ResearchRank
DIGITAL SIGNATURES

Cryptographically signed certificate originals

ResearchRank supports hardware-token signing through the Windows agent and server PKCS#12 signing where an authorized private key is intentionally installed.

USB token / CryptoID mode

The private signing key remains inside the connected hardware token. After a paid certificate enters the queue, the Windows agent receives only the prepared PDF signing payload, asks the locally registered certificate to create the cryptographic signature, and returns the CMS signature to WordPress. The server verifies the response against the configured public certificate before accepting it.

Visible digital-signature status

Certificates prepared for cryptographic signing contain a visible Digitally Signed status area. The authoritative signature itself is the cryptographic PDF signature shown by a compatible PDF reader, not the visible label alone.

Registry verification

Every certificate carries a unique certificate number and QR verification URL. The verification page reports certificate status, evidence, ranking context and whether an official digitally signed PDF is on file.

Integrity preservation

The final signed PDF bytes are stored with a SHA-256 integrity hash and served without regeneration. Editing a signed PDF after signing may invalidate the cryptographic signature, so the signed original is preserved.

Security boundary

ResearchRank never needs the USB-token private key. Server PKCS#12 mode should be used only with a signing identity that your organization is authorized to store and operate on the server.

DETAILED GUIDANCE

Detailed service guidance

ResearchRank separates source data, analytical calculations, eligibility, payment, issuance and permanent verification so each step can be understood independently.

How should this page be interpreted?

Source-linked scholarly metadata describes the profile; ResearchRank calculations add ranking and recognition context. Eligibility is assessed independently of payment, and the certificate registry records the issued recognition separately from the changing live profile.

What happens when research data changes?

Profiles and rankings may change when indexed works, citations, affiliations, topics, open-access status or source records refresh. An issued certificate preserves its issue-time evidence and context; the live research profile can continue to evolve.

How are certification and payment separated?

Eligibility is determined before payment. Payment cannot create, increase or improve eligibility. Online payment must be verified by the server before certificate release; approved manual transfers follow the same issuance controls.

How are rankings and recognition calculated?

Ranking pages identify their ranking basis and evaluated population. Percentile recognition uses the profile's eligible ranking position relative to that population. Composite indicators are analytical aids and do not silently replace the stated ranking basis.

How is customer information protected?

Contact and delivery information is used for order fulfilment, certificate access, fraud prevention and limited transactional reminders. Sensitive payment credentials are handled by secure gateway components rather than stored in ResearchRank.

How does permanent verification work?

Each issued certificate receives a unique certificate number and verification record. Verification can show certificate status, issue date, recognition context and recorded scholarly evidence. A QR/reference on the PDF can point back to that record.

What are the limitations of bibliographic data?

Open scholarly metadata can contain author disambiguation errors, affiliation gaps, duplicate records, incomplete coverage and field differences. Source identifiers and linked records should be reviewed when the result is used for formal assessment.

What is the difference between live data and issue-time evidence?

Live data is refreshed for discovery and analytics. Issue-time evidence is the snapshot/context attached to the certificate transaction. This distinction helps preserve what was recognised even when current metrics later change.

How should ResearchRank recognition be described?

Use the exact certificate title and ResearchRank recognition class shown on the verification record. Do not describe a ResearchRank certificate as an official award or endorsement from OpenAlex, ORCID, a university, publisher or another external data source unless that organisation separately confirms it.