# FAQ — Frequently Asked Questions — VerixID

Comprehensive answers regarding how VerixID works, free-tier features, COA, On-Demand Forensics, data security, and regulatory alignment under Indonesian EIT Law (UU ITE). Designed for general users, businesses, and developers.

---

## CATEGORY INDEX

* [General](#general)
* [Products & Services](#products--services)
* [Security & Privacy](#security--privacy)
* [Legal & Compliance](#legal--compliance)
* [Technical](#technical)
* [For Creators](#for-creators)
* [Casual Questions](#casual-questions)

---

## GENERAL

### What is VerixID?
VerixID functions as an independent **Digital Witness**—a platform that records the cryptographic fingerprint of your file onto an immutable ledger. It proves that a specific file existed in an exact state at a precise timestamp—without ever storing or viewing the original file.

### Is VerixID free?
File submission and verification are **free forever**. Every registration is free of charge. Records remain active and publicly verifiable on the ledger for 1 year. Certificates of Authenticity (COA) and On-Demand Forensics are available as separate paid services.

### Do I need to create an account?
No account is required for Submission or Verification. Anyone can register files and verify ledger records without registering an account.

### How long are records stored?
Ledger records are retained for **1 year** from the initial submission date. This Time-To-Live (TTL) is enforced at the architectural level—it is a structural guarantee, not a flexible business policy. Once the 1-year TTL expires, the entry is permanently purged.

### What file formats can I register?
Any digital file—PDF, Word documents, Excel spreadsheets, images, videos, audio, source code, log files, ZIP archives, and more. VerixID does not inspect file contents; it only calculates the cryptographic hash. Cryptographically, there are no file format or size restrictions.

---

## PRODUCTS & SERVICES

### What is the difference between a COA and On-Demand Forensics?
They represent distinct, complementary service tiers:
* **COA (Certificate of Authenticity):** The artifact layer—a one-time purchase that generates a formal certificate acting as an *immutable snapshot* of an active ledger record. It serves as an official technical document aligned with UU ITE regulations.
* **On-Demand Forensics:** The expert analysis layer—a bespoke, case-by-case service providing in-depth technical investigations, chain-of-custody reconstruction, and structured technical reports tailored for audits or courtroom proceedings.

### Can a COA be issued for an expired record?
No. A COA can only be generated for an actively maintained record on the ledger. The validity of a COA is anchored to the ledger’s TTL (1 year from initial submission).

### When do I need On-Demand Forensics?
On-Demand Forensics is required when deep technical analysis is necessary—such as complex legal litigation requiring chain-of-custody reconstruction, independent verification of ledger signatures, or formal expert witness statements for court or compliance audits. This service is available as long as the record’s TTL has not expired.

### Can the same file be registered more than once?
No. SHA-256 hashes are mathematically unique to the exact file content. Re-submitting an identical file triggers duplicate detection, returning the existing Record ID. This is a core integrity feature—ensuring no duplicate records exist for the same hash.

### Can an expired record be re-registered?
Yes. Once the 1-year TTL expires and the record is purged from the active ledger, the same file hash can be re-submitted. A new Record ID will be issued with a new timestamp and a fresh TTL. This is the only way to extend mathematical proof continuity past the initial expiration.

---

## SECURITY & PRIVACY

### Can VerixID view the contents of my document?
No—it is technically impossible. SHA-256 hash calculations occur client-side in your browser via the Web Crypto API. Your original file is never transmitted to VerixID servers. Our system only receives a 64-character hex string—which cannot be mathematically reversed to reconstruct the original file. This is our **Zero Custody** architecture *by design*.

### Is my data safe if VerixID is compromised?
Yes—because original files are never uploaded to or stored on our infrastructure. The ledger only stores non-reversible hashes and timestamps. No stored data can leak file contents. Furthermore, every record is cryptographically signed using **Ed25519**—any unauthorized tampering with the ledger renders signatures invalid and immediately detectable.

### Is it safe to enter my Ownership Key on the Verify page?
Yes. Ownership Keys are transmitted over encrypted HTTPS connections. Server-side, the key is processed purely to validate ownership against the stored hash—it is never saved, logged, or reconstructed. VerixID does not store Ownership Keys in any form.

### Can my record be modified or deleted?
No. The VerixID ledger operates on an *append-only* basis—data can only be added, never modified or deleted prior to TTL expiration. This is enforced by system architecture rather than administrative policy. Even the VerixID engineering team cannot alter a recorded entry.

### Is VerixID compliant with the Personal Data Protection Law (UU PDP)?
Yes. VerixID is built on *privacy by design* principles. No personal identifiable information (PII) is stored on the ledger—only file hashes and timestamps. No names, emails, or user identities are tied to Record IDs. Because no personal data is collected or retained, there is no sensitive data to purge under UU PDP data subject rights.

---

## LEGAL & COMPLIANCE

### Can verification results be used as evidence in court?
Public verification results constitute valid digital evidence under Indonesia's EIT Law (UU ITE jo. Law No. 1/2024). Article 5 recognizes electronic information as valid legal evidence, while Article 6 requires verifiable integrity—which VerixID guarantees via cryptographic hashing. For full courtroom admissibility, generating a COA is recommended.

### Can a VerixID COA be presented in court without expert testimony?
A VerixID COA serves as admissible technical evidence under Articles 5 and 6 of the UU ITE. Its evidentiary weight is maximized when accompanied by expert witness testimony in digital forensics. Presiding judges retain full authority to weigh evidence; we provide immutable cryptographic facts while your legal counsel constructs the legal argument.

### What does VerixID prove and not prove?
* **What We Prove:** The exact file existed at a specific timestamp; its unique fingerprint was registered for the first time on our ledger; file content has remained unaltered since registration; and the record was authentically issued by VerixID (verified via Ed25519 signature).
* **What We Do Not Prove:** The real-world identity of the author; the truthfulness or legal validity of file content; copyright or Intellectual Property (IP) ownership; intent or bad faith; or legal liability/guilt.

### Is VerixID valid for international documents outside Indonesia?
SHA-256 and Ed25519 are global cryptographic standards independent of legal jurisdictions. Users worldwide can register hashes and independently verify results. For formal legal proceedings, evidentiary acceptance depends on local jurisdictional laws. In Indonesia, VerixID operates under the governing framework of UU ITE.

---

## TECHNICAL

### How do I verify a record independently without VerixID?
Every ledger record is signed using Ed25519. VerixID publishes its public key openly at `verixid.com/.well-known/verixid-public-key.pem`. Developers can download this key and verify record signatures using standard cryptographic libraries in any environment—without relying on VerixID infrastructure. Step-by-step instructions are available in our documentation.

### Is an API available for integration?
Yes. VerixID offers a REST API for automated Submit and Verify functions. Send a SHA-256 hash and receive a signed Record ID with an Ed25519 signature. Complete endpoints and code samples are available in our API Reference.

### How do I manually calculate a SHA-256 hash?
* **Linux / macOS (Terminal):**
  `sha256sum filename.pdf`
* **Windows (PowerShell):**
  `Get-FileHash filename.pdf -Algorithm SHA256`
* **Python:**
  `hashlib.sha256(open('filename.pdf','rb').read()).hexdigest()`

The resulting hexadecimal output will match the hash stored on the VerixID ledger if the file remains unaltered.

### What is Ed25519 and why is it important?
Ed25519 is a high-speed, modern public-key signature system used by VerixID to sign every record entry. It proves that a record was genuinely issued by VerixID and has not been tampered with since issuance. Anyone can verify signature authenticity using our published public key—eliminating the need to blindly trust VerixID.

---

## FOR CREATORS

### Is registering with VerixID equivalent to copyright registration?
No, but they are complementary. VerixID proves *when* a creative work existed in a specific state—not who legally owns the copyright. In intellectual property disputes, establishing an early timestamp is often decisive. Register your creative assets on VerixID before public distribution.

### How do I prove my work predates someone else's claim?
By registering your work's hash on VerixID before publishing, an immutable timestamp is recorded on the ledger. If a third party claims ownership at a later date, your VerixID timestamp serves as mathematical proof that your file existed first—regardless of who published online first.

### Can my creative work be viewed or stolen from VerixID?
No. Original files are never uploaded or transmitted to VerixID—only non-reversible SHA-256 hashes are processed. Hashes cannot be reverse-engineered to reconstruct original files. Your work remains safe on your local storage; VerixID merely logs proof of its existence.

---

## CASUAL QUESTIONS

### What happens if VerixID shuts down?
SHA-256 and Ed25519 are open cryptographic standards verifiable using offline tools on any computer—independent of VerixID's existence. As long as you retain your Record ID and original file, the mathematical proof remains independently verifiable forever. Previously generated COA documents remain valid proof artifacts.

### I lost my Ownership Key. What can I do?
Ownership Keys cannot be recovered or reset—this is a strict security feature, not a platform limitation. If you retain your official COA receipt, that document can still serve as supporting evidence in legal proceedings, though automated ownership verification requires the key. The public record remains on the ledger to prove file existence.

### Why trust mathematics over centralized institutions?
Institutions can alter policies, face conflicts of interest, or make errors. Mathematics does not. A SHA-256 calculation produces identical results on any computer, anywhere in the world, at any time—without requiring trust in a third-party intermediary. This embodies our core principle: *"Math does not take sides."*

---

## ADDITIONAL INFORMATION

* **Regulatory & Legal Status:** Registered Electronic System Provider (PSE Komdigi) No. `022901.01/DJAI.PSE/04/2026`
* **Governing Framework:** Fully aligned with UU ITE, PP PSTE, and UU PDP regulations.