Sealway
How it works · files

Create evidence from your files.

A document, a photo, a video, a recording, or several files that belong together: from the app, you group them into one proof. Sealway computes their fingerprint, binds it to a qualified electronic timestamp and hands you an evidence file anyone can verify, without Sealway. The proof establishes that a file existed on a date and has not changed since; it does not say that its content is true.

A proof is a set of files dated together.

A proof does not have to be a single file: it can gather everything that documents one situation.

A property inventory is the signed document and the photographs of the rooms. A piece of music is the master, the lyrics and the score. A loss is the overall view, the detail of the damage and the invoice of the item. Grouping these files into one proof dates them together, and the certificate lists them one by one, each with its own fingerprint.

Each file remains verifiable on its own: producing a single photograph from the proof later is enough to establish that it was part of it and has not changed.

  • Property inventory: inventory.pdf, living-room.jpg, kitchen.jpg, bedroom.jpg.
  • Music: master.wav, lyrics.pdf, score.pdf.
  • Loss: overall-view.jpg, damaged-cabinet.jpg, invoice.pdf.

Up to 10 files and 250 MB per proof, of any type. Beyond that, several proofs in one collection keep the whole legible.

The four steps.

What you do, then what Sealway does.

  1. 1

    Choose what to document

    From the mobile app, take a photo or a video (no duration limit, within the proof’s 250 MB); from the mobile or web app, select existing files: photos and videos from the gallery, documents, PDFs, audio or music files, exports, source files. No format is excluded.

  2. 2

    Group the files into one proof

    Add the files that belong together, give the proof a title and, if useful, a description. Both are there to help you find it again: they stay editable and are not part of what is timestamped.

  3. 3

    Create the proof

    Each file travels over an encrypted connection; Sealway computes its SHA-512 fingerprint on receipt (the mobile app computes it on its side as well), then encrypts it before storing it. The fingerprints are gathered and timestamped, as the “fingerprint” section below explains. The certificate lists each file with its name, its fingerprint and its source: captured directly or imported.

  4. 4

    Download, keep, verify

    The evidence file holds the PDF certificate, the timestamp token (RFC 3161), the fingerprints, the manifest that ties them together and the original files. Without a storage plan, the originals are kept 7 days: keep a copy. The evidence file you keep remains verifiable indefinitely, and without Sealway.

Your files SHA-512 fingerprint of each file Merkle tree Qualified electronic timestamp Anchoring on public blockchains Evidence file

The fingerprint is what gets timestamped, not the file. The files travel over an encrypted connection and are encrypted on arrival, before storage, on servers in Europe.

Encryption, hosting, providers: the Security page

What live capture does not guarantee.

Capturing from the app or importing an existing file: both can be used, the certificate says which one was used for each file, and the next section says what each establishes about the date.

That the scene photographed is genuine, that the image is not that of a screen or a montage, or that the device was not tampered with. Sealway has no detection of generated content; it dates and fixes the file as it was produced.

What a qualified electronic timestamp changes.

When the proof is created, the fingerprint of each file is bound, through the Merkle tree, to a qualified electronic timestamp issued by a qualified trust service provider under the eIDAS Regulation. The date comes neither from the device, nor from the software, nor from Sealway.

Regulation (EU) No 910/2014, known as eIDAS

Article 41(2)

A qualified electronic time stamp shall enjoy the presumption of the accuracy of the date and the time it indicates and the integrity of the data to which the date and time are bound.

Regulation (EU) No 910/2014, Article 41(2)

A qualified electronic timestamp therefore enjoys a presumption of:

  • the accuracy of the date it indicates;
  • the accuracy of the time it indicates;
  • the integrity of the data to which that date and time are bound.

Sealway uses this mechanism to bind each file to a date independent of the device that produced it and of the person presenting it.

The presumption covers the date, the time and the integrity of the data. It covers neither what the image shows, nor the cause of what it shows, nor the compliance of what is photographed. Those questions remain for the court to assess, with an expert where needed.

Read the Regulation on EUR-Lex →

A photo’s date is not a proof’s date

A photo kept on a phone usually carries a date in its metadata. That information can be useful, but it depends on the device and can be modified: it does not enjoy the presumption attached to a qualified timestamp. Sealway binds the file’s fingerprint to an independent timestamp.

Photo taken from the app or imported

A photo taken from the Sealway app is created and immediately entered into the evidence process, and the certificate states for each file that it was captured directly. A photo imported from the library or a computer is just as usable: the proof establishes that this exact file existed no later than the timestamp. It does not establish that the picture was taken on the date written in its metadata, if that date is earlier.

Location is context, not a finding

When the photo is taken from the app and a position is available, the geolocation coordinates are written into the file before its fingerprint is computed and complete the context of the capture. It is data supplied by the device: Sealway does not certify the position the way it does the date.

The fingerprint: an identity, not a copy.

The SHA-512 fingerprint is a string of 128 characters computed from the exact content of a file. Two identical files give the same fingerprint; modifying a file, cropping it, recompressing it or fixing a comma gives another. The file cannot be recovered from its fingerprint, so a document can be dated without being disclosed.

The fingerprints of a proof are gathered in a Merkle tree, a fingerprint of fingerprints whose root is timestamped. Each file keeps its path in the tree, which lets one file be verified alone without producing the others. The root is also anchored on public blockchains: a second trace, independent of the timestamp provider.

  • Verify a file: recompute its SHA-512 fingerprint on your computer and compare it with the one on the certificate.
  • Verify the date: read the timestamp token, signed by the qualified provider, which carries the root of the tree.
  • Verify the whole: the tools on the Verification page check files, fingerprints, tree, timestamp and anchors, on your device.

What this proof establishes, and what it does not.

Sealway makes it possible to establish

  • that a given file existed at the latest at the time of the timestamp;
  • its integrity: the file has not been modified since;
  • whether a file presented later matches the one in the proof;
  • that a set of files was gathered and dated together;
  • for a live capture, that the file was created from the app and immediately taken into the proof.

Sealway does not, on its own, establish

  • that the content of the file is true;
  • that the events it shows happened as described;
  • that the author of the file is the person creating the proof;
  • the original creation date of an imported file;
  • the accuracy of the file’s metadata: date, device, position;
  • the legal qualification of what the file shows.

The existence and integrity of a file on a date is what the proof establishes. What the file proves in a given situation depends on the situation, the applicable law and, where it comes to that, the court’s assessment: that is what the use cases are about.

Frequently asked questions

What people ask about proofs created from files.

How do I timestamp a file with Sealway?
Open the app, create a proof, add the file (or capture a photo or a video), give it a title and confirm. Sealway computes the SHA-512 fingerprint of the file, binds it to a qualified electronic timestamp and produces the evidence file. The file does not need to be shared with anyone to be dated.
Does Sealway certify my documents?
Sealway establishes that a file existed on a given date and has not been modified since. It certifies neither the truth of the content, nor the identity of the author, nor the compliance of the document with anything. “Certify” must therefore not be read as a validation of the content.
Which file types are accepted?
All of them: photos, videos, PDFs, office documents, audio files, archives, exports, source files. Every file is handled the same way, through the fingerprint of its bytes, whatever its format.
How many files in a proof, and how large?
Up to 10 files and 250 MB in total per proof, with no per-file limit. For a larger set, create several proofs in one collection.
Can I film directly from the app?
Yes. A video captured from the app is taken into the proof immediately, with no duration limit: recording stops when the proof reaches 250 MB. A video filmed earlier is imported as an existing file.
What happens to my file?
It travels over an encrypted connection, then it is encrypted server-side before being stored, on servers in Europe. Only its fingerprint is timestamped and anchored. Without a storage plan, the original is kept 7 days and then deleted; the proof remains verifiable as long as you keep the file on your side.
Is an imported photo dated from the day it was taken?
No: it is dated from the moment of the proof, which establishes that it existed at the latest at that instant; the date in its metadata remains device information, not certified.
How does someone verify my proof without Sealway?
With the evidence file and the file itself: they recompute the fingerprint of the file, compare it with the certificate, then verify the timestamp token signed by the qualified provider. The Verification page offers tools that run on their device; any software able to compute a SHA-512, recompute the Merkle tree described on the certificate and read an RFC 3161 token will do as well.
What is this proof worth in court?
Under the eIDAS Regulation, a qualified electronic timestamp enjoys a presumption of the accuracy of the date and time and of the integrity of the data. What the file then proves depends on the situation and on the court’s assessment, which remains free; Sealway does not provide legal advice. Under French law, facts can be proven by any means.
Can I create evidence of an email by importing a .eml file?
No. Evidence of an email is created by adding Sealway in BCC when the email is sent, so that Sealway actually receives the message. A .eml imported afterwards would only prove that the file existed on the date of the import; the web app refuses it. See the guide on email evidence.

References

The texts and standards a proof from files rests on.

  • Regulation (EU) No 910/2014 of 23 July 2014 (eIDAS), art. 41 and 42, consolidated text EUR-Lex →
  • RFC 3161, Internet X.509 Public Key Infrastructure Time-Stamp Protocol IETF →
  • FIPS 180-4, Secure Hash Standard (SHA-512) NIST →
  • French Code civil, art. 1366 (evidential weight of electronic writing), in French Légifrance →
  • French Code civil, art. 1358 to 1362 (admissibility of the modes of proof), in French Légifrance →

Sealway does not provide legal advice. The weight of a proof in a given situation depends on the applicable law and on the court’s assessment.

Create evidence from your files.

Photos, videos, documents, audio: SHA-512 fingerprint, qualified electronic timestamp under eIDAS, evidence file verifiable without Sealway. Join the waitlist to be notified at launch.

By signing up, you agree to be contacted by Sealway about the launch. No sharing with third parties.