Confidential by default
No public search by person, email, filename, description, date or arbitrary file hash.
Anti-probingAttestarium is designed so compromise of one layer does not silently rewrite history. Security states are explicit, sensitive data is minimised and stronger trust services remain independently identifiable.
No public search by person, email, filename, description, date or arbitrary file hash.
Anti-probingPassword plus TOTP is required before permanent sealing. Sessions are server-side and revocable.
Step-up authenticationCanonical manifests and seals are written outside the public web root and checked after write.
Tamper evidenceA DDEP package can carry the evidence manifest, signature key and trust material beyond the current domain.
No domain lock-inProvider administrators can manage the service but the design does not give them an “edit sealed evidence” function.
Operational controlsQualified timestamps, identity, payment, anchoring and storage are designed behind adapters.
Avoid supplier lock-inAttestarium presents platform seal time, Merkle batch state, independent anchor state, qualified timestamp state and identity assurance separately. That makes failure visible instead of pretending every green badge means the same thing.
The development build already implements browser hashing, TOTP-protected sealing, canonical evidence, Ed25519 platform signatures, adaptive Merkle batching and portable package verification. Independent production anchoring, qualified timestamps, identity verification, payment processing and Vault storage are separate integrations and are not falsely presented as active until configured.
Portable packages carry the issuer root key and an operational signing-key certificate. Compare this fingerprint through a trusted Attestarium channel when verifying outside this installation.
urn:attestarium:issuer:edf4398b-0dbc-42d4-af7b-f42a9c82d244