Security & trust

Evidence infrastructure should assume things can go wrong

Attestarium is designed so compromise of one layer does not silently rewrite history. Security states are explicit, sensitive data is minimised and stronger trust services remain independently identifiable.

01

Confidential by default

No public search by person, email, filename, description, date or arbitrary file hash.

Anti-probing
02

Strong account security

Password plus TOTP is required before permanent sealing. Sessions are server-side and revocable.

Step-up authentication
03

Immutable canonical store

Canonical manifests and seals are written outside the public web root and checked after write.

Tamper evidence
04

Portable verification

A DDEP package can carry the evidence manifest, signature key and trust material beyond the current domain.

No domain lock-in
05

Role separation

Provider administrators can manage the service but the design does not give them an “edit sealed evidence” function.

Operational controls
06

Supplier abstraction

Qualified timestamps, identity, payment, anchoring and storage are designed behind adapters.

Avoid supplier lock-in
Trust layers

One status should never hide five different facts

Attestarium presents platform seal time, Merkle batch state, independent anchor state, qualified timestamp state and identity assurance separately. That makes failure visible instead of pretending every green badge means the same thing.

Platform sealSigned evidence commitment
Merkle inclusionShared chronology structure
Independent anchorExternal chronology reference
Qualified timestampQTSP trust material

Current build status

The development build already implements browser hashing, TOTP-protected sealing, canonical evidence, Ed25519 platform signatures, adaptive Merkle batching and portable package verification. Independent production anchoring, qualified timestamps, identity verification, payment processing and Vault storage are separate integrations and are not falsely presented as active until configured.

Issuer identity

Attestarium issuer root fingerprint

Portable packages carry the issuer root key and an operational signing-key certificate. Compare this fingerprint through a trusted Attestarium channel when verifying outside this installation.

58c71a868ec66041a992ab0f388aa8ec71c67c295bcb9a12ba83f747b3b00823

urn:attestarium:issuer:edf4398b-0dbc-42d4-af7b-f42a9c82d244