# Metadata & SEO Documentation

*   **Page Title:** How VerixID Works — From File to Cryptographic Fingerprint
*   **Description:** Discover how VerixID secures your digital assets: SHA-256 fingerprints, Ed25519 signatures, immutable ledger architecture, and zero-upload privacy by design.
*   **Keywords:** how VerixID works, SHA-256 fingerprinting, digital document proof, zero upload, cryptography, Ed25519 signature
*   **App Version:** 1.2
*   **Canonical URL:** `https://verixid.com/how-it-works/`

---

# Structured Data Schema (JSON-LD)

### 1. HowTo Schema
*   **Name:** How VerixID Works — From File to Cryptographic Proof
*   **Description:** A 5-step process from file to cryptographic proof. Zero uploads, SHA-256 fingerprinting, and an immutable ledger.
*   **Step List:**
    1.  **Select File:** Drag and drop or select any file. The file never leaves your local device.
    2.  **Fingerprint Calculation:** The browser computes a SHA-256 fingerprint entirely client-side.
    3.  **Fingerprint Registration:** Only the cryptographic fingerprint is transmitted to the VerixID immutable ledger, stamped with a timestamp and Ed25519 server signature.
    4.  **Receive Record ID & Ownership Key:** VerixID issues a Record ID as a public identifier and an Ownership Key as proof of registration ownership.
    5.  **Verify Anytime:** Anyone can verify the Record ID at any time without creating an account.

### 2. FAQ Schema (FAQPage Schema)
*   *All question-and-answer entities are directly integrated into the structured FAQ component below.*

---

# Main Content

## How Does VerixID Work?
### From File to Cryptographic Fingerprint

No accounts required. Zero file uploads. Uncompromised privacy. Just verifiable mathematical proof—anytime, anywhere.

> **Key Takeaway:** VerixID does not prove who authored a file. VerixID proves when a file was first registered and who holds the cryptographic claim to that registration.

---

## 1. File Submission

Select a file from your local device. Your browser calculates a mathematical *fingerprint* (SHA-256) directly on your machine—the original file is never transmitted to our servers.

Only this cryptographic fingerprint is registered to VerixID, stamped with an authoritative timestamp, and digitally signed. Upon completion, you receive a **Record ID** (public identifier) and an **Ownership Key** (proof of record ownership).

### Workflow Process:

*   **Step 01: Select File**
    *   Drag and drop or select any digital file.
    *   The file remains strictly on your device—**it is never uploaded to any server**.
*   **Step 02: Fingerprint Calculation**
    *   Your browser computes a unique hash using the **SHA-256** algorithm directly on your client device.
    *   *Cryptographic Properties:*
        *   Identical file $\rightarrow$ yields an identical fingerprint.
        *   Any minute modification $\rightarrow$ produces a completely different fingerprint (avalanche effect).
        *   Two distinct files $\rightarrow$ mathematically will not produce the same fingerprint (collision resistance).
*   **Step 03: Fingerprint Registration**
    *   Only the computed fingerprint string is sent and recorded on the VerixID ledger, anchored by:
        *   **Server Timestamp (UTC):** Globally consistent, tamper-proof time-logging.
        *   **Digital Signature (Ed25519):** Ensures record authenticity and prevents system spoofing.
*   **Step 04: Receive Your Evidence**
    *   VerixID issues the following proof artifacts:
        *   **Record ID:** Public reference identifier.
        *   **Ownership Key:** Cryptographic proof of ownership.
        *   **Receipt:** Structured record containing the file hash, timestamp, and signature.
        *   **Verification Link:** Direct URL to your record’s verification page.
    *   *Implementation Note:* Include the verification link when sharing files with third parties, enabling recipients to instantly confirm the file's fingerprint exists unaltered on the ledger.
*   **Step 05: Verify Anytime**
    *   Anyone can verify your **Record ID** at any time, from any device.
    *   Use the **Ownership Key** to mathematically demonstrate your ownership claim.
    *   The entire workflow operates without accounts or authentication barriers.

---

## 2. Verification

Verification on VerixID works by comparing a file's calculated *fingerprint* against the active ledger entry. This process confirms that a file existed in an exact state at a specific point in time and has remained uncorrupted ever since.

*   **Record ID (Public Verification):** Enter a Record ID to confirm if a fingerprint exists on the VerixID ledger. The system displays the timestamp and associated parameters as proof of existence and data integrity.
*   **Ownership Key (Ownership Verification):** Provide the Ownership Key to mathematically validate ownership of the registration. Only the holder of this key can prove they executed the initial record submission.

---

## 3. What Is Actually Stored (Zero-Custody Architecture)

VerixID never stores or accesses your original file. The entire cryptographic process runs locally on your device—only the mathematical fingerprint (SHA-256) is transmitted to our network.

> **Zero-Custody Model:** No file storage, zero data leakage risk. There is no technical mechanism for our infrastructure to access, view, or reconstruct your original file contents.

### Data Recorded on the Ledger:
1.  **File Fingerprint (SHA-256 Hash):** A unique, non-reversible mathematical representation of your file. Contains no file contents and cannot be reverse-engineered.
2.  **Server Timestamp (UTC):** An authoritative, immutable timestamp recording exact entry creation time.
3.  **Digital Signature (Ed25519):** A cryptographic signature generated by VerixID system keys, verifying record authenticity and protecting against tamper attempts.

---

## 4. What Cryptographic Proof Means

VerixID generates deterministic mathematical proof that anyone can independently verify with identical, reproducible results—without placing blind trust in any single entity.

*   **Proof of Existence:** Proves an exact file existed at a specific time via the timestamp tied to its hash registration.
*   **Proof of Integrity:** Proves file contents have not been modified, as even a single-bit alteration changes the resulting hash.
*   **Consistency:** Demonstrates that a file verified today is mathematically identical to the file initially logged on the ledger.

---

## 5. System Integrity (Why Records Cannot Be Forged)

Every ledger entry is secured through three cryptographic pillars:
*   **File Fingerprint (SHA-256):** Uniquely identifies data; no two distinct files share the same hash value.
*   **Digital Signature (Ed25519):** Validates system issuance; any external data modification immediately invalidates the signature.
*   **Immutable Ledger (Append-Only):** Data can only be written, never modified or overwritten. Forging a record would require generating a colliding hash, forging the Ed25519 private key, and tampering with the ledger simultaneously—a scenario that is computationally impossible.

---

## 6. Account-Free Infrastructure

VerixID eliminates passwords, credentials, and central identity management. Record ownership is governed purely by cryptography:
*   Anyone can verify a record using the public **Record ID**.
*   Only the holder of the **Ownership Key** can mathematically prove registration ownership.

---

## 7. What Is Not Proved

VerixID operates within a defined technical scope. VerixID **does not prove**:
*   The real-world identity or author of the original file.
*   Legal copyright ownership or Intellectual Property (IP) rights.
*   The substantive accuracy, truthfulness, or legal validity of the file's contents.

---

## 8. Practical Real-World Applications

*   **Freelancers & Creators:** Register design files, manuscripts, or portfolios before sending them to clients to secure an immutable timestamp of prior existence in case of disputes.
*   **Contracts & Agreements:** Register final executed agreements to guarantee neither party can unilaterally modify terms post-signing.
*   **Auditing & Compliance:** Attach Record IDs to financial or technical reports, allowing auditors to independently confirm data integrity.
*   **Sensitive File Distribution:** Include hash and Record ID references when transmitting critical files to ensure recipients can verify bitstream integrity upon receipt.
*   **Long-Term Archiving:** Register master digital asset records to ensure verifiable proof of existence far into the future.

---

# Technical Architecture Overview

| Technology Component | Architectural Role |
| :--- | :--- |
| **🧬 SHA-256** | Industry-standard cryptographic hash algorithm generating unique 256-bit signatures. Used globally in banking, cybersecurity, and blockchain protocols. |
| **🔑 Ed25519** | High-speed, high-security public-key signature system validating server record authenticity. |
| **🗃 Immutable Ledger** | An append-only database architecture ensuring recorded entries cannot be modified or deleted by anyone—including VerixID. |
| **🛡 Zero Upload** | Client-side hashing executed in-browser via the native Web Crypto API. Raw file data never leaves your device. |
| **♾ Long-Term Integrity** | System optimization providing consistent verification performance over a standard 1-year* active ledger retention horizon. |
| **🖧 Edge Computing** | Multi-region edge deployment delivering low latency, high availability, and isolated security boundaries. |

---

# Frequently Asked Questions (FAQ)

#### Can VerixID prove who created a file?
VerixID proves **who registered the file first** and at what exact timestamp—not who authored it. The party holding the Ownership Key possesses the mathematical proof of that registration.

#### Do two identical files generate the same Record ID?
Yes—two files that are bit-for-bit identical generate the exact same SHA-256 fingerprint. VerixID accepts only the initial submission; subsequent attempts to register an identical file will return the existing record. This is a built-in integrity feature, not a limitation.

#### What happens if I lose my Ownership Key?
Ownership Keys cannot be recovered—VerixID never stores your key. You can still perform public verifications using the **Record ID**, but you will no longer be able to mathematically prove ownership. Always back up your key and receipt in a secure location.

#### How long does a Record ID remain active?
Free tier Record IDs remain active on the public ledger for 1 year* for online verification. However, anyone can independently confirm file integrity offline at any time by re-computing the file's SHA-256 hash.

#### Is a VerixID record admissible as legal evidence?
VerixID records provide valid technical proof under electronic document regulations. For formal legal proceedings, our **COA (Certificate of Authenticity)** service provides regulatory-aligned verification documents.

---

# Regulatory Compliance & Footer Navigation

*   **Legal Alignment:** Fully compliant with Indonesian EIT Law (UU ITE), PP PSTE, and Personal Data Protection Law (UU PDP).
*   **Government Registration:** Registered Electronic System Provider (PSE Komdigi) No. `022901.01/DJAI.PSE/04/2026`.
*   **Quick Links:**
    *   Register Document: `https://verixid.com/#dropzone`
    *   Verify Record: `https://verixid.com/verify/`
    *   COA Services: `https://verixid.com/coa/`
    *   Technical Documentation: `https://verixid.com/docs/`