-party indexed text and successful web extraction; direct raw HTML returned 403. FAQ on licensing advantages and footer TRUST section.

    Names NIST IAL2. This corrects the prior audit draft’s statement that no assurance level was identified; no actual assessment or configuration mapping was obtained. The footer presents the NIST agency image beside SOC 2 and MISMO images; its extracted label is NIST Compliant and its image link resolves to P-nist-logo.

  57. MBA NewsLink: MISMO RON Certification — What You Need to Know

    contemporaneous interview: statements attributed to MISMO technology vice president · Checked

    Displayed September 21, 2020; URL/issue path says September 16. Reviewer read answers attributed to Jonathan Kearns; later direct recheck returned 403.

    Describes questionnaire/attestation, document and demonstration stages and distinguishes certification against MISMO standards from explicit certification of jurisdictional legal compliance. It is not the signed certification agreement or an MBA adjudication.

  58. NotaryCam homepage trust footer

    provider statement — evidence of representation · Checked

    Web-extracted footer, TRUST section; image link resolved to P-nist-logo.

    NIST Compliant image label appears beside SOC 2 and MISMO images. Search-service labels and link resolution were verified; raw DOM attributes were not.

  59. Commerce DAO 201-1: Symbols of the Department of Commerce

    official departmental policy · Checked

    Effective August 5, 2021; sections 7.02–7.06; official indexed text retrieved, direct open 403.

    Outside use requires approval and, for nonfederal users, a written license specifying manner, circumstances and period. Approval excludes actual or reasonably apparent improper endorsement; evaluation considers placement and proximity to other symbols. This is the applicable policy, not an agency determination about NotaryCam.

  60. NIST Digital Identity Group implementation FAQ

    official technical-program guidance · Checked

    Updated September 30, 2026; SP 800-63A question about CSP certification and trusted referees; direct page retrieved.

    NIST states that it does not operate a certification program for these Digital Identity Guidelines. This does not exclude independent conformity assessments or imply that no other NIST program has validation or certification marks.

  61. NotaryCam: Why NotaryCam security FAQ

    provider statement — evidence of representation · Checked

    Security-measures FAQ; user-supplied passage corroborated by first-party indexed text and successful web extraction on October 2; initial direct open returned 403.

    Describes practices derived from NIST/SOC 2, encryption, screening, training, monitoring, external audits and penetration testing; uses a strongest-controls superlative and continuous-security assurances. No report or implemented-control evidence was obtained. This is a related-page finding, not text attributed to the Virginia article.

  62. NIST Cybersecurity Framework 2.0 publication description

    official technical-framework source · Checked

    Published February 26, 2024; abstract; direct page retrieved.

    CSF 2.0 provides risk-management outcomes and does not prescribe how to achieve them. Cited to explain framework scope, not to assume that NotaryCam’s unspecified NIST reference means CSF 2.0 or that every NIST publication has the same scope.

  63. AICPA Trust Services Criteria, revised points of focus 2022

    standards body — primary assurance source · Checked

    Public resource description retrieved; full download requires account access and was not obtained.

    Describes criteria for evaluating and reporting on controls in attestation or consulting engagements. A criteria reference is distinct from evidence of a completed examination, its covered system, opinion and operating results.

  64. AICPA testimony on cybersecurity issues affecting health benefit plans

    standards body — primary explanatory testimony · Checked

    July 18, 2022; printed pages 4 and 6; full PDF retrieved.

    AICPA testimony explains that mature security programs remain susceptible to breaches and describes Type 2 opinions in terms of a defined system, reasonable assurance, control effectiveness and tests. This is explanatory testimony, not legislation, a guarantee or an assessment of NotaryCam.

  65. NIST documentary funding opportunity: project-specific logo attribution

    official historical project terms · Checked

    2016 funding opportunity, section I.4, printed page 8; PDF retrieved.

    Required the recipient to credit NIST as funding sponsor and use its logo in the completed documentary and copies, but excluded the logo from derivative works. Concrete historical permitted use, not a current general license or permission for NotaryCam.

  66. NIST CeramicAM Feedstock image: editorial reuse terms

    official asset-specific reuse terms · Checked

    Image page and licensing terms; direct page retrieved.

    This particular image containing a NIST logo is offered for editorial articles mentioning NIST with credit; stock-art use requires permission. Asset-specific terms do not authorize a commercial compliance badge or resolve all conceivable editorial/logo uses.

  67. NIST CMVP: use of validation logos and phrases

    official program-specific mark rules · Checked

    FIPS 140-3/140-2 mark rules; direct page retrieved.

    Eligible validated modules or products incorporating them may use prescribed validation marks under program rules, with certificate identification and a logo request. Those marks do not imply product endorsement and are distinct from the generic NIST agency logo.

  68. NIST SP 800-63A-4: identity proofing and enrollment

    official current technical requirements · Checked

    Final Revision 4, published July 2025; sections 2.5.1 and 3.2.1 items 15–16; direct text retrieved.

    Current baseline prohibits KBA/KBV for identity verification. It expressly permits KBV in fraud management; fraud measures used as compensating controls require documented deviations and DIAS disclosure to relying parties before integration. Collecting attributes for identity resolution is distinct from KBV.

  69. NIST SP 800-63-4: tailoring and Digital Identity Acceptance Statements

    official current technical requirements · Checked

    Sections 2.3.1 and 3.4.2–3.4.4; direct text retrieved.

    KBA is not an acceptable secret for digital authentication. Tailoring permits documented compensating controls with rationale, comparability, residual risk and relying-party communication/acceptance. Supplemental and compensating controls are not evidence of unmodified baseline conformity.

  70. NIST SP 800-63A: Revision 3 identity-proofing requirements

    official historical technical requirements · Checked

    Sections 5.3.2 and 9.3, plus IAL2 verification requirements; direct text retrieved.

    Revision 3 restricted KBV sources, required an alternative, excluded static/publicly obtainable answers and imposed question/attempt controls. Its usability guidance advised avoiding KBV. Read with the official FAQ: these limited provisions did not make KBV sufficient for IAL2/IAL3 verification.

  71. NIST Revision 3 Digital Identity Guidelines FAQ

    official historical technical clarification · Checked

    Dated March 3, 2022; Q-A4 and Q-B07; direct page retrieved.

    Q-A4 states that KBV cannot satisfy IAL2/IAL3 verification requirements, though it may supplement evidence verification in a risk-based evaluation. Q-B07 distinguishes prohibited KBA authenticators from restricted proofing KBV. This FAQ interprets Revision 3, not Revision 4.

Evidence limits

Correction request

Markdown source inputs prepared for provider corrections and NIST logo/identity-assurance review; document production is backlogged. No generation, sending, provider or agency response, admission or determination is claimed.