Trust hub · proof.epochpay.today

How our PDF receipts hold up.

proof.epochpay.today is the IP-firm product in the EpochCore family. Every sealed PDF you produce gets a unique fingerprint, two independent signatures, and a public-record entry that anyone can verify — no login, no API key, no calling our firm. The same machinery is shared with Sealed (the SMB receipts product) and with the public verifier.

The promises we make

What we publish, and what we don't.

  • FRE 902(13) / 902(14)
    Every sealed PDF includes the Rule 902 self-authentication certification structure embedded in its metadata. See Cornell LII.
  • NC Rule 902
    North Carolina Rule of Evidence 902 governs self-authentication; NC Crim. Proc. Manual § 710.2 (UNC SoG) is the controlling commentary.
  • Bank-grade hardware
    Every public-record entry is signed inside the same kind of secure hardware that signs ACH transactions for U.S. banks. The hardware's identity is published as part of the record.
  • Future-proof signatures
    Every record carries two independent signatures — today's standards and a second one built to survive future quantum computers. A forger would have to break both at once.
  • Court-grade retention
    Records kept at least 7 years on Solo, 10 on Boutique, 15 on Mid, and custom (15 / 25 / permanent) on Firm. The retention period is part of the receipt itself.
  • SOC 2 Type II
    In progress · Evidence collection live · Type II report target: Q4 2026.
  • IBM Partner Plus
    Enrolled. Twelve EpochCore agents listed in IBM's watsonx Orchestrate marketplace. proof shares the same public-record substrate.
  • SEC 17a-4(f) attestation
    Engagement pending. Target: Q3 2026. The chain substrate is designed to meet 17a-4(f) WORM and indexing requirements; the third-party attestation (Cohasset Associates or equivalent) will confirm. Procurement pre-questions: privacy@epochcoreqcs.com.
  • BTC witness anchoring
    Daily summary hash anchored to Bitcoin via OpenTimestamps. Recent anchors at /anchors. Verifiable with ots-cli; no EpochCore servers in the loop.
How a receipt works

Plain English, no jargon.

Step 1 · Take the fingerprint
Every sealed PDF gets a unique digital fingerprint.

The moment a document is sealed, we compute a one-of-a-kind digital fingerprint of its exact bytes. Change a comma — the fingerprint changes completely. Anyone holding the original file can recompute the fingerprint locally and confirm it matches.

Step 2 · Add it to the hour's batch
Once an hour, the batch lands in the public record.

Every fingerprint joins that hour's batch of receipts. At the top of the next hour, the whole batch gets bundled into one public-record entry. flash-sync.epochcoreqcs.com/aggregator/status shows the live batch as it fills.

Step 3 · Sign the record twice
Two independent signatures, both published.

The hour's record is signed with two independent signatures — today's standards and a second one built to survive future quantum computers. A forger would have to break both at once.

Step 4 · Lock it in hardware
Bank-grade secure hardware does the signing.

The signing happens inside the same kind of secure hardware U.S. banks use to sign ACH transactions. The hardware's identity is published as part of the record. This is the layer that survives a deposition challenge.

Step 5 · Anyone can check
No login, no API key, no calling our firm.

Open chain.epochcoreqcs.com, paste the receipt's fingerprint, see the answer. Includes confirmation of both signatures, the hardware that signed them, and the record's integrity. If we vanished tomorrow, your receipts still verify.

Every receipt across every EpochCore product traces back to a single founding record from when we started. That trail is permanent and public.

We sign our own software the same way

Every update lands in the same public record.

Every time we update our software, we publish a build receipt: a snapshot of the exact code that was running when your PDF was sealed. The build receipt's fingerprint is added to the same public record where your receipts live. So when someone asks "what version of the software was running when my client's contract was sealed?", we point at the record and they verify it themselves.

Latest build receipt
Always available from the public verifier.

Check today's public record on the verifier →

What's inside
The full source code, file-by-file.

The build receipt contains every line of source for every public product we run, each file fingerprinted. Anyone can unpack the receipt and read the exact code that was running on the day of their seal.

What this answers
"What code minted my client's seal?"

The build receipt from that hour is the answer — and we don't have to be in the room for you to confirm it. The receipt and your client's seal land in the same hour's public record. Forging either means forging both — and the math behind that resistance is the same math behind U.S. banking infrastructure.

Your content stays yours

No AI training on your records.

We publish a machine-readable opt-out so AI-training crawlers can't use anything on our public pages. We don't grant any third party permission to train models on your sealed records.

Security disclosure

Responsible-disclosure path.

Vulnerabilities in any EpochCore-operated surface: seal.epochpay.today/security. Same-day acknowledgment; coordinated-disclosure timelines on request. We do not share reporter identity with third parties.

Subprocessors

Who handles your data, and what they handle.

We use a small, deliberately-selected set of subprocessors. Each plays a specific role; none of them touches raw decision payloads (payloads are fingerprinted — one-way hashed — before any chain commit). A signed DPA is available on request from privacy@epochcoreqcs.com. Builder-tone draft template online at /dpa-template.

  • Cloudflare, Inc.
    Workers, KV, Browser Rendering, DNS, CDN. U.S.-headquartered, global PoPs. Request-level analytics + edge logs retained 30 days.
  • IBM Cloud
    watsonx Orchestrate bridge worker proxies tournament_decision skill invocations originating from Watson.x. U.S. + EU regions available. Payloads pass through but are not persisted.
  • Resend, Inc.
    Transactional email (walkthrough confirmations, security disclosures). U.S.-based. We do not send marketing email; opt-in not required for transactional category.
  • OpenTimestamps
    Free public calendar pool (a.pool.opentimestamps.org). Receives a daily 32-byte fingerprint of our chain-activity summary; batches with other submissions into Bitcoin transactions. No personal data leaves our worker; only the fingerprint. See /anchors for the live record.
  • chain.epochcoreqcs.com
    EpochCore-operated public read endpoint. Chain receipts are append-only and publicly readable by anyone, by design — that's the whole point of the substrate.
Key management

Per-receipt key IDs, annual rotation.

Each chain receipt carries two independent signatures — a bank-grade signature (Ed25519, FIPS 186-5) and a future-proof signature (ML-DSA-87, FIPS 204 Level 5). The signing-key IDs are published in the receipt itself as the fields ed25519_signing_key_id and mldsa87_signing_key_id.

  • Where keys live
    Inside the EpochCore signing service. Keys never leave the signing boundary; only the public key IDs are externalized into receipts.
  • Rotation cadence
    Annual rotation. Prior keys retained indefinitely so historical receipts remain verifiable against their original signing key.
  • Rotation ceremony
    Witnessed by EpochCore officers; a third-party observer joins the ceremony for the first paid customer onwards. Ceremony notes published on this page after each rotation.
  • Compromise response
    If a signing key is compromised, the compromise is announced on this page; subsequent receipts use the new key; the compromised key's receipts remain verifiable but are marked at the chain level with a compromise note. We do not retroactively re-sign.
BTC witness anchoring

Every day's activity hashes into Bitcoin.

Each UTC midnight, a deterministic SHA-256 summary of the day's chain activity is submitted to the OpenTimestamps calendar pool. Within ~1 hour, that hash is included in a Bitcoin transaction; within ~6 confirmations it's permanently anchored to a specific Bitcoin block.

Why this matters. The chain at chain.epochcoreqcs.com is EpochCore-operated. The Bitcoin chain is not. Anchoring our daily activity hash to Bitcoin means anyone can independently verify that the day's summary existed at the timestamp we claim — even if we disappeared tomorrow.

How to verify. Download the OpenTimestamps proof for any anchor from /anchors, then verify against the live Bitcoin chain using the open-source ots-cli or the public verifier at opentimestamps.org/verify. No EpochCore servers in the verification loop.

What is anchored. A deterministic canonical-text summary of the day's TRIBUNAL_DECISION_OUTCOME + TRIBUNAL_APPELLATE_VERIFY seal hashes (sorted lexicographically, joined with newlines, hashed once with SHA-256). Anyone with public chain access can reproduce the exact bytes we anchored and confirm it matches the BTC-anchored hash.

Vulnerability disclosure

Send it to security@; we acknowledge in 24h.

Coordinated disclosure. We acknowledge every report within 24 hours and target a fix within 30 days, depending on severity. We do not run a cash bug-bounty program yet; credit is published in the Acknowledgments list below (opt-out available on request).

Reporting: security@epochcoreqcs.com.
Machine-readable contact: /.well-known/security.txt (RFC 9116).

Out of scope: social engineering of EpochCore staff; physical attacks; denial of service against the marketing site (we accept the cost); third-party services (report directly to the subprocessor).

Acknowledgments: none yet. Be the first.