Technical trust
Trust and verifiability
Understand the technical evidence Provenia preserves, how it can be checked, and the limits of what those checks establish.
Provenance, chronology, and traceability
Projects organize records into a documented chronology. Each record combines declared context, technical metadata, relationships to earlier milestones, and a SHA-256 fingerprint of the referenced file.
The resulting Dossier presents this material as a readable PDF and structured JSON package for independent examination.
Cryptographic integrity
SHA-256, standardized in NIST FIPS 180-4, provides a deterministic fingerprint for comparing file contents. Provenia signs the structured Dossier data using Ed25519 as specified by RFC 8032.
Public signing keys and fingerprints are published so the signature can be checked independently, including against historical keys.
External timestamp evidence
RFC 3161 timestamp evidence supplies an independently verifiable indication that a specific hash existed no later than the timestamp represented by the token. It does not independently establish who created the underlying work.
Certificate-based PDF signature
The PDF Dossier is digitally signed using a certificate issued within Brazil's ICP-Brasil public key infrastructure. This adds an independently verifiable certificate-based integrity and signer-identification layer.
This technical mechanism does not by itself establish authorship of the underlying creative work or guarantee a particular legal effect or evidentiary treatment in any jurisdiction.
How to verify a Dossier
- Upload the exported ZIP package to the browser-based verifier.
- Review package structure, hashes, signatures, timestamp evidence, and documentary-chain checks.
- Optionally compare referenced original files locally; their contents remain on your device.
- Compare the signing key identifier and fingerprint with the permanent public-key registry.
Open the Dossier verifier or consult the public signing-key registry.
Technical and epistemic limits
Successful verification supports conclusions about package integrity, internal consistency, signature validity, and the evidence represented by the included artifacts. It does not automatically prove originality, ownership, creative authorship, truth of every declared statement, or legal admissibility.
Jurisdiction-specific legal interpretation and institutional disclosures are intentionally outside this technical explanation.