A family asks for proof of what their kid finished. You hand them a certificate nobody can check.
A camper spends three weeks on a sailing certification, a season of a robotics build, or a coding intensive, and in September the family needs to show it for a scholarship form, a homeschool filing, or a college application asking what the student did outside a regular classroom. You open a template, type the program name and the dates, sign it, and export a certificate. The family attaches it. The office that reads it has no way to check it beyond calling the camp, and the same fact gets typed again into the next form next season. This page walks through the other way: you declare the course once, the instructor who ran it co-signs from a link, the family claims the record and holds it, and any receiver checks it at one public link with no account.
Checked against the live Records tab, the witness page, and the verify page. Requirements on this page last reviewed September 21, 2026. The product as it runs today is always the source of truth.
Why the certificate is the problem
The certificate cannot be checked. A reader who wants to know whether it is real has to find the camp’s phone number and call, and a scholarship committee reading two hundred applications does not call two hundred camps. It sets the file aside.
The certificate has no witness beyond the camp’s own signature. The instructor who watched the camper pass the swim test or finish the robot build never puts a name on anything the family keeps.
And the certificate lives in your files, in a format only your office can reprint. If the family asks again next year, or a different receiver wants the same proof in a different shape, someone opens the template and types it again.
The rail, in four moves
1. Declare
You create an organization account, open the Records tab, read the founding terms and tick the box. Then you import your roster: one camper per line as name, family email, and grade or age group, or a paste of your registration export. You can email every family a claim link in the same step.
Now you declare the course, meaning the program, the session, or the certification the camper completed. Describe it once, with a title, the term or session dates, and the outcome in the word your camp already uses on a certificate (Completed, Pass, a level such as Advanced), and pick the campers who earned it. Every one of them gets a signed course row. On the public verify page that row reads “Declared by” followed by your camp’s name, never as the family’s own claim.
2. Co-sign
Add the instructor’s email when you declare the course. The instructor gets one link that opens to exactly what they are being asked to sign, writes what they saw in their own words, and signs. No login, no account, no document to upload. A signature says the instructor was there and this is what they saw. It does not certify anything on its own, and the instructor is asked once and never chased, though declaring the same course again with the same instructor address sends the email again.
Next to each signature the verify page says how far the signer’s identity was checked, as a plain fact: an email address only; a school or organization address (automatic when the invited address is at a .edu, .gov, k12, or similar institutional domain) or a professional license that Eformogi staff looked up; an identity document checked by staff; or a history of earlier signatures. An instructor invited at a personal address, or at your camp’s own .org or .com address, reads as an email address only. That is the honest default, and it is still a named person who signed.
3. Verify
Every course row, and the Witness Transcript™ the family issues from it, has a public link of the form eformogi.com/verify/ followed by the receipt id. A scholarship office, an admissions reader, or an employer opens it with no account and sees what was issued, when, by whom, who co-signed, and the hash that proves the bytes have not changed since they were sealed. A reader who does not want to trust our page can download the proof file and run the published verifier with no Eformogi server in the loop. We wrote a page for that reader: reading a Witness Transcript.
4. The family holds it
The claim link you sent binds the record to the family. They hold it on their own device and in an encrypted cloud copy, and your rows fold into the transcript they issue. They can add to it, export it, share it, and revoke a share. You are the issuer and they are the holder, and that does not change once the season ends or the family moves on to a different camp next summer. Once a family has claimed a camper, you can archive that camper on your side, but you cannot delete their record.
A sample you can open
Both samples are fictional demos, and the mechanism does not change by issuer type: a camp’s declared row looks the same as the one below, with your camp’s name where this one says a school’s. Open one declared course from Sample Microschool (Demo) for a learner named Avery Sample, and the sample family transcript that shows what the whole record looks like to a receiver.
What it costs
The record is free for the learner, forever: capturing, witnessing, issuing, exporting, and verifying never cost the family anything. Schools, microschools, and counselors who issue on the record get a free founding year through June 30, 2027, then pay $49 per learner per year, billed to the issuer and never to the family; founding issuers keep that price for as long as they issue, and if an issuer stops paying, its learners keep the record and its export. Receivers verify a single link free, forever; an office that wants a hosted verification service at volume can ask us. In New York, each student's first IHIP of the season is free, rendered from the record the family already entered. Families who want the rest of the season's filed paperwork, the four quarterly reports and the annual assessment, and every other state document rendered and filed can add Family Pro for $99 per year, which is included for every learner an issuer enrolls; the enrollment and service-hours letters cost $12 each, the good-student letter is free while insurers are new to family-issued records, and the record itself is never behind any of it.
The whole price list is on the pricing page, and the terms are on the founding terms page.
What this does not do
- It does not certify your camp. A signed record says who ran what and who witnessed it. It does not make your camp accredited or official, and no page of ours will describe it that way.
- It does not decide for a receiver. Whether a record satisfies a scholarship form, an application question, or a state filing is that receiver’s decision. Where it matters we quote the receiver’s own published policy, and we never speak for it.
- It does not compare campers. A record is a sum of what happened. There is no comparison of one camper to another anywhere on the learner’s surface.
Frequently asked questions
Our camp does not grade campers. What goes in the grade field?
Whatever word your camp already puts on a certificate. The rail asks for one short field per course, the same field a school would put a letter grade in, and it takes free text: Completed, Pass, or a level such as Advanced. The instructor who co-signs can write a fuller statement in their own words alongside it. Nothing about the record requires a letter grade or a number.
Does the family need an account to claim the record?
Yes. The claim link you email from the roster step binds the camper to the family's own sign in, and from then on the family holds the record on their own device and in an encrypted cloud copy. You keep issuing into it; they keep holding it. If they have not claimed it yet, your declared rows still exist and still verify. A claim link is good for thirty days, and you can send a fresh one from the Records tab at any time.
What happens if an instructor never signs?
The row stands as declared by your camp, with no co-signature, and the verify page says exactly that. The instructor is asked once by email and is not reminded, because a witness page never pressures anyone to sign; declaring the same course again with the same instructor address does send the email again. A row with a named instructor's signature carries more for a reader than a row without one, and the reader can see which is which.
Can I correct or remove a row after the season ends?
There is no withdraw action in the Records tab today. A declared row is content addressed, so the fix for a wrong row is to declare the corrected course, which creates a new row, and to tell the family. Once a family has claimed a camper, you can archive the camper on your side, but you cannot delete their record.
How long does the first hour take, for a seasonal staff?
About an hour to set up before the season, and a few minutes per course per session after that, which fits a program that runs for a few weeks and hands its records off at closing. Creating the organization account is a one tap sign in link and two fields. Enrolling is reading the terms and ticking a box. Importing the roster is a paste. Declaring the first course and inviting its instructor is one form. The three steps are written out on the start page.
The camp is the witness, not the owner
A season ends, staff turn over, and a camp that keeps every family’s proof in its own files is a fragile place to leave a record. The conviction underneath this rail is plain: a record of what a camper did belongs to the learner, and the camp that ran the program is its witness and its issuer, never its owner. When the learner holds the record and takes it with them, nothing is lost except a filing cabinet at the end of a season. The format is published at eformogi.com/spec so that this stays true whether or not we are in the room, and the promises behind it are written down in the sovereignty contract.
See also: how a microschool issues a transcript · the founding issuer offer · what a receiver sees