A digital certificate portal for a laboratory is a secure web application where your customers retrieve sealed test reports and calibration certificates and verify their authenticity. It sits around your existing LIMS, handling delivery, role-based access, eIDAS seals, and audit trails that your LIMS does not provide. Sandorian builds it as the layer between your system of record and the people who depend on what it produces.
A lab certificate portal is a customer-facing web application that makes approved test reports, calibration certificates, and conformity certificates available to the organisations that commissioned them - with cryptographic proof that the documents are authentic and unaltered.
Here is what it does in practice:
The portal is not a replacement for your Laboratory Information Management System (LIMS). Your LIMS records results, manages chains of custody, and drives approval workflows. The portal takes approved, signed-off results and delivers them to customers with legal-grade integrity. They serve different functions, and both need to do their job well.
Most labs still ship certificates by email - a plain PDF with no tamper evidence, no audit trail, and no way for a regulator or customs broker to verify authenticity without picking up the phone. That process breaks down at scale, and it breaks down in ways that cost operations staff real time every day.
A digital certificate portal replaces:
The gap between emailing a PDF and delivering through an eIDAS-sealed portal is not marginal. The table below shows why.
| Feature | Email PDF delivery | eIDAS-sealed certificate portal |
|---|---|---|
| Tamper evidence | None | Qualified electronic seal (PAdES) |
| Third-party verification | Phone call to lab | Verification link / QR code |
| Access control | None | Role-based, per customer organisation |
| Audit trail | None | Full access and download log |
| Timestamping | None | Qualified electronic timestamp |
| LIMS integration | Manual export | API-driven, automated |
Book a discovery call to scope a certificate portal around your LIMS.
Think of the architecture in three columns.
The LIMS is the system of record. It holds results, manages approval workflows, and carries traceability back to raw measurements and instrument calibration. Nothing in the portal touches this layer except to read from it.
The certificate portal is the delivery and access layer. It authenticates customers, serves the right certificates to the right organisations, applies eIDAS seals through a qualified trust service provider (QTSP), and logs every access and download event.
The QTSP operates as the trust layer. It issues the qualified electronic seal and anchors it with a qualified electronic timestamp. The QTSP must appear on an EU member state's national trusted list under the eIDAS Regulation (EU) 910/2014 - you can check status through the EU Trusted List Browser.
The flow between layers runs in one direction: the LIMS API pushes approved results to the portal, the portal sends a seal request to the QTSP, the QTSP returns the sealed and timestamped PDF, and the portal serves that PDF to the authorised customer with a verification endpoint attached.
Most LIMS vendors do not offer customer-facing, eIDAS-compliant delivery. That gap is structural, not incidental - LIMS are built for internal laboratory workflows, not for regulated external document delivery.
The portal takes on:

The sequence from approved result to sealed certificate in the customer's hands looks like this:
Every step is logged. Every sealed PDF carries a cryptographic fingerprint that locks in the document state at the moment of sealing.
PAdES (PDF Advanced Electronic Signatures), standardised under ETSI EN 319 142, embeds the qualified electronic seal directly inside the PDF file - not as a separate sidecar file or an external reference. This matters for three concrete reasons:
For lab certificates crossing borders, appearing in regulatory submissions, or being presented to customs authorities, PAdES-embedded seals are the technically correct format for durable legal-grade integrity.
Sandorian builds the portal to connect via the LIMS API or, where the API is limited or undocumented, via a direct database interface. Both connections are read-only. The LIMS stays the system of record. The portal never writes back to it.
Only approved, signed-off results pass through. Draft results, pending approvals, and intermediate data never appear in the customer-facing layer. This is a deliberate design choice, not a limitation - it protects the integrity of the accreditation workflow.
When a LIMS does not expose a well-documented API, Sandorian scopes the integration at the discovery stage. Most laboratory systems - whether commercial or custom-built - offer at least database-level access that supports a read-only connector. We address the specific integration pattern for your LIMS in the first technical conversation.
ISO 17025:2017 requires laboratories to maintain the integrity and traceability of their results. The portal is engineered to support those requirements without touching the accreditation-critical configuration in the LIMS.
The LIMS stays the system of record. The portal never writes back to it.
The same principle applies to labs operating under ISO 15189 (medical laboratories) or in scope of the IVDR (In Vitro Diagnostic Regulation) - the non-disruptive read-only integration model holds regardless of the accreditation framework.
The eIDAS Regulation establishes the legal framework for qualified electronic seals - the legal-person equivalent of a qualified electronic signature, used when an organisation rather than an individual needs to assert the authenticity of a document.
Two eIDAS instruments matter for lab certificate delivery:
Both must be issued by a QTSP that appears on a national trusted list. The EU Trusted List Browser is the authoritative source for checking QTSP status.
For the legal effect of seals in your specific jurisdiction and use case, confirm with qualified legal counsel. Technical detail on how seals work lives on our separate page about how an eIDAS electronic seal works.
The portal must not alter approved result data - it reads and delivers. Access control must be auditable. Certificate version control must align with the document control requirements that ISO 17025:2017 places on laboratories.
Role-based access control means each customer organisation sees only its own certificates. No customer can browse another organisation's documents. Retention and deletion policies are configurable to align with GDPR data retention rules and the lab's own data governance requirements.

Adobe Acrobat and any PDF reader with PKI validation capability display the seal status natively when opening a PAdES-sealed certificate. The reader checks the embedded seal against the QTSP's public certificate and shows whether the document is authentic and unmodified. No portal login, no phone call, no manual check - the software handles it automatically.
Each certificate delivered through the portal carries a unique verification URL. A recipient - or a third party such as a customs broker, regulator, or industrial client - opens that URL and the portal confirms:
That confirmation comes back in seconds, without involving any lab staff.
Sandorian optionally generates a QR code printed on the PDF that links directly to the verification endpoint. When a broker or inspector has a paper printout of a sealed certificate, they scan the QR code and the portal confirms authenticity instantly. This is the mechanism behind the operational outcome described below.
A national customs authority required test labs to deliver sealed import certificates to customs brokers before goods could clear customs. Before the portal existed, brokers had no way to confirm certificate authenticity independently - so they called the lab. Every certificate, every shipment: a phone call.
A national customs authority required test labs to deliver sealed import certificates to customs brokers. Before the portal, brokers called the lab to confirm every certificate - dozens of calls per day. Sandorian built a digital certificate portal with embedded eIDAS seals and a public verification endpoint. Result: verification calls dropped by 98%. Brokers verify independently; the lab's operations team handles testing, not the phone.
A 98% reduction in verification calls is not an abstract metric. Let's break it down:
For labs handling high certificate volumes, or serving industries where third-party verification is a regulatory requirement, this outcome is the business case. Sandorian has delivered it once in production; the architecture that produced it is available for your lab.
When Sandorian builds a lab certificate portal, the delivery covers:
Honest scoping matters to technical buyers. Here is where the service ends:
Book a discovery call. Sandorian scopes the portal around your LIMS, your certificate types, and your compliance context. It is a technical conversation - your architecture and requirements, not a pitch deck. Most discovery calls take less than an hour and produce a concrete scope outline.
Book a discovery call to scope a certificate portal around your LIMS.
What is a digital certificate portal for a laboratory?
It is a secure web application where customers retrieve sealed test reports and calibration certificates and verify their authenticity. It sits around the LIMS and handles delivery, access control, and verification - functions most LIMS do not cover.
Can the portal work with our existing LIMS?
Yes. Sandorian builds the portal as a layer around the LIMS, pulling approved results through its API or database interfaces. The LIMS stays the system of record.
Do you provide the eIDAS seal itself?
Seals are issued through a qualified trust service provider, which we integrate rather than replace. We build the signing, timestamping, and validation workflow around the provider you choose.
Does the portal give us legal certainty under eIDAS?
We engineer to eIDAS technical requirements but do not give legal advice. Confirm legal effect for your use case with qualified counsel.
How long does it take to build and deploy a certificate portal?
Timeline depends on LIMS complexity, certificate types, and the compliance context of the lab. Sandorian scopes a realistic delivery timeline during the discovery call, after understanding your specific architecture.
Can the portal support long-term validation (LTV) so certificates remain verifiable after the seal certificate expires?
Yes. PAdES supports LTV by embedding validation data at the time of sealing. Certificates sealed through the portal retain verifiability even after the underlying QTSP certificate has expired - a practical necessity for labs whose certificates are referenced years after issue.
We build the systems that power your business. Let us know how we can help.
Book a 30-min Call