Nobody can quietly rewrite it.

Every packet keeps its own history, written as things happen. Nothing in it is edited or removed, and each entry is sealed against the one before it, so an alteration is something anybody can detect.

What gets recorded

There are 38 kinds of entry and the list is fixed. Documents arriving with their digests, invitations going out, each person opening and reading, each field as it is filled, and every authentication attempt whether it worked or not.

The history outlives the documents. When a packet is eventually purged the files go and the record of what happened stays.

The certificate

Issued when a packet finishes, as a PDF and as machine-readable data. It prints each document’s digest, every party and what they did, and the caveats that apply to the connection details, rather than presenting an address as though it identified a person.

It is regenerated from the record on demand rather than stored as the only copy, so it cannot drift away from what actually happened.

Anybody can check it

A completed packet has a short code. Whoever holds it opens our check page, and we recompute the whole chain in front of them and say plainly whether it holds.

There is no account, no login and no request to us for a copy. That matters because the party who most needs to verify an agreement is usually the one who does not have a relationship with the software.