What Is Certificate Transparency?
Certificate Transparency is a system of public, append-only logs that record every TLS certificate a certificate authority issues, so a mis-issued or fraudulent certificate cannot stay hidden. Standardised as RFC 6962, it uses Merkle trees to let anyone verify that a certificate was logged and that the log has not been tampered with. It is the working template for the estate’s own transparency log over sealed claims.
Making misissuance visible
Before Certificate Transparency, a compromised or coerced certificate authority could issue a certificate for a domain and no one would necessarily know. CT requires certificates to be logged in public, append-only logs, so domain owners and auditors can watch for certificates they did not request, and the log’s Merkle structure makes any tampering detectable.
The pattern — a public append-only log whose integrity anyone can check — is exactly what the estate’s checkpoint and transparency formats apply to sealed claims, so a record’s presence and order can be proven to a stranger.
Related standards
Questions
Does CT stop a bad certificate being issued?
No — it makes issuance visible after the fact, so misissuance is detected quickly rather than prevented silently.
What does it have to do with agents?
It is the proven design for an auditable, append-only record — the same guarantee the estate needs for the claims agents seal.
Keep reading
By Michael Gord · published 2026-10-09 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.