LintTrust
The working paper behind a WebTrust opinion, written from the certificates themselves.
LintTrust reads a CA's certificates, judges each one against the CA/Browser Forum Baseline Requirements in force when it was issued and at the end of the audit period, and writes the working paper per WebTrust criterion, with the evidence, the questions only the auditor can answer, and the auditor's own appreciation beside its verdicts. It states facts. You keep the judgement and the signature.

What It Does
Every certificate, against the right edition.
Nineteen editions of the TLS Baseline Requirements, from 2.1.2 to 2.3.0. A certificate issued in March 2025 is judged against the edition of March 2025, and again against the edition in force at the end of your period. Both verdicts are shown, and the rule written later is named as such.
Every criterion, with its evidence.
Verdicts are grouped by WebTrust criterion, not by linter rule. Under each criterion, the certificates that pass, the certificates that fail, and for each failure the Baseline Requirements clause, the value found, and the value required. Two clicks from the summary to the byte.
The auditor's appreciation, kept apart.
Where the auditor judges a failure non-material, or compliant with an observation, the appreciation is recorded with its basis, marked, counted apart, and printed in the working paper. LintTrust never changes a verdict on its own.
What a Linter Cannot Do
An independent comparison with zlint and pkilint on the same certificates, read against the text of the Baseline Requirements:
- Twenty-five non-conformities the linters could not see, because the check needs the issuer's key, the certificate's declared type, or a clause no linter implements.
- Twenty false findings the linters raised, among them fourteen wildcard names the Baseline Requirements permit and that pkilint rejects.
- One hundred ninety-five recommendations reported as findings by the linters. LintTrust keeps a
RECOMMENDEDapart from aMUST, and lets the auditor apply the strict reading deliberately, workspace-wide. - Sections no linter reads: root and cross-certificate validity, the CA's declared profile, the dated rules on both sides of their date.
The Working Paper

A working paper per engagement: the audit period, the editions applied, the verdicts per criterion, the evidence per certificate, the questions awaiting the auditor, the appreciations with their basis, and the observations on recommendations, apart. PDF and Word, in any script the certificates carry. Ten thousand certificates in one workspace, and the CA certificate store beside them, seeded from the CCADB.
Who It Is For
Audit firms.
Less time cross-referencing the Baseline Requirements by hand, the same reading on every engagement, and a criterion-level evidence trail behind the opinion.
Certification authorities.
Quarterly self-audits on your own sample, a dry run before the auditor arrives, and a new profile tested against every edition before the first certificate is issued.
Questions
What does LintTrust read?
X.509 certificates, one at a time or by the thousand, in DER or PEM, as files or zips. Nothing else: no CA system access, no private key, no password.
What does it judge them against?
The CA/Browser Forum's TLS Baseline Requirements, nineteen editions from 2.1.2 to 2.3.0, and the WebTrust for CAs TLS criteria that cite them. Each certificate is judged against the edition in force when it was issued and against the edition in force at the end of the audit period.
Does LintTrust give an audit opinion?
No. It states what the certificates show, clause by clause, and records the auditor's own appreciation beside its verdicts. The opinion and the signature stay the auditor's.
How is it different from zlint or pkilint?
A linter returns lines per certificate. LintTrust groups verdicts by WebTrust criterion across the whole population, keeps a recommendation apart from a requirement, judges by the edition in force, reads what a standalone linter cannot (the issuer's key, the chain, the declared profile), and writes the working paper. An independent comparison on the same certificates is on this page.
What can it not decide?
What a certificate does not carry: whether the CA validated a name, whether a serial number came from a random generator, whether an organization is an affiliate. Those rows say so, and the auditor answers them once, with a basis, under his name.
Where does it run?
On LintTrust's servers in the European Union, one isolated instance per customer, reached over TLS with an account and a second factor. Nothing is installed on your side.
What comes out?
A working paper per engagement, as PDF and Word, in the scripts the certificates carry, the evidence per certificate, and the certificates themselves as a zip for the audit file. A CA receives a report of findings by severity with the recommended action.
Who can see my data, LintTrust included?
Your instance is yours: its database, its files, and its backups are separate from every other customer's and encrypted at rest. LintTrust's staff have no standing access to it. An operator sign-in for support happens only at your written request, and every one is written in your instance's journal, which you read. You can export everything and delete everything, at any time, and receive a written confirmation of the deletion.
Which certificates should I bring to a demonstration?
None are needed: the demonstration runs on a fictional PKI built for it. If you would rather see your own certificates judged, send a sample the day before and they will be shown.
What does it cost?
An annual licence per organization, by the referentials used and the number of certificates. Ask for a demonstration and a quote.
Will other referentials follow?
Yes, soon: the EV Guidelines, the S/MIME and Code Signing Baseline Requirements, and the WebTrust criteria that cite them, on the same engine. Each is licensed as a module, so a CA that issues TLS certificates only pays for TLS.
How do I know the verdicts are right?
Every verdict names the clause it applies and the value it read, so it can be checked by hand. The editions of the Baseline Requirements are taken from the CA/Browser Forum's own repository, commit by commit. A fictional PKI of 108 certificates, one rule each, written from the text before any run, is judged at every release, and independent checks against zlint and pkilint are published on this page.
Where is my data hosted?
In the European Union, in France, on servers LintTrust operates, one isolated instance per customer. A data processing agreement under the GDPR is part of every contract, whatever the customer's own jurisdiction.
Request a Demo
A thirty-minute demonstration on a fictional PKI, or on a sample you send the day before.
Thank you. You will hear from us within two working days.
Your request could not be sent. Please write to contact@linttrust.com.