Security

Your source file is visible to you alone.

Without a subscription, it stays on your machine: only its fingerprint is transmitted, and that's enough to prove an identical file existed on a given date, without revealing anything about its content. With a subscription, you can also choose to entrust it to us, encrypted, for better organization of your deposits. Either way, whether storage is handled by you or by our servers, no one but you has access to its content.

How it works

01

Deposit

You deposit your file, which always stays with you.

02

Fingerprint

The browser computes a unique SHA-256 digest of the file.

03

Timestamping

The fingerprint is dated by an independent time authority.

04

Certificate

You receive an enforceable, publicly verifiable certificate.

Keep your source file: it's what proves the proof

The certificate attests that a given fingerprint existed on a given date — it doesn't replace the file itself. To use it one day (dispute, audit, challenge), you need to be able to reproduce that fingerprint from the original, intact file. If you lose that file, or modify it afterwards, the certificate loses all practical value: you won't be able to demonstrate that it matches your creation. Keeping your source file, in its original state, is therefore just as important as the deposit itself.

Why Ipocamp's timestamping uses so little energy

No mining, no proof of work: certifying a 32-byte fingerprint requires no competitive computation. An Ipocamp certificate uses the equivalent of a few seconds of web browsing.

What actually moves around

By default, the file stays on your machine, whatever its size: a 2 GB video and a 40 KB sketch produce the same 32-byte fingerprint, so the same traffic and the same carbon footprint. The fingerprint is anchored on the Tezos blockchain, chosen for its marginal energy use (proof of stake, no mining); when storage of the associated file is enabled, it's encrypted and distributed via Storj rather than on a single server; the application infrastructure is hosted with OVHcloud, in France.

Fingerprint transmitted32 bytes — never the file
HostingOVHcloud, France and European Union, GDPR-compliant
TimestampingIndependent time authority, anchored on the Tezos blockchain
Optional file storageEncrypted and distributed via Storj
VerificationPublic, no account needed, at any time
RetentionFor life, with no recurring fees
Evidentiary valueFree-form evidence in civil matters under French law — Art. 1358 of the French Civil Code
Insurance distributionIpocamp, a broker registered with ORIAS
IntegrationSaaS, API, white label

Enterprise deployment

For technical and security teams

Beyond the proof mechanism, what IT, security and procurement teams ask for before signing off on the tool.

Single sign-on (SSO)

Sign-in via your identity provider, over SAML or OIDC, with provisioning and deprovisioning through the systems you already operate.

API and automation

Every deposit can be triggered via API, including at volume and from your CI/CD pipeline, with real-time processing tracking.

Chained audit log

Every action is recorded in a tamper-proof registry — who did what, when — exportable for your audits.

Spaces per subsidiary or brand

Each entity, or each white-label deployment, has its own space, its own users and its own history, under shared governance.

Details by profile: IP and R&D teams, White-label publishing, Large accounts.

Glossary

The words of digital proof

Six terms come up in every intellectual property case. Here they are, one sentence each, without unnecessary jargon.

Prior existence

The fact that a creation existed before another one, or before a given date. This is what you seek to demonstrate in the event of copying.

SHA-256 fingerprint

A 32-byte string computed from a file. Unique, non-reversible: it identifies the file without revealing its content.

Timestamping

A date affixed by an independent trusted provider, attesting that a file existed at that moment.

Tamper-proof registry

A public log where an entry, once recorded, can no longer be modified or deleted — allowing a third party to verify it without going through us.

Infringement

The use of a protected creation without its owner's authorisation. It can be proven, and quantified as damages.

Trade secret

Confidential business information protected by reasonable measures — which you need to be able to document.