Universal DocumentOpen document infrastructure
Menu

Authenticity Bug Light 8 · free local verification

A green integrity check is one answer—not every answer.

Check whether the exact document changed. Then inspect signature, signer identity, time, current status and transparency as independent evidence.

Six questions, six honest answers

Structure

Is this parseable as the supported UD schema?

Integrity

Do the protected bytes match the canonical seal hash?

Signature

Is the cryptographic signature mathematically valid for the signed state?

Signer identity

Is that signing key bound to a real person or organization by checked evidence?

Time

Is there a trusted timestamp, rather than merely a local clock value?

Current status

Has the key or document been revoked, expired, superseded, or otherwise changed in status?

Offline vs online verification → · Why the document cannot vouch for its own identity →

Start with your responsibility

Document recipient

Can I trust the exact copy I received?

Open path →

Records manager

Can I preserve finality, supersession, revocation and retention context?

Open path →

General Counsel

Which state was signed, by which key, under which identity evidence?

Open path →

Litigation and eDiscovery

Can the file and its custody evidence be examined independently?

Open path →

Compliance and investigations

Which checks passed, failed, or were not performed?

Open path →

Auditor

Can I export a reproducible verification result without conflating integrity and truth?

Open path →

Security and digital identity

Is key validity separate from identity assurance and current trust?

Open path →

Procurement

What neutral capabilities should a verifier demonstrate?

Open path →

Government records

Can verification work locally while online status checks remain explicit?

Open path →

Health information management

Can integrity be checked without uploading document contents?

Open path →

Financial operations

Can a retained copy be checked without claiming its numbers are correct?

Open path →

Software developer

Are the inputs, hashes, algorithms and outcomes machine-readable?

Open path →

Trust-service operator

Can registry, revocation, timestamp and transparency evidence remain independently inspectable?

Open path →

Authoritative answers

What Does Document Verification Actually Prove?

It can establish specific technical facts—such as structure, exact-state integrity and signature validity—while leaving identity, time, status and content truth as separate questions.

Read the answer →

Signature Validity Is Not the Same as Identity Verification

A valid signature proves possession of a private key for a signed state. Real-world identity requires separate, checked binding evidence.

Read the answer →

Tamper-Evident Is Not the Same as Tamper-Proof

Tamper evidence makes later change detectable. It does not make alteration impossible.

Read the answer →

Integrity Does Not Prove That the Document Is True

An unchanged document can still contain mistakes or false statements. Integrity proves state, not factual correctness.

Read the answer →

Why Document Verification Needs Layers

Structure, integrity, signature, identity, time and current status answer different questions and should never collapse into one green badge.

Read the answer →

Offline Verification and Online Trust Checks Solve Different Problems

Offline checks can prove exact-state integrity. Online checks can add current registry, revocation, timestamp or transparency evidence when explicitly requested.

Read the answer →

Why a Document Cannot Be Its Own Identity Witness

A file can carry a claimed signer name, but independent identity assurance requires evidence outside the claim being evaluated.

Read the answer →

What Happens After a Document Is Signed?

Recipients still need to check the signed state, signature, key and identity status, timestamp evidence, revocation, supersession and retention context.

Read the answer →

Trust services stay separate

The Trust Registry can publish key and identity status. Witnesses can observe checkpoints. Certification can describe implementation conformance. None of those are silently inferred from a matching hash.