Function guide
The certification engine — turn a consent event into tamper-evident, independently-verifiable proof.
Libretto is the certification engine at the core of LeadOpera. You don’t buy “Libretto” directly — it’s branded and sold as two products on the same engine:
| Product | Certifies | For |
|---|---|---|
| LeadProof | Lead consent — web-form and phone-call leads | Lead generators & buyers proving TCPA-style consent |
| TermsProof | Agreements & e-signatures (ESIGN/UETA) | Anyone sealing a signed agreement as evidence |
Both mint the same thing: a certificate — a cryptographically sealed record of a consent or acceptance event that anyone can verify independently, without trusting you or us. That certificate is the evidence layer the rest of the OS builds on (a lead’s cert tier is what buyers price and screen against in Nota and Galleria).
A certificate is a tamper-evident technical record — not a determination of legal or regulatory compliance, and not legal advice. Capturing and Verify are free; you only pay for the actions you choose to run (see Pricing).
The consent markup and text, the page URL and timestamp, the archived disclosure documents the consent linked to, the trust/fraud signals, and an integrity hash that binds it all together. Change any sealed field later and the hash no longer reproduces — that’s what makes tampering detectable.
The integrity hash is a SHA-256 digest over the consent content plus the content hash of every linked disclosure — so tampering with even a referenced document is detectable from the certificate alone. That hash is sent to an independent RFC-3161 timestamp authority (DigiCert, with Sectigo fallback), which returns a signed token binding the hash to a third-party-asserted time; Libretto also cryptographically verifies that token.
Disclosures are the documents your consent links to (Terms, Privacy Policy, SMS policy). Libretto independently re-fetches and hashes each one, then follows the links inside them, archiving a bounded chain (up to 3 fetched layers, same-site, citation-only outer layer). Consent often depends on documents that aren’t on the consent page itself, so the whole chain is preserved.
A 0–100 score of how human and legitimate a submission looked — from the bot challenge, time-to-fill, pointer movement, keyboard interaction, and IP fraud risk — mapped to a tier: Certified (85+), Verified (70+), Standard (55+), or Flagged. A failed bot challenge caps the score low regardless of the rest. The tier gates eligibility and weights bids in the marketplace auction.
Yes — they’re independent scripts and coexist on the same page. When a TrustedForm (xxTrustedFormCertUrl) or Jornaya (universal_leadid) token is present, Libretto captures it and seals it into the certificate as supplementary evidence. The difference: a Libretto certificate is independent and portable — it verifies on its own, offline, with no vendor lookup — so it can stand alone or sit alongside the tools you already run. Coexistence, never dependence.
Confirms a certificate’s seal is genuine and untampered. The public tool at /verify requires both the certificate ID and its hash, so only someone with those details can look it up.
Confirms whether a given phone or email matches a certificate, by comparing hashed identifiers — no personal data revealed. Works before you claim, so a prospective buyer can confirm a match and see trust signals before paying. Charged only when there’s data on file to compare.
Locks a certificate to your account, sets retention (5 or 7 years), and unlocks the full record plus Confirm, Drift, and evidence exports. Claiming is what gates access to the underlying content.
Runs AI compliance checks against the sealed consent — a preset checklist (autodialer disclosure, clear-and-conspicuous consent, …) and/or a custom question. It reasons over the raw captured markup, so structural facts like checkbox ordering are preserved. Each check returns a Yes / No / Unclear verdict with an explanation.
Re-fetches the consent page and its archived disclosures and compares them to what was sealed. Unchanged documents are confirmed by hash alone (no AI); changed ones — and the consent page always — get an AI materiality read that ignores cosmetic differences.
The evidence package is a court-ready sealed PDF bundling the certificate, disclosures, and your verification/compliance history under a compound hash. Attestation adds an Ed25519 digital signature and a dated, first-person re-verification statement; attestations are human-reviewed before release and refunded if not approved.
5 years covers the FTC TSR recordkeeping baseline; 7 years is the longer option for stricter internal or state requirements. You choose at claim time.
There is a 90-day claim window. A certificate not claimed within 90 days of capture is archived out of your active list, and after that window it can no longer be Checked or Claimed — the sealed record is retained, but access closes. Claim the ones you’ll rely on before the deadline (or use Auto-Claim). Already-claimed certificates keep their full 5- or 7-year retention.
A rule that automatically claims certificates captured on a given domain, at capture time, with the retention you set — so leads you generate are locked in without a manual step.
A saved compliance rule that fires automatically, once, the moment a matching certificate is claimed. It applies prospectively and never blocks a claim — if you’re short on credits, that one analysis is simply skipped and the rule stays active.
Automatically buys more credits when your balance drops below a threshold you set (requires a card on file) — keeps automations running without manual top-ups.
In Setup, add and verify your domain (a DNS TXT record), then install the capture script with your widget token. One script covers standard forms, custom/AJAX/multi-step funnels, and co-registration (multi-partner, one cert per partner) — see Capturing web forms. The widget token is public and only mints certificates; your API key is secret and spends credits — never mix them.
Everything runs on prepaid credits. See Pricing for rates and the Credits & billing page for your balance and transaction journal.
Yes — invite them from Team; they sign in with the invited email (no password required, though they can set one). Permissions are per capability: Setup, Check, Claim, Confirm/Drift/Automations, Evidence, Billing, API access, Support.
Open a ticket from the Support tab — our team replies right there, and you get an email when we do.
Next: put certified leads to work in Nota, or wire capture programmatically via the API reference.
More: Pricing · API reference · Getting started. Sign in to use these functions in the portal.
LeadOpera™ is a trademark of LeadOpera LLC, a Colorado limited liability company. Its products and services — including LeadProof™ and TermsProof™ — are proprietary and operated through their independent websites; LeadProof™ and TermsProof™ are trademarks of LeadOpera LLC. Unauthorized use of these marks is strictly prohibited. The certification method used by LeadOpera’s products is patent pending. A certificate is a tamper-evident technical record — not a determination of legal or regulatory compliance, validity, or enforceability, and not legal advice.
TrustedForm, Jornaya, Boberdoo, Phonexa, LeadsPedia, Google, Meta, Facebook, Instagram, Twilio, DigiCert, and Sectigo are trademarks of their respective owners; their mention describes interoperability only and does not imply any affiliation with, endorsement by, or sponsorship from those companies.
Press, partnership, and general inquiries: inquiry@leadopera.com
© 2026 LeadOpera LLC. All rights reserved.