How our PDF receipts hold up.
proof.epochpay.today is the IP-firm product in the EpochCore family. Every sealed PDF you produce gets a unique fingerprint, two independent signatures, and a public-record entry that anyone can verify — no login, no API key, no calling our firm. The same machinery is shared with Sealed (the SMB receipts product) and with the public verifier.
What we publish, and what we don't.
-
FRE 902(13) / 902(14)
Every sealed PDF includes the Rule 902 self-authentication certification structure embedded in its metadata. See Cornell LII.
-
NC Rule 902
North Carolina Rule of Evidence 902 governs self-authentication; NC Crim. Proc. Manual § 710.2 (UNC SoG) is the controlling commentary.
-
Bank-grade hardware
Every public-record entry is signed inside the same kind of secure hardware that signs ACH transactions for U.S. banks. The hardware's identity is published as part of the record.
-
Future-proof signatures
Every record carries two independent signatures — today's standards and a second one built to survive future quantum computers. A forger would have to break both at once.
-
Court-grade retention
Records kept at least 7 years on Solo, 10 on Boutique, 15 on Mid, and custom (15 / 25 / permanent) on Firm. The retention period is part of the receipt itself.
-
SOC 2 Type II
In progress · Evidence collection live · Type II report target: Q4 2026.
-
IBM Partner Plus
Enrolled. Twelve EpochCore agents listed in IBM's watsonx Orchestrate marketplace. proof shares the same public-record substrate.
-
SEC 17a-4(f) attestation
Engagement pending. Target: Q3 2026. The chain substrate is designed to meet 17a-4(f) WORM and indexing requirements; the third-party attestation (Cohasset Associates or equivalent) will confirm. Procurement pre-questions: privacy@epochcoreqcs.com.
-
BTC witness anchoring
Daily summary hash anchored to Bitcoin via OpenTimestamps. Recent anchors at
/anchors. Verifiable withots-cli; no EpochCore servers in the loop.
Plain English, no jargon.
The moment a document is sealed, we compute a one-of-a-kind digital fingerprint of its exact bytes. Change a comma — the fingerprint changes completely. Anyone holding the original file can recompute the fingerprint locally and confirm it matches.
Every fingerprint joins that hour's batch of receipts. At the top of the next hour, the whole batch gets bundled into one public-record entry. flash-sync.epochcoreqcs.com/aggregator/status shows the live batch as it fills.
The hour's record is signed with two independent signatures — today's standards and a second one built to survive future quantum computers. A forger would have to break both at once.
The signing happens inside the same kind of secure hardware U.S. banks use to sign ACH transactions. The hardware's identity is published as part of the record. This is the layer that survives a deposition challenge.
Open chain.epochcoreqcs.com, paste the receipt's fingerprint, see the answer. Includes confirmation of both signatures, the hardware that signed them, and the record's integrity. If we vanished tomorrow, your receipts still verify.
Every receipt across every EpochCore product traces back to a single founding record from when we started. That trail is permanent and public.
Every update lands in the same public record.
Every time we update our software, we publish a build receipt: a snapshot of the exact code that was running when your PDF was sealed. The build receipt's fingerprint is added to the same public record where your receipts live. So when someone asks "what version of the software was running when my client's contract was sealed?", we point at the record and they verify it themselves.
The build receipt contains every line of source for every public product we run, each file fingerprinted. Anyone can unpack the receipt and read the exact code that was running on the day of their seal.
The build receipt from that hour is the answer — and we don't have to be in the room for you to confirm it. The receipt and your client's seal land in the same hour's public record. Forging either means forging both — and the math behind that resistance is the same math behind U.S. banking infrastructure.
No AI training on your records.
We publish a machine-readable opt-out so AI-training crawlers can't use anything on our public pages. We don't grant any third party permission to train models on your sealed records.
Responsible-disclosure path.
Vulnerabilities in any EpochCore-operated surface: seal.epochpay.today/security. Same-day acknowledgment; coordinated-disclosure timelines on request. We do not share reporter identity with third parties.
Who handles your data, and what they handle.
We use a small, deliberately-selected set of subprocessors. Each plays a specific role; none of them touches raw decision payloads (payloads are fingerprinted — one-way hashed — before any chain commit). A signed DPA is available on request from privacy@epochcoreqcs.com. Builder-tone draft template online at /dpa-template.
-
Cloudflare, Inc.
Workers, KV, Browser Rendering, DNS, CDN. U.S.-headquartered, global PoPs. Request-level analytics + edge logs retained 30 days.
-
IBM Cloud
watsonx Orchestrate bridge worker proxies tournament_decision skill invocations originating from Watson.x. U.S. + EU regions available. Payloads pass through but are not persisted.
-
Resend, Inc.
Transactional email (walkthrough confirmations, security disclosures). U.S.-based. We do not send marketing email; opt-in not required for transactional category.
-
OpenTimestamps
Free public calendar pool (
a.pool.opentimestamps.org). Receives a daily 32-byte fingerprint of our chain-activity summary; batches with other submissions into Bitcoin transactions. No personal data leaves our worker; only the fingerprint. See /anchors for the live record. -
chain.epochcoreqcs.com
EpochCore-operated public read endpoint. Chain receipts are append-only and publicly readable by anyone, by design — that's the whole point of the substrate.
Per-receipt key IDs, annual rotation.
Each chain receipt carries two independent signatures — a bank-grade signature (Ed25519, FIPS 186-5) and a future-proof signature (ML-DSA-87, FIPS 204 Level 5). The signing-key IDs are published in the receipt itself as the fields ed25519_signing_key_id and mldsa87_signing_key_id.
-
Where keys live
Inside the EpochCore signing service. Keys never leave the signing boundary; only the public key IDs are externalized into receipts.
-
Rotation cadence
Annual rotation. Prior keys retained indefinitely so historical receipts remain verifiable against their original signing key.
-
Rotation ceremony
Witnessed by EpochCore officers; a third-party observer joins the ceremony for the first paid customer onwards. Ceremony notes published on this page after each rotation.
-
Compromise response
If a signing key is compromised, the compromise is announced on this page; subsequent receipts use the new key; the compromised key's receipts remain verifiable but are marked at the chain level with a compromise note. We do not retroactively re-sign.
Every day's activity hashes into Bitcoin.
Each UTC midnight, a deterministic SHA-256 summary of the day's chain activity is submitted to the OpenTimestamps calendar pool. Within ~1 hour, that hash is included in a Bitcoin transaction; within ~6 confirmations it's permanently anchored to a specific Bitcoin block.
Why this matters. The chain at chain.epochcoreqcs.com is EpochCore-operated. The Bitcoin chain is not. Anchoring our daily activity hash to Bitcoin means anyone can independently verify that the day's summary existed at the timestamp we claim — even if we disappeared tomorrow.
How to verify. Download the OpenTimestamps proof for any anchor from /anchors, then verify against the live Bitcoin chain using the open-source ots-cli or the public verifier at opentimestamps.org/verify. No EpochCore servers in the verification loop.
What is anchored. A deterministic canonical-text summary of the day's TRIBUNAL_DECISION_OUTCOME + TRIBUNAL_APPELLATE_VERIFY seal hashes (sorted lexicographically, joined with newlines, hashed once with SHA-256). Anyone with public chain access can reproduce the exact bytes we anchored and confirm it matches the BTC-anchored hash.
Send it to security@; we acknowledge in 24h.
Coordinated disclosure. We acknowledge every report within 24 hours and target a fix within 30 days, depending on severity. We do not run a cash bug-bounty program yet; credit is published in the Acknowledgments list below (opt-out available on request).
Reporting: security@epochcoreqcs.com.
Machine-readable contact: /.well-known/security.txt (RFC 9116).
Out of scope: social engineering of EpochCore staff; physical attacks; denial of service against the marketing site (we accept the cost); third-party services (report directly to the subprocessor).
Acknowledgments: none yet. Be the first.