I don't think StartCom / StartSSL is worthy of your trust. My reasoning:
For validation they require a scanned passport and drivers license. Information like this is very sensitive as it can easily be used for identity theft, for instance to acquire a loan in your name.
As a principle, I watermark these documents with the name of the company I supplied them to. They are still perfectly legible but this way, they can no longer be used for identity theft.
Startcom is unwilling to process these watermarked documents because they 'could be forged' (not because they were unreadable or anything like that). Imagine that. Any digital image I send 'could be forged', of course. Adding or not adding a watermark changes little on that account.
And where is the business case on their end? Why do they need (or even want) documents that can be used for Identity Theft? And why won't they process documents that are clearly suited for their purpose of identification?
The only reasons I can think of is that they are either very naive in their security thinking or worse, that they have plans for your documents where the watermark would get in the way. Makes me wonder...
Also please take note that they have been hacked in the past (and admitted to that) so why trust them with you identity in this way?
http://www.theregister.co.uk/2011/06/21/startssl_security_breach/
Bas