Public hash chain publications
One signed, timestamped PDF per day. Each publication lists, for every library, the SHA-256 head of its
audit hash chain — and nothing else. No documents, no names, no contents. Because each head commits to the
entire history before it, these publications let anyone verify that no audit record was rewritten after the day it was published.
Loading…
Signing certificates
Every certificate this deployment has signed documents with. The root is a single stable anchor:
check its fingerprint against any document you hold, from any year, and it should not change.
Leaf certificates are replaced annually and their private keys are destroyed once the year ends,
so no document can be signed retroactively. Private keys are never published, here or anywhere else.
Loading…