# NotaryCam Virginia article: dated corrections

Reviewed: October 2, 2026. Research and analysis: Greg Lirette / Notary Geek.

The [NotaryCam article](https://www.notarycam.com/online-notary-virginia/) displays July 15, 2026 as its publication date. The review assesses substantive body text, tables and FAQ available in the October 2 extraction, deduplicating repeated page text. Direct adversarial rechecks returned 403; first-party indexed text supplied the recheck. No complete original-page version or raw HTML hash was preserved. It also checks related product disclosures and certification materials. This note summarizes independently written findings; it is not a preserved copy of the article.

The canonical claim record is `docs/evidence-analysis/notarycam-virginia-claims-2026-10-02.json`. Its public projections are the [full audit](/notarycam-virginia-claims.html) and [JSON record](/notarycam-virginia-claims.json); a repository change alone does not establish deployment. The record contains individual classifications, source URLs, checked dates, evidence limits and contextual findings. It extends the existing Notarial Routing Model without replacing its source hierarchy.

## Broader investigation

The issue is not Virginia in isolation. This page makes Virginia commercially important by presenting its history and supposed flexibility as assurance. The same scrutiny belongs in Texas and every other commissioned state: what does the provider promise, which dated law governs, what method is actually used, and what proves it? This audit assesses the identified Virginia-page claims; it does not substitute an unexamined Texas conclusion. Correctly implemented methods would remove the need to rely on a Virginia exceptionalism narrative.

## Paid no-SSN service and the NIST trust presentation

The issue is the combined commercial assurance. The [Virginia article](https://www.notarycam.com/online-notary-virginia/) promotes a biometric alternative for international signers without U.S. SSNs, while the [purchase page](https://www.notarycam.com/notarize-now/) advertises fees for that SSN-status category. The site presents the NIST agency logo as a trust signal and separately advertises IAL2. A missing SSN creates no biometric exception in [§ 47.1-2](https://law.lis.virginia.gov/vacode/title47.1/chapter1/section47.1-2/); the actual complete statutory method still must be established. A government logo cannot supply that missing legal basis.

| Advertised category | Published amount | Evidence limit |
| --- | --- | --- |
| Real-estate signers without SSNs | $50 add-on | Described as an add-on; no completed checkout inspected. |
| Other-document signers without U.S. SSNs | $79 fee, listed with $25 per seal | Whether the fee replaces or adds to another charge, and the complete total, remain unresolved. |

PCX10 assesses this combined presentation as misleading: it invites buyers to rely on a paid route through deficient legal assurances reinforced by an agency trust symbol. It does not infer a charge based solely on nationality, an unlawful fee, a particular payment or buyer reliance, knowing intent, or an agency decision. The article itself connects the route to foreign nationals and recent immigrants; the observed fee categories are based on SSN status. Those distinctions make the commercial concern precise rather than erase it.

A separate Markdown source for a NIST letter has been prepared, requesting review of the exact logo permission, technical assurances and appropriate correction or removal. It explains the Virginia and pricing context without asking NIST to adjudicate every notarization. The two Markdown inputs are tracked for later production by the existing Linux document factory. No generation has been queued or executed, and neither letter has been sent; no response or finding is claimed.

## False rules and unsupported assurances

| Subject | Source-based correction |
| --- | --- |
| Current identity requirements | [§ 47.1-2](https://law.lis.virginia.gov/vacode/title47.1/chapter1/section47.1-2/) permits personal knowledge, a qualifying credible witness, or at least two of five specified methods. Credential analysis plus KBA is one combination. |
| No-SSN biometrics | Missing an SSN creates no statutory exception. An ordinary selfie or face-match result does not establish the specified signer-certificate method or an alternative authorized by applicable adopted guidance. |
| State platform review | [Assurance Standard § 1.1(c)](https://www.commonwealth.virginia.gov/media/governorvirginiagov/secretary-of-the-commonwealth/pdf/VAe-NotarizationStandard2013Version10.pdf) disclaims Secretary system-compliance determinations. Approval of an individual application is not platform approval. Virginia’s reviewed authorities do not establish an approved/supported-platform regime; the notary remains responsible for compliant methods and technology. |
| Traditional notary location | [§ 47.1-13(B)](https://law.lis.virginia.gov/vacode/title47.1/chapter3/section47.1-13/) permits compliant acts outside Virginia. The current electronic certificate separately requires the Virginia county or city where the notary physically was under [§ 47.1-16(A)](https://law.lis.virginia.gov/vacode/title47.1/chapter3/section47.1-16/). |
| Traditional records | [§ 47.1-14](https://law.lis.virginia.gov/vacode/title47.1/chapter3/section47.1-14/) requires records for nonelectronic acts from July 1, 2026; the record must be kept at least five years. |
| Education | The new statutory instruction/examination requirement begins [July 1, 2027](https://law.lis.virginia.gov/vacodeupdates/title47.1/section47.1-5.2/), after both the displayed publication date and this review. |
| Statutory range | The [official Chapter 2 index](https://law.lis.virginia.gov/vacode/title47.1/chapter2/) contains § 47.1-6.1 followed by § 47.1-7, not the claimed 6.1-through-6.7 range. |

Document execution, witnessing, federal I-9 verification, foreign receiving requirements, commercial acceptance and notarial authority are separate questions. The full ledger also covers wills, trusts, powers of attorney, real-estate records, fees, retention, device requirements, network capacity, current pricing and provider biometric disclosures.

## The chronology cannot be flattened

| Effective date | Change |
| --- | --- |
| July 1, 2012 | Audio-video provisions of [2011 Chapter 731](https://legacylis.virginia.gov/cgi-bin/legp604.exe?111+ful+CHAP0731+pdf=). The same act, approved March 26, 2011, removed the older Virginia-recordation-purpose wording from extraterritorial authority. |
| March 11, 2021 | Emergency [Chapter 78](https://legacylis.virginia.gov/cgi-bin/legp604.exe?212+ful+CHAP0078+pdf=): credential analysis, the two-of-four structure, adopted-guidance route and electronic certificate location wording. |
| July 1, 2024 | [Chapter 832](https://legacylis.virginia.gov/cgi-bin/legp604.exe?241+ful+CHAP0832+pdf=) expressly added KBA and made it the fifth method. Its retroactivity clause concerns § 47.1-20.1(B), not wholesale retrospective authorization of all identity practices. |
| July 1, 2026 / July 1, 2027 | Distinct records and education changes, as the [Secretary’s 2026 notice](https://www.commonwealth.virginia.gov/media/governorvirginiagov/secretary-of-the-commonwealth/pdf/notary/Notary-News-Letter-July-1-Changes-2026.pdf) explains. |

Early RON adoption is not evidence that today’s CA/KBA framework existed unchanged from the beginning. The article does not expressly date KBA to 2012; that continuity concern is labeled as reviewer inference. A provider may use KBA, fingerprints or other extra checks without proving that the law required them or that they satisfied a statutory method. For an earlier transaction, identify the actual then-current authority and retained method evidence. The [published IMSAC guidance](https://townhall.virginia.gov/l/GetFile.cfm?File=C%3A%5CTownHall%5Cdocroot%5CGuidanceDocs%5C1011%5CGDoc_IMSAC_6009_v1.pdf) and [2018 Register listing](https://register.dls.virginia.gov/vol34/iss16/v34i16.pdf) identify a possible earlier authority chain, not proved provider compliance. Adoption, supersession, applicability and the complete method still require evidence. The [2026 handbook](https://www.commonwealth.virginia.gov/media/governorvirginiagov/secretary-of-the-commonwealth/pdf/notary/Notary-Handbook_Final_7.14.2026.pdf) is also included, including summaries that require reconciliation with current statutes. The limited validation statute and its retained remedies also matter; this review does not declare all earlier acts invalid.

## MISMO, title-industry reliance and company size

NotaryCam’s MISMO listing is supported. MISMO describes applicant attestations, submitted documents and a system demonstration reviewed against its standards. Its [stated scope](https://www.mismo.org/events-education/certifications/emortgage-technology-certification/ron) excludes verification of compliance with jurisdiction-specific law. Applicant state-compliance statements are not a governmental or transaction-specific determination.

The [November 2020 NotaryCam announcement](https://www.notarycam.com/notarycam-certifies-compliance-with-mismo-ron-standards-for-real-estate-transactions/) linked certification to broad confidence in compliant remote closings. [ALTA republished that attributed assurance](https://www.alta.org/news-and-publications/news/20201124-NotaryCam-Receives-MISMO-RON-Certification). This is a concrete example of the message circulating in title-industry communications; it is not an independent ALTA adjudication of a Virginia workflow. A [contemporaneous September 2020 interview](https://newslink.mba.org/mba-newslinks/2020/september/mba-newslink-wednesday-sept-16-2020/scott-roller-mismo-ron-certification-what-you-need-to-know/) attributes the standards-versus-law distinction to MISMO’s technology vice president. The broad-reassurance criticism is an identified inference, not a claim that the announcement expressly guaranteed every act. The review did not obtain the 2020 certification agreement or a completed provider application.

A certification can be a private contractual requirement without becoming a statute or proving an individual act lawful. The practical correction is to require the actual state-law analysis and transaction evidence alongside any badge or approved-provider list. No conclusion about every title company’s practice is needed to identify this gap.

Notary Geek’s size does not diminish a correct source-backed objection, and a large provider’s size does not answer one. Greg’s criticism of selling false compliance assurances as a scam concerns the assurances sold. The published claims can be evaluated without proving intent. Calling the pattern theater does not cure it. This follows the existing [June 6 source-quality note](vendor-no-intent-safe-harbor-authority-laundering-voice-note-2026-06-06.md).

## NIST agency logo and official assurance

The [homepage](https://www.notarycam.com/) and [licensing page](https://www.notarycam.com/platform/software-licensing/) use the actual [NIST agency logo](https://www.notarycam.com/wp-content/uploads/2025/04/NIST-logo.jpg) in their TRUST footers beside SOC 2 and MISMO images. The extracted image label is NIST Compliant; clicking the image resolves to the supplied asset. Its bytes were inspected: JPEG, 637 × 284, 28,748 bytes, SHA-256 `2598c5713b953ceb26d5d8ed4c58ff7586c925b416a1b40a1d833d772b838ef1`. The image itself contains agency identity, not certification wording. Raw DOM attributes and exact placement on the Virginia article were not independently recaptured in this supplement; the URL directory does not prove first-use date.

Finding PCX05 assesses the combined commercial presentation as misleading official assurance. [Commerce DAO 201-1 § 7](https://www.commerce.gov/ogc/symbols-department-commerce) requires outside-use approval and a written license and considers apparent improper endorsement, including placement near other symbols. [USAGov](https://www.usa.gov/government-copyright) separately confirms the logo-permission and no-implied-endorsement rules. The [NIST Digital Identity Group FAQ](https://pages.nist.gov/800-63-4-Implementation-Resources/faqs/index.html) states that NIST does not operate a certification program for these guidelines.

The strongest defense is that the logo identifies the standards publisher and the label claims conformity. That does not answer the impression created by an agency logo among trust badges. No license or agency determination about this display was obtained, so unauthorized use is not established. A license covering this layout and clear, scoped independent assessment would warrant reassessing the presentation; neither would create government endorsement or prove notarial-law compliance. Actual IAL2 conformity remains unverified, not disproved. Other NIST programs have their own validation marks; this finding concerns the agency logo and Digital Identity Guidelines.

## Security claims beyond the logo

The [Why NotaryCam security FAQ](https://www.notarycam.com/why-notarycam/) uses framework-derived practices to assure readers of the strongest controls, then links encryption and external auditing/testing to continuous security. PCX06 identifies the misleading inference; PCX07 identifies unsupported outcome breadth; PCX08 preserves the underlying measures as provider claims. No breach or implementation failure was established.

The [NIST CSF 2.0 description](https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20) concerns risk-management outcomes rather than prescribed implementation. The page does not identify this particular NIST publication, so the audit does not choose it on the provider’s behalf. [AICPA’s criteria description](https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022) concerns evaluation and reporting on controls; citing SOC 2 does not supply a completed examination or its results. Request the actual baseline, system boundary, assessment scope/period and findings. Any strongest-controls comparison also needs a defined measure.

CA14 answers the marketing-shorthand and confidential-report defenses. An unpublished report is not necessarily absent, but its unknown contents cannot substantiate an unlimited assurance. A successful scoped assessment does not establish all future security. These statements can be corrected without waiting for a breach. Security evidence also does not replace a statutory identity method. The unsent letter requests appropriately shared evidence without sensitive testing details or customer records.

## When NIST logo use can be permitted

Permission depends on the purpose, image and placement. [Commerce DAO 201-1 § 7](https://www.commerce.gov/ogc/symbols-department-commerce) provides an approval/licensing route for a defined outside use that advances the agency mission without apparent improper endorsement. A concrete historical example is [NIST’s 2016 documentary funding opportunity](https://www.nist.gov/system/files/documents/public_affairs/20160707-NIST-Documentary-Film-FFO.pdf), which required agency-logo funding credit on the finished film but excluded it from derivative works. [A particular NIST image](https://www.nist.gov/image/ceramicam-feedstock-nist-logo) has explicit editorial reuse terms. [CMVP validation marks](https://csrc.nist.gov/Projects/cryptographic-module-validation-program/use-of-fips-140-2-logo-and-phrases) have separate eligibility and certificate-identification rules and disclaim endorsement; they are not the generic agency logo.

These examples answer how permission could exist. They do not establish permission for NotaryCam’s exact TRUST display. Following publications, using a validated cryptographic component or holding an independent assessment does not itself grant agency-logo authorization. Request the actual terms covering this image, purpose, layout and period. The audit does not turn an administrative usage policy into a categorical ruling against every possible editorial depiction.

## KBA and the claimed NIST identity assurance

[Current SP 800-63A-4 § 2.5.1](https://pages.nist.gov/800-63-4/sp800-63a.html) expressly prohibits KBA and KBV for identity verification. This is stronger than a recommendation against them. Its § 3.2.1 separately permits KBV within fraud management. [Revision 3’s FAQ, Q-A4](https://pages.nist.gov/800-63-FAQ/) already explained that KBV could not satisfy IAL2/IAL3 verification requirements, despite limited supplementary use; [Revision 3 § 9.3](https://pages.nist.gov/800-63-3/sp800-63a.html) also advised avoiding KBV for usability. The revisions must not be collapsed into a claim that every historical use was prohibited.

Finding PCX09 requires NotaryCam to reconcile its KBA descriptions with its separate IAL2 claim: identify the revision, baseline verification method or documented deviation and compensating controls, and role of KBA. Current [tailoring rules](https://pages.nist.gov/800-63-4/sp800-63.html) recognize compensating controls but require documented rationale, comparability, residual risk and disclosure to relying parties for their acceptance decision, including a Digital Identity Acceptance Statement. Those are evidence requirements, not an assumed defense. A separate fraud check could coexist with an otherwise qualifying process; the provider must show that process rather than have a reviewer invent it.

State-law KBA requirements or permissions do not make KBA NIST-approved. Conversely, a NIST prohibition for a particular technical function does not determine a notarization’s legal validity. A generic derived-from-NIST statement is narrower than conformity to the identity guidelines; the separately advertised IAL2 claim is why this specific identity standard must be addressed. CA15 and IR15 preserve these distinctions without diluting the baseline prohibition.

## Evidence and publication boundaries

The ledger distinguishes false, misleading, incomplete, unsupported, conflicting, provider-asserted and supported propositions. Lack of corroboration is not automatically falsity. Current privacy disclosures describe document verification and face comparison, but do not identify a Virginia notary, complete lawful method or particular session. NotaryCam’s licensing page names NIST IAL2; the audit corrected its earlier omission of that fact. The assessed version, workflow and scope remain unverified, as does the private SOC 2 report. On-camera KBA is an untested provider claim, not an observed failure.

The adversarial pass also corrected overstatements in our draft: the onboarding body includes a commission-cycle qualification; pre-session credential analysis and stop-on-failure rules may be provider policies; and deed/loan/POA examples already include conditions. The ledger preserves those qualifications. Its 83 review entries include 67 article entries and 16 supplemental findings, supported propositions and overlapping checks—not 83 unique errors. Fifteen objections and responses, with evidence that would change each assessment, appear in both public projections.

Some primary pages were reviewed through indexed content where direct access returned 403; each source records this. No customer transaction, confidential assurance report or private biometric data was inspected. The retained LinkedIn correspondence remains a separate repository research source and is not republished here. The article’s authorship process was not established. The provider correction request and NIST review request are Markdown source inputs for backlogged document production; no generated document, sending, response, admission, deployment or outcome is claimed.


## What the evidence limits do not change

The six false-law findings remain source-backed contradictions. No session inspection limits conclusions about an individual act; it does not reduce those contradictions to unclear wording. A hypothetical earlier route is not evidence that the provider used an authorized method. Validation of an act does not prove the original duty was met. Performing KBA, fingerprints or another check proves neither that the law required it nor that the complete statutory method was satisfied.

MISMO’s real review does not rebut a specific legal error. The corrected IAL2 fact is that NotaryCam names the level, not that this audit verified conformity. An unexamined private report supports neither a negative assessment nor an assumption of favorable compliance. ALTA’s publication and company size add no independent statutory authority. Unknown intent establishes neither knowing deception nor good faith and does not bar correcting a false assurance.

The canonical record and human audit include fifteen interpretation rules that keep each limitation attached to the proposition it actually limits. Accurate qualifications, supported examples and corrections to our own draft do not cancel unrelated false findings. Capture limits remain open; contrary evidence should be assessed for the particular claim it answers.

## Correspondence factory handoff

The [Markdown source packet and production backlog](../letters/notarycam-correspondence-factory-backlog-20261002.md) maps the two letter inputs to BootStrapCritical issues [#1728](https://github.com/glirette/BootStrapCritical/issues/1728) and [#1729](https://github.com/glirette/BootStrapCritical/issues/1729). The existing Linux document factory owns document production. This change prepares source and backlog records only.
