Here is a question worth asking any evidence tool, including ours: if your company disappeared tomorrow, what would happen to my proof?

For most tools the honest answer is: it dies with us. The record lives in their database, the verification runs on their servers, the certificate is their word in PDF form. That architecture has a name — a trust dependency — and opposing counsel will find it: "So this record says whatever the vendor's system says. What if their system is wrong, or their staff modified it?"

The answer to that objection cannot be a promise. It has to be architecture.

What an external proof is

An external proof takes the fingerprint of a sealed record and registers it with parties that have nothing to do with the vendor or the dispute:

Timestamp authorities (RFC 3161). Institutions whose business is signing statements of the form "this fingerprint existed at this time." The format is standardized, decades old, and familiar to courts and auditors. Verification uses the authority's public certificate — not the evidence vendor's goodwill.

Public append-only networks. Networks that no single party controls, where an entry, once included, is prohibitively expensive for anyone to rewrite. The fingerprint is registered as a permanent public fact. Only the fingerprint: it reveals nothing about the content, so privacy survives publication.

Different mechanisms, same property: the reference exists outside the system that produced the evidence. The vendor cannot backdate it, cannot alter it, and — the part that matters — cannot take it down, even by going out of business.

Why more than one

A single reference has a single point of failure: one authority's certificate practice, one network's fate. Registering the same fingerprint with multiple independent references — different institutions, different mechanisms, different jurisdictions — means the proof survives any one of them failing. Corroboration is cheap at capture time and impossible to retrofit later.

What this proves, precisely

An external proof establishes one thing with great force: the fingerprint existed no later than the anchored moment. Combined with the properties of hashing, that means the exact content existed by then, unchanged since.

It does not prove the content was true, and it does not replace the capture environment or custody chain — it corroborates them from the outside. Each layer does one job; the layers together are what make the record hard to argue with.

The uncomfortable standard

Any vendor can certify its own records. The question that separates evidence infrastructure from evidence theater is whether the record can be verified against the vendor — by a skeptic, with public tools, years later, with the company gone.

That standard is uncomfortable precisely because it removes the vendor from the trust equation. Which is the point: the strongest thing an evidence company can say is that, once sealed and anchored, your proof no longer needs us.