- They are not two companies any more. On January 8, 2026 Verisk announced the sale of Verisk Marketing Solutions, the business that carried Jornaya, to ActiveProspect, which already owned TrustedForm (Verisk newsroom).
- The real difference is timing. A Jornaya LeadiD token is generated when the form loads; a TrustedForm certificate is issued at the moment the consumer submits (Lead Prosper).
- Only ActiveProspect publishes a per-unit price; Jornaya sells on negotiated annual contracts. That gap is about how each vendor sells, not which token you need. The full numbers live on our TrustedForm and Jornaya pricing breakdown.
- Your buyers pick the token, not the feature list. Read the lead spec you have already signed and find the clause that names the certificate; a named requirement ends the discussion.
- A certificate or token proves the consent event happened. It does not prove the lead is any good, which is a separate check on the traffic behind the form.
Quick answers:
- Who owns TrustedForm and Jornaya now?
- What does each certificate actually record?
- Do I need both TrustedForm and Jornaya?
- Which consent token does my lead buyer require?
- Does a certificate or token mean a lead is good?
- What is a Jornaya lead ID?
- How do you check a Jornaya lead ID?
Most comparisons of these two tools are still written as if you are choosing between two companies. You are not. That stopped being true at the start of 2026, and almost nothing on the first page of Google has caught up.
The Two Certificates Have Had the Same Owner Since January 2026
On January 8, 2026, Verisk announced it had sold Verisk Marketing Solutions to ActiveProspect (Verisk newsroom). Verisk Marketing Solutions was the business that carried Jornaya, which Verisk had bought and folded in years earlier. ActiveProspect already owned TrustedForm. The sale was covered in the financial press at the time (MarketWatch). ActiveProspect rebranded the acquired data unit as InfutorData on April 21, 2026.
So the two names most operators treat as competitors now sit inside one company.
Nothing about the products changed on that date. The tags still fire the same way, the integrations still run, and no consolidation of the two certificates has been announced. What changed is the shape of the negotiation. Buying both used to mean two suppliers, two contracts and two renewal conversations, which gave you a second vendor to price the first one against. Now both line items land on one supplier’s invoice.
That cuts both ways. One relationship is simpler to manage, and your combined spend counts toward a single commitment threshold instead of being split across two. It also means you have no second supplier to quote against at renewal. Your entire consent record now depends on one company staying in business and staying interested in both product lines.
One Token Fires When the Form Loads, the Other When It Is Submitted
The real difference is timing, and it has a practical consequence.
A Jornaya LeadiD token is generated when the form loads. A TrustedForm certificate is issued at the moment the consumer submits (Lead Prosper documentation). A token can therefore exist for a form that was never completed, while a certificate exists only where somebody actually submitted. If you are reconciling counts between your form platform and your buyer, that difference explains a gap before you go looking for a bug.
You will see capability scorecards that rate these two out of ten across half a dozen categories. I would not build a buying decision on them. The published scorecards disagree with each other and with the platform documentation on which tool does behavioral filtering and duplicate detection, and none of them show their working. Below is the comparison limited to what the vendor and independent platform documentation actually state.
| TrustedForm | Jornaya LeadiD | |
|---|---|---|
| Owner since January 8, 2026 | ActiveProspect (Verisk) | ActiveProspect (Verisk) |
| When the record is created | At form submission (Lead Prosper) | At form load (Lead Prosper) |
| What it captures | Session-level data including timestamp, browser, IP address and URL (Lead Prosper) | A unique token recording that the lead event occurred, with an auditable history (Lead Prosper) |
| Published per-unit rate | Yes, per unit (see our pricing breakdown) | None published |
| How it is bought | Self-serve pay as you go, or a contract (ActiveProspect) | Negotiated annual contract (Vendr) |
| Retention of the stored record | Up to five years on Retain (ActiveProspect) | Not published |
The row that decides most stacks is how you buy it. You can start using one of them this afternoon with a card. The other needs a procurement conversation.
How to Check a Jornaya Token Somebody Just Sent You
Knowing which token fires when is one thing. Deciding whether the one sitting in tonight’s lead payload is real is another, and that is where most buyers stop.
Start with what the fields are actually called. Lead Prosper’s integration guidance is blunt about it: add hidden fields named trustedform_cert_url and jornaya_leadid to your form. Those are the two field names to write into your post spec. Not “consent proof”, not “certificate”. Name the fields, or you will spend a month arguing about what a seller meant by proof.
What arrives in jornaya_leadid is a UUID. On its own it proves almost nothing, and the reason is the firing rule from the section above. The same Lead Prosper doc states that Jornaya “generates a unique LeadiD token when a form is loaded.” Loaded, not submitted. So a token can exist for a form view that never became a submission, and a token in your payload tells you a script ran on a page. It does not tell you a person agreed to anything.
The check costs you an account, not a lookup
To turn the UUID into evidence you query Jornaya’s authentication service. Here is the part nobody puts in the sales deck: you query it with your own Jornaya credentials. Phonexa’s iClear Jornaya authentication setup spells out the input it needs from you, “your Jornaya Account Code (LAC): Fill in the Lead Account Code, the unique identifier for your Jornaya Account.”
Read that as a buying fact. The token is free to receive and it is not free to check. The seller hands you a UUID at no cost, and the relationship that makes the UUID mean something is one you have to open and pay for yourself. A lead spec that demands a Jornaya token and budgets nothing for authentication has bought a field, not a control.
Once you have the account, the setting that does the work is a rejection rule rather than a report. The same iClear page exposes it as a yes or no: “Reject if lead not found or not Authentic: Select ‘Yes’ to filter out the leads whose Lead ID token was not confirmed to be valid.” Set it to yes before you scale spend, not after a bad month. A check that only writes to a log is a check you will read once.
The two tokens are not equally checkable
| Field in the payload | When it is created | What holding it proves by itself | What turns it into evidence |
|---|---|---|---|
jornaya_leadid | When the form loads (Lead Prosper) | That a Jornaya script ran on a form somebody opened | An authenticated query billed to your own Jornaya account |
trustedform_cert_url | When the form is submitted (Lead Prosper) | That a certificate exists at that address | Retrieving the certificate at that address |
That asymmetry is the practical difference at 3am when a lead goes bad. One field is an address you can go and open. The other is an opaque string that means nothing until a paid service tells you what it means. Neither is better. They fail differently, and your dispute process has to know which kind of failure it is looking at.
Three lines for your next post spec. Name both fields explicitly. Turn authentication on with reject-on-not-authentic before you buy volume, the same way you would verify a lead before you bid on it rather than after. And budget for your own Jornaya account, because the query bills you and not the seller.
None of this replaces knowing where the lead came from. A token proves a form event happened. It says nothing about whether the traffic in front of that form was real, which is a separate and usually bigger problem covered in our note on verifying leads at the source, and it says nothing about how many other buyers received the same record, which is the exclusive versus shared question.
What It Costs Is a Separate Question
Only ActiveProspect publishes a per-unit rate for the TrustedForm line. Jornaya publishes nothing and sells on negotiated annual contracts, which tells you how each company expects to be bought rather than which token you need. For the current rate card, the account tiers and the volume at which you should stop paying list price, see our breakdown of what TrustedForm and Jornaya pricing costs a buyer.
Which Certificate You Actually Need
There is no honest winner here, because the answer is set by your buyers rather than by the feature list.
Start with the contract. If you sell leads, read the lead spec you have already signed and find the clause that names the certificate. Some buyers name one explicitly. Claim Supply, for example, requires TrustedForm on every lead it routes (Claim Supply). A named requirement ends the discussion, and no capability argument outranks it.
From there, three profiles cover most operators.
| How you source and sell | The token that matters | Why |
|---|---|---|
| You generate leads on your own forms and sell them on | Certify | Issuing certificates is free, so it costs nothing and makes your leads easier to sell. Take the token your largest buyer names, and do not pay to store certificates your buyers already keep. |
| You buy leads from other people | Verify, and Retain if you hold the evidence yourself | You are checking a record somebody else created, so verification is the job. Retain matters when you cannot trust the seller to keep the proof. |
| You ping several buyer networks with one lead | Usually both, set by the widest buyer list | Different downstream buyers name different tokens, and you cannot create a token for a lead you have already sold. If you run ping post distribution, the widest buyer list sets the requirement. |
What has changed is the last step. Once you have decided you need both, you are no longer assembling a stack from two vendors. You are buying two products from one supplier. Quote, negotiate and renew them as one relationship, not two. If you are working out where verification sits in the buying process more broadly, we covered that in verifying the lead before you bid.
Certificates prove the event happened and that the disclosure was on the page. They do not tell you the lead is any good. That is a separate job, and confusing the two is how operators end up with a fully documented pile of leads nobody wants to work.
Frequently Asked Questions
Who owns TrustedForm and Jornaya now?
ActiveProspect owns both. It acquired Verisk Marketing Solutions, the business that carried Jornaya, in a sale Verisk announced on January 8, 2026, and it rebranded the acquired data unit as InfutorData that April. TrustedForm was already an ActiveProspect product. Comparisons that describe the two as competing vendors are describing the market as it was before 2026.
What does each certificate actually record?
The certificate records the session. The token records the event. A LeadiD token is generated when the form loads, and a TrustedForm certificate is issued when the consumer submits. The certificate carries session-level data such as timestamp, browser, IP address and URL. In practice a token can exist for an abandoned form, while a certificate only exists where somebody completed one.
Do I need both TrustedForm and Jornaya?
Only if your buyers require both. The deciding document is your lead spec, not a feature comparison. Operators who ping several buyer networks with the same lead are the group most likely to genuinely need both. You cannot go back and create a token for a lead you have already sold.
Which consent token does my lead buyer require?
The one your buyer names in the lead spec you signed, not the one with the better feature list. Some buyers name a token explicitly. The lead marketplace Claim Supply requires a TrustedForm certificate on every lead it routes. A named requirement ends the discussion, and no capability argument outranks it. Price does not decide it either, because the deciding document is the contract rather than a rate card.
Does a TrustedForm certificate or Jornaya token mean a lead is good?
No. A certificate proves the consent event happened and that the disclosure was on the page, and a token proves a form event occurred. Neither tells you the traffic in front of the form was real or that the person will convert. Lead quality is a separate job, which is why we verify a lead before we bid on it and screen the source for ad fraud. Treat consent proof and lead quality as two different questions.
What is a Jornaya lead ID?
It is a unique token, a UUID, that Jornaya’s script issues for a form event and passes along with the lead in a hidden field named jornaya_leadid. Lead Prosper’s integration guidance states that Jornaya generates the token when a form is loaded, which is earlier than the moment a TrustedForm certificate is issued. Practically that means the token identifies a form interaction. It is a pointer to a record Jornaya holds, not the record itself, and it carries no readable content on its own.
How do you check a Jornaya lead ID?
You query Jornaya’s authentication service with your own Jornaya credentials. Phonexa’s iClear setup page shows what the query needs from the buyer, a Jornaya Account Code, described as the unique identifier for your Jornaya account. The same page exposes the setting that matters, a reject rule that filters out leads whose token was not confirmed valid. So checking a token is not a free lookup you run on a URL. It requires a Jornaya relationship you open and pay for, which is the cost most lead specs forget to budget.
Your Two Invoices Are Now One Negotiation
Which one is better stopped being the interesting question. Both invoices now go to the same company, and almost nobody has repriced that.
Pull your last twelve months of certificate spend across both products and look at it as one number rather than two. That number is your negotiating position, and it decides whether you belong on published rates or a contract. It is also the honest measure of how much of your consent record now sits with one supplier. If losing that supplier would hurt, you want to know that now, not at renewal.
If you want a second read on how your verification stack is priced and where it sits in your buying process, talk to us.





