Trust
What independent verification proves
Independent verification means somebody else can confirm that the report they are holding is the exact report that was produced, from the exact set of documents recorded, using the exact processing details recorded. It does not confirm that your documents are genuine, and it does not confirm that any conclusion in the report is correct.
The short version
When a report is produced, TraceFolio calculates a fingerprint for every uploaded document, a fingerprint for the list of those documents, a fingerprint for the structured findings, and a fingerprint for the finished PDF. Those fingerprints, together with the processing details, are recorded and certified. Anyone with the verification reference can check them.
Because verification relies on fingerprints rather than on keeping your files, your report stays checkable after your uploaded documents have been deleted.
What verification does prove
- The report file is cryptographically linked to the recorded list of evidence, the recorded processing details and this exact report document.
- The report has not been altered since it was produced: a changed PDF produces a different fingerprint.
- The set of documents recorded for the report is the set that was analysed, identified by fingerprint.
- The processing details recorded, including versions and settings, are the ones that produced this report.
- Somebody who was not involved can carry out the check themselves using the verification reference.
What verification does not prove
- It does not prove that an uploaded document is genuine, unaltered before upload, or written by the person it appears to be from.
- It does not prove that the claims inside those documents are true.
- It does not prove that every interpretation in the report is correct.
- It does not establish any legal conclusion, and it is not a court certification or an official accreditation.
This distinction is the whole point. Verification is about the honesty of the process, not about the honesty of the paperwork you fed into it.
How to check a downloaded PDF
Every report page includes a check for the file you downloaded: select the PDF and the browser recalculates its fingerprint locally and compares it with the certified value. The comparison happens on your own device, so the file is not uploaded again to be checked.
If the fingerprints match, the file is byte-for-byte the certified report. If they do not match, the file has been changed since it was issued, even if it looks identical.
What a Certified Execution Record is
A Certified Execution Record is the certificate issued for one report run. It contains the fingerprints described above plus the processing details, and it is signed by the certification service so the record cannot be quietly rewritten later.
Certification is issued through NexArt, an independent execution-certification service. NexArt receives fingerprints and processing details only. It never receives your documents, the text extracted from them, the findings or your filenames, which is why certification adds an external check without widening who can read your evidence.
What another person can see
A verification page shows fingerprints, versions, timestamps and the certification status. It does not show the contents of your documents or the contents of your report. Sharing a verification reference lets somebody confirm a report's integrity without giving them access to the evidence.
Related reading
Create your evidence report
Every report comes with a verification record, at no extra cost and on every tier.
Holding a verification reference already? Open it directly at the verification page.