VerixID

Frequently Asked Questions

Everything you need to know about VerixID.

Clear answers organized by topic to help you find what you need quickly.

💡

General

5 questions
VerixID is a Digital Witness platform—it logs the cryptographic fingerprint of your file into an immutable ledger. This proves a file existed in a precise state at a specific point in time without ever storing the underlying file.
Submitting and Verifying files are free forever. Every entry remains active and publicly verifiable for 1 year*. Official Certificates of Authenticity (COA) and Expert Forensics are available as paid add-on services.
No. Anyone can register files and verify records immediately without signing up or creating an account.
Records are retained for 1 year* from the initial submission timestamp. This Time-To-Live (TTL) is enforced at the system architecture level. Once expired, records are permanently purged from the active ledger.
Any digital file—PDFs, Word documents, spreadsheets, images, videos, audio tracks, source code, server logs, or ZIP archives. VerixID never reads content; it calculates a SHA-256 hash locally. There are no file format or cryptographic size constraints.
📦

Products & Services

5 questions
They serve distinct operational and legal functions:

COA (Certificate of Authenticity) is an artifact layer—a one-off purchase generating an immutable official certificate snapshot of your active record.

Forensics is an expert analysis layer—a bespoke service for deep technical investigations, timeline reconstructions, and courtroom-ready technical audit reports.
No. Certificates of Authenticity can only be generated from active ledger entries. A COA’s underlying validity is tied to the ledger’s retention window (1 year* from initial submission).
Forensics are tailored for formal legal disputes requiring in-depth technical analysis—such as complete timeline reconstruction, independent ledger signature verification, or formal affidavits for court proceedings and corporate audits. Available anytime before record TTL expiration.
No. SHA-256 hashes are strictly unique to identical file contents. Re-submitting an identical file detects the existing entry and returns the original Record ID. This integrity safeguard prevents duplicate entries for identical hashes.
Yes. Once the 1-year* TTL ends and the entry is purged, submitting the same file issues a new Record ID with a fresh timestamp and reset TTL. This is the standard method to maintain cryptographic continuity post-expiration.
🔒

Security & Privacy

5 questions
No—it is technically impossible. The SHA-256 hash is computed locally in your browser via the Web Crypto API. Your original file is never uploaded. VerixID only receives a 64-character hash string that cannot be reverse-engineered into the original document. This is a fundamental Zero-Custody architecture by design.
Yes. Because original files never touch our infrastructure, a server compromise yields only public cryptographic hashes and timestamps—no confidential document data exists to leak. Furthermore, every entry is signed using Ed25519 cryptography; any tampering invalidates the signature instantly.
Yes. The Ownership Key is transmitted via encrypted HTTPS solely to match against stored state. It is never stored, logged, or recoverable server-side. VerixID maintains zero retention of your Ownership Key.
No. The VerixID ledger operates as an append-only structure—data can only be appended and cannot be altered or removed prior to TTL expiration. Even the VerixID engineering team cannot modify established cryptographic records.
VerixID is built around strict privacy-by-design principles. No Personal Identifiable Information (PII) is stored in the ledger—only mathematical hashes and timestamps. Because no personal data is processed or retained, zero PII exists to delete or breach.
⚙️

Technical

4 questions
Every record is signed via Ed25519. The VerixID public key is published openly at verixid.com/.well-known/verixid-public-key.pem. Developers can download this key and verify cryptographic signatures offline using standard libraries in any programming environment—completely independent of VerixID infrastructure. See our verification guide.
Yes. VerixID provides REST APIs for automated Submissions and Verifications. Submit SHA-256 hashes programmatically and receive signed Record IDs. Full technical docs are at our API Reference.
Linux/Mac Terminal: sha256sum filename.pdf
Windows PowerShell: Get-FileHash filename.pdf -Algorithm SHA256
Python: hashlib.sha256(open('file','rb').read()).hexdigest()

The output string matches the VerixID ledger hash exactly if the file is untampered.
Ed25519 is a high-speed, modern public-key signature system used by VerixID to sign every record entry. It guarantees the record was authentically issued by VerixID and hasn't been altered. Anyone can verify this signature using our public key without trusting our servers. Learn more in our Learn section.
🎨

For Creators

3 questions
Not identical, but highly complementary. VerixID proves when a creative work first existed in a specific state—not who holds the underlying legal title. In copyright litigation, timestamped priority proof is often key. Register your work on VerixID before public distribution.
By logging your file's hash with VerixID prior to public release, an immutable timestamp is established. If an external party claims ownership later, your VerixID record serves as mathematical proof that your work pre-dated their claim.
No. Original files are never transmitted or stored on VerixID servers. Only the cryptographic hash—a one-way mathematical fingerprint—is processed. Your files remain completely private on your local storage.
☕

Casual Enquiries

3 questions
SHA-256 is an open universal standard computable on any machine without VerixID. As long as you maintain your Record ID and Ownership Key, your mathematical proof remains independently verifiable forever. Issued COA documents also remain permanently valid.
Ownership Keys cannot be recovered—this is a strict zero-knowledge security guarantee. If you purchased a COA, that receipt serves as supporting documentation. However, key-less cryptographic proof of ownership cannot be forced. The record itself remains publicly visible on the ledger.
Institutions can change rules, face conflicts, or make mistakes. Mathematics is immutable. SHA-256 produces identical results on any computer, anywhere, at any time—without requiring third-party trust. That is VerixID’s core conviction: "We don't take sides. Math does."

Still have questions?

Can't find what you're looking for? Reach out to us or explore our technical documentation.