Platform · External proofs

Proof that doesn't depend on Provena.

When a session is sealed, its material hashes are registered with independent external providers — creating proof of existence that stands on its own, even without trusting Provena. Only hashes ever leave the platform; the evidence content never does.

Anchor targets

Two values carry the whole record.

Provena anchors exactly two things — and each one fixes an entire layer of the session.

Anchor target 01 · the evidence set
Package anchor

The SHA-512 of the evidence package — every file and the manifest, fixed as one set.

target package sha512 9f86d081… ANCHORED ✓
Anchor target 02 · the recorded history
Custody chain anchor

The sealed head of the custody chain — the record of every event, including how the session ended.

target custody seal 4c1d… ANCHORED ✓
  • Individual files are never anchored — they are already fixed by the package hash, through the manifest.
  • Each target is registered independently, so the evidence set and the custody history can each be checked on their own.
The basics

Blockchains and certificate authorities, in plain words.

The anchors live in two kinds of places. If you have never met them, here is what each one is — and why it can hold a proof.

What is a blockchain?

Think of a shared notebook, copied across thousands of computers around the world. New entries can be added — but changing a past one would mean rewriting thousands of copies at once, so no one can quietly edit or erase it. Nobody owns it, and it is publicly readable.

That is why a fingerprint recorded there is hard to dispute: it exists in public, on machines that don't answer to anyone — including Provena.

[ block 1042 ] → [ block 1043 ] → [ block 1044 ] · mirrored on thousands of machines

What is a certificate authority?

A regulated company whose entire business is vouching for identity and time on the internet. The padlock in your browser exists because a certificate authority stands behind the site you're visiting.

An RFC 3161 token is that same institution signing a dated statement: this fingerprint existed at this exact moment — a signature that can be checked against keys the world already trusts.

package.tsr · signed 2026-08-07 14:47:02 UTC · verifiable signature
Where the proofs live

Anchored in three independent places.

The same two values — the package hash and the custody seal — are registered in three different kinds of places, with six independent providers. Each one holds the proof in its own way, outside Provena's servers.

Public blockchain networks

Open ledgers kept by thousands of independent machines — entries are public, and no one can quietly rewrite them.

SolanaHigh-throughput; anchors visible on any explorer.
HederaGoverned by a council of global organizations.
AlgorandProof-of-stake, fast final settlement.
the anchor → a public transaction
Bitcoin-backed timestamping

An open standard that commits fingerprints to Bitcoin — proof with no authority involved, held in a file you keep.

OpenTimestamps · BitcoinAnchored to the oldest, most audited public ledger; verifiable with open tooling.
the anchor → package.ots, a portable file
Time-stamp authorities (RFC 3161)

Regulated institutions signing dated statements — the same trust class behind the padlock in your browser.

SectigoOne of the world’s largest certificate authorities.
DigiCertA second, independent institutional signature.
the anchor → package.tsr, a signed token
Why three families, and not one?

Different systems fail in different ways: a network can be congested, an authority can be questioned, a service can disappear. Independent families corroborating the same value mean the proof survives any single failure — and even if Provena's own records were compromised, what an independent provider already attested would not change.

Only fingerprints travel — the evidence content and personal data never leave the platform.

Honest states

Anchors tell you exactly where they stand.

External systems have their own clocks. Provena reports anchor status as it is — including the states other tools hide.

  • Confirmation is asynchronous: an anchor can legitimately be pending when the report first opens, and confirm later through scheduled reconciliation.
  • Production and test are never mixed: anchors registered in a test environment carry no evidentiary value — and the report says so, visibly.
  • Failures are recorded, not erased — a failed registration shows as failed, next to the sources that confirmed.
Do it yourself

How it works — and how you verify it.

  1. Step 1 · Fingerprint

    The report shows the anchored values — the package hash and the custody seal, in full.

  2. Step 2 · Independent record

    Each anchor links to its external reference — a public explorer entry, an .ots artifact, or a signed .tsr token.

  3. Step 3 · Verification

    Compare the value in the external record with the value in the report. If they match, the proof holds — no Provena account required.

Verify evidence yourself →

Anchored — and ready to be read.

Everything the anchors attest is presented for human review in a report built for three kinds of readers.