# WHAT IS A DIGITAL COA?
## Certificate of Authenticity — Mathematical Proof of Document Authenticity

A Certificate of Authenticity (COA) provides mathematical proof that a specific document *existed in an exact, unaltered state* at a specific point in time. Issued by computing a deterministic cryptographic SHA-256 fingerprint, the COA guarantees data integrity based on verifiable mathematics—not institutional trust or arbitrary policy.

### Core Attributes
* **Deterministic Verification:** Authenticity claims rely exclusively on bit-for-bit SHA-256 cryptographic verification rather than probabilistic estimation or manual oversight.
* **Zero-Custody Architecture:** Hashing is executed 100% locally client-side within the browser. Source files are never uploaded, stored, or processed on external servers.
* **Long-Term Persistence:** Active record visibility is maintained for 10 years backed by an immutable ledger architecture.
* **Regulatory Compliance:** Designed in alignment with EIT Law (UU ITE), Electronic System Operations Regulations (PP PSTE), and Personal Data Protection Act (UU PDP).

---

## SYSTEM MECHANICS

1. **Client-Side Local Hashing**  
   Standard cryptographic algorithms compute the file’s SHA-256 fingerprint directly within the user's browser. Source payloads never leave the local client environment.
2. **Immutable Ledger Entry**  
   The unique 64-character hexadecimal hash string is dispatched to the ledger and committed alongside an authoritative server timestamp. Altering a single bit in the source file results in an entirely different hash value.
3. **Credential Issuance (Receipt & Key)**  
   The system generates a verification receipt containing:
   * **Record ID:** A unique, publicly queryable identifier.
   * **Ownership Key:** A secret token used to assert technical control and ownership over the registration entry.

---

## SERVICE ECOSYSTEM & PRICING

* **File Submission (Free):** Initial registration for hash computation and basic record creation.
* **Digital COA (Formal Artifact):**  
  * **Fee:** IDR 750,000 / certificate (one-time purchase).
  * **Scope:** Formal proof document containing mathematical fingerprints, authoritative timestamps, and public verification references. Includes a 10-year data retention window.
* **On-Demand Forensics (In-Depth Investigation):**  
  * **Scope:** Case-based technical investigations, including chain-of-custody reconstruction, ledger signature verification, and formal audit report compilation for legal proceedings.

---

## TECHNICAL PROOF MATRIX

| Proof Parameter | Technical Explanation |
| :--- | :--- |
| **Proof of Existence (Timestamp Priority)** | Demonstrates that a file existed in its exact form prior to a specific timestamp, pre-dating subsequent claims or disputes. |
| **Registrant Attribution** | Associates document authenticity records with the verified identity of the submitting party. |
| **Long-Term Data Integrity** | Guarantees that document payloads remain free from tampering throughout storage and transmission cycles. |
| **Independent Public Verification** | Enables external third parties to validate authenticity directly without requiring platform account credentials. |

---

## IMPLEMENTATION SCENARIOS

* **Legal Counsel & Law Firms:** Anchoring final contract versions, non-disclosure agreements (NDAs), and formal legal filings.
* **Creators & Researchers:** Establishing priority timestamps for intellectual property, research data, whitepapers, and product designs.
* **Consultants & Freelancers:** Verifying delivery timestamps for project deliverables submitted to clients.
* **Auditors & Data Analysts:** Safeguarding the integrity of financial audits, logistics logs, and compliance exports.
* **Enterprises & Startups:** Logging product roadmaps, confidential internal documentation, and critical digital assets.

---

## FREQUENTLY ASKED QUESTIONS (FAQ)

### How does a Digital COA differ from an Electronic Signature (e-Sign)?
An electronic signature verifies **the identity of the signing party**. A VerixID COA proves **the existence and bit-level integrity of the document payload** at a specific point in time. They serve complementary functions.

### Are source documents uploaded to VerixID servers?
No. Fingerprint calculation is performed entirely client-side inside the user's browser. Only the resulting 64-character hash string is transmitted to our ledger. Servers retain zero technical access to original file content.

### What is the active validity period of a COA?
Issued COAs carry an active retention window of 10 years within the system.

### What is the legal standing of a VerixID COA in Indonesia?
A COA serves as admissible supporting electronic evidence under **EIT Law No. 11/2008 (adj. No. 19/2016)**, **PP PSTE No. 71/2019**, and **UU PDP No. 27/2022**. Certificates may be augmented with official Peruri e-Meterai stamps for formal judicial proceedings.

### What happens if the exact same file is registered again?
The system operates on a strict *first-to-register* principle. Each unique file hash can only be registered **once** on the ledger. Subsequent registration attempts for an identical payload will reflect the original record entry as the primary priority holder.

---

## CORPORATE ENTITY & NAVIGATION

**VerixID** — Digital Trust Infrastructure & Mathematical Proof of Digital Asset Ownership.
* **Regulatory Status:** Registered Electronic System Provider (PSE Komdigi) Reg No. `022901.01/DJAI.PSE/04/2026`.

### Navigation Index
* **Company:** [About Us](/en/about/) | [Contact Us](/en/contact/) | [Acceptable Use](/en/acceptable-use/) | [Privacy Policy](/en/privacy/) | [Terms of Service](/en/terms/) | [Manifesto](/en/manifesto/)
* **Resources:** [Documentation](/en/docs/) | [Learn](/en/learn/) | [How It Works](/en/how-it-works/) | [FAQ](/en/faq/) | [Whitepaper](/en/whitepaper/) | [Security Architecture](/en/security/)
* **Products:** [Submit File](/#dropzone) | [Verify Record](/en/verify/) | [COA System](/en/coa/) | [Trust API](/en/trust-api/) | [MCP Server](/en/mcp-server/)