# Metadata & SEO Document

*   **Page Title:** System Security — VerixID
*   **Description:** VerixID Security Architecture: Zero-upload mechanics, unstored ownership keys, cryptographic chain ledger, Ed25519 signatures, and global edge network infrastructure.
*   **Canonical URL:** `https://verixid.com/en/security/`
*   **Application Version:** 1.2
*   **Robots Rule:** index, follow
*   **Keywords:** digital document security, zero custody, Ed25519, SHA-256, immutable ledger, cryptography

---

# Structured Data Schema (JSON-LD)

### Organization Entity
*   **Name:** VerixID
*   **URL:** `https://verixid.com`
*   **Logo:** `https://verixid.com/logo.png`
*   **Description:** Mathematical verification system for digital assets. Built on mathematics, not promises.
*   **Support Contact:** `contact@verixid.com` (English & Indonesian)
*   **Official Social Channels:** 
    *   X (Twitter): `https://twitter.com/verixid`
    *   LinkedIn: `https://linkedin.com/company/verixid`

---

# Core Content

## Hero Section
### VerixID Security Architecture
Transparency is fundamentally embedded within our protocol. Here are the mathematical guarantees applied to every recorded entry—along with their explicit boundaries.

*   **Primary Navigation:**
    *   [Submit File](/#dropzone)
    *   [Verify Record](/en/verify/)
    *   [COA (Certificate of Authenticity)](/en/coa/)
    *   [Documentation](/en/docs/)

---

## Core Principles: Built on Cryptographic Proof

*   **Zero Upload Architecture**
    Every record is cryptographically signed using VerixID’s Ed25519 private key. Public keys for independent verification are published alongside our self-verification roadmap.
*   **Unstored Ownership Keys**
    VerixID stores exclusively the cryptographic hash of an Ownership Key—never the raw key itself. The key remains entirely unknown to VerixID systems and staff. Ownership verification relies on hash comparisons, eliminating plaintext exposure.
*   **Cryptographic Chain Ledger**
    Each entry commits the cryptographic hash of the preceding record, establishing a continuous chain where unauthorized retroactivity causes immediate, detectable corruption.
*   **Ed25519 Digital Signatures**
    Records are signed via VerixID’s Ed25519 private key, enabling external parties to independently confirm record authenticity via our public key.
*   **Authoritative Server Timestamps**
    Timestamps are generated exclusively server-side upon request arrival and processing—bypassing client-side clock manipulation.
*   **Uniqueness Guarantee & Anti-Duplication**
    Registered fingerprints cannot be re-committed. The architecture enforces a strict 1-to-1 mapping between a file fingerprint and its record, granting exclusivity to the initial registration.

---

## Trust Model: What Is Guaranteed — and What Is Not

### ✔ What We Guarantee
*   The target file **existed in its exact byte form** at the registered server timestamp.
*   The SHA-256 hash committed to the ledger **remains unchanged** since initial registration.
*   The ledger operates on an **append-only** model—lacking technical operations for modification or deletion, even by internal system administrators.
*   Data retention for **1 year** (in accordance with our [Terms & Conditions](/en/terms/#ttl-free-note)) is guaranteed by system architecture, not arbitrary policy.

### ❌ What We Do Not Guarantee
*   VerixID **does not prove** real-world author identity or creation origin.
*   VerixID **does not prove** factual accuracy, legality, or validity of file content.
*   VerixID **does not validate** legal copyright ownership or intellectual property rights.
*   VerixID **does not provide** judicial interpretation of record context—legal weight remains under the sole jurisdiction of courts and legal counsel.

---

## Trust Method: Independent Mathematical Verification

VerixID leverages structured mathematical workflows to validate hash integrity and schema compliance. Verification employs black-box methodologies grounded in independent hash computation and receipt output comparison, ensuring reproducible auditability for any third party.

### Verification Methodology
*   **Hash Computation:** Independent SHA-256 computation utilizing dual execution environments (CLI tools & standard cryptographic libraries).
*   **Format Validation:** Strict schema validation across all attributes (Record ID, Ownership Key, Timestamp).
*   **Bit-Level Comparison:** Exact matching between local hash computations and receipt records—with zero error tolerance.
*   **Uniqueness Testing:** Sequential registration of distinct files to verify Record ID and fingerprint divergence.
*   **Avalanche Effect Testing:** Validating that minor payload adjustments result in entirely disparate SHA-256 output hashes.
*   **Zero-Custody Audit:** Verifying that infrastructure retains cryptographic fingerprints exclusively, with zero file payload storage.

### Benchmark Results

| Test Parameter | Verification Method | Result |
| :--- | :--- | :--- |
| **Hash Integrity** | Independent execution vs. cryptographic receipt | ✅ Exact bit-for-bit match |
| **Record ID Format** | Pattern matching (`vx+YYYY+MM+8-hex`) | ✅ Fully compliant |
| **SHA-256 Output** | 64-character hexadecimal format (`[0-9a-f]`) | ✅ Validated |
| **Ownership Key** | SHA-256 standard output schema | ✅ Consistent |
| **Timestamp** | ISO 8601 UTC standard | ✅ Validated |
| **Uniqueness** | Comparative evaluation of discrete records | ✅ Unique |
| **Avalanche Effect** | Comparative evaluation of modified payloads | ✅ Total hash divergence |

---

## Independent AI Audit & Forensic Reports

Digital trust must be open to third-party validation. VerixID has undergone rigorous testing by state-of-the-art AI models to evaluate cryptographic integrity, ledger immutability, and hashing standard compliance.

*   **ChatGPT (OpenAI):** File integrity, zero-custody architecture, and cryptographic receipt audits. \[[Download PDF Report](reports/verixid-forensik-2026-03-26-chatgptai.pdf)\]
*   **Claude (Anthropic):** In-depth structural evaluation of encryption mechanics and zero-custody data flow. \[[Download PDF Report](reports/verixid-forensik-2026-03-25-claudeai.pdf)\]
*   **DeepSeek:** Mathematical validation of immutable ledger structures and anti-tampering resistance. \[[Download PDF Report](reports/verixid-forensik-2026-03-25-deepseekai.pdf)\]
*   **Gemini (Google):** System consistency and data integrity audit against technical documentation claims. \[[Download PDF Report](reports/verixid-forensik-2026-03-26-geminiai.pdf)\]
*   **Grok (xAI):** Edge infrastructure security evaluation and timestamp authority validation. \[[Download PDF Report](reports/verixid-forensik-2026-03-26-grokai.pdf)\]

> 💬 **"Proof, not promises."**
> VerixID establishes digital trust through mathematical verification. We validate our technical guarantees publicly via independent forensic evaluation reports as a standard of transparency.

---

## Adversarial Threat Model: How Could the System Fail?

*   **What if VerixID goes offline?**
    SHA-256 is an open international standard. Anyone can independently compute file hashes using native environment utilities (`sha256sum` on Linux/macOS, `certutil` on Windows) and compare them against recorded values. Mathematical verification operates independently of VerixID server availability.
*   **What if VerixID servers are compromised?**
    VerixID servers receive mathematical hashes exclusively—never source files. A server breach exposes zero document content. For the ledger itself, append-only mechanics and cryptographic chaining ensure retroactive tampering breaks subsequent hashes and triggers instant detection.
*   **Can VerixID forge timestamps?**
    Timestamps are generated server-side upon HTTP request arrival and committed immediately to the immutable ledger. No administrative workflow exists to modify a timestamp post-commit. For legal proceedings, forensic services offer full timeline reconstructions accompanied by verifiable audit trails.
*   **Can VerixID modify or purge records?**
    No. This constraint is architectural, not policy-driven. The ledger uses a write-once model with no `UPDATE` or `DELETE` operations implemented at the database layer. Even with direct database access, modifying a historic entry invalidates the cryptographic hash chain for all subsequent entries, exposing tampering instantly.
*   **What if VerixID ceases operations?**
    Your computed hash remains permanently verifiable offline using standard SHA-256 tools. Issued COAs remain valid as standalone formal documents. To ensure record continuity, our 1-year retention commitment is enforced by infrastructure built on multi-region, vendor-neutral storage.

---

## Infrastructure Architecture

*   **Global Edge Network**
    VerixID services execute on a distributed global edge network, ensuring low-latency verification and high service availability.
*   **High-Durability Ledger**
    Mathematical fingerprints are committed to high-durability storage systems engineered for maximum fault tolerance.
*   **End-to-End Transport Security**
    Data in transit is protected via industry-standard TLS encryption. Internal data flows enforce multi-layered encryption controls.
*   **Automated Abuse Prevention**
    System traffic is monitored in real time to detect anomalous patterns, automatically rate-limiting bad actors before service integrity or operational performance is impacted.
*   **Multi-Factor Access Isolation**
    Infrastructure access is restricted via strict least-privilege policies, network isolation, and multi-factor authentication protocols.

---

## Vulnerability Disclosure (Responsible Disclosure)

Identified a security vulnerability within VerixID? We welcome responsible security research. Please submit vulnerability disclosures to our security team at [security@verixid.com](mailto:security@verixid.com).

---

# Compliance & Legal Footer

*   **Service Declaration:** VerixID — Mathematical Proof for Digital Assets. Immutable file fingerprints and server timestamps verifying early proof-of-existence—without storing file content or collecting personal data. Engineered in compliance with Indonesian EIT Law (UU ITE), PP PSTE, and Personal Data Protection Law (UU PDP).
*   **PSE Registration:** Registered Electronic System Provider (PSE Komdigi) No. [022901.01/DJAI.PSE/04/2026](/assets/images/0512210000869-I-202604061458529391413.avif)
*   **Sitemap Navigation:**
    *   **Company:** [About Us](/en/about/) | [Contact](/en/contact/) | [Acceptable Use](/en/acceptable-use/) | [Privacy Policy](/en/privacy/) | [Terms & Conditions](/en/terms/) | [Manifesto](/en/manifesto/)
    *   **Reference:** [Documentation](/en/docs/) | [Learn](/en/learn/) | [How It Works](/en/how-it-works/) | [FAQ](/en/faq/) | [Whitepaper](/en/whitepaper/) | [Security](/en/security/) | [Report Incident](/en/security/#verify-report)
    *   **Products:** [Submit File](/#dropzone) | [Verify Record](/en/verify/) | [COA Services](/en/coa/)