Three tools are on the shortlist, the demos all went fine, and the feature grids look close enough that the decision is drifting toward whoever presented best. All of them promise proof: that a document existed, that it hasn't been altered, that somebody signed it. One question separates the tools that hold up from the ones that don't, and it's on nobody's comparison sheet.
Here it is. Can a person who has no account with the vendor verify the evidence on their own, and does that still work if the vendor is gone?
What a product page means by proof, and what a dispute means by it
On a product page, proof usually means the tool shows you something: a green badge, an audit trail inside the vendor's dashboard. That's the vendor making a statement about its own records. In a dispute, proof is narrower. A third party with no relationship to you or the vendor, an arbitrator or opposing counsel, has to look at an artifact and reach a conclusion without taking anyone's word for it.
The gap shows up when somebody asks for the evidence, you send a link, and they land on a sign in page.
First half: can a stranger verify it
Put the scenario to every vendor in the same words. I hand your artifact to somebody with a laptop and no account. What can they establish, and with what software? Answers fall into three groups.
- Verification works only inside the product, for signed in users. The evidence and the vendor are the same thing, so it's only as available as the account.
- Verification works through a public page the vendor hosts. Better, and useful day to day, but it's still tied to that vendor being reachable on the day somebody checks.
- Verification works offline with standard software. The file carries its own cryptographic material, and a common PDF reader or an open verification utility checks it against certificates published by a certification authority.
Only the third is independent in the sense a lawyer means. Ask for a sample artifact and open it on a machine that has never touched the vendor's software.
Second half: does the evidence outlive the vendor
Evidence gets used years later. It has to survive three separate disappearances.
- The subscription. If your organisation stops using the service, do existing artifacts keep verifying, or does verification end with the account?
- The vendor. Companies get acquired, change direction, and shut down. If those servers went dark tomorrow, which artifacts would still mean anything?
- The format. Algorithms weaken as computing power grows. Ask whether evidence can be renewed, and whether the artifact follows a documented public standard rather than a container only that vendor reads.
What is actually being attested
Proof collapses three different claims into one word, and tools differ in which of them they make.
| Claim | What it establishes | What it does not establish |
|---|---|---|
| Identity of a signer | A verified person applied a signature | When the content was created |
| Integrity of a file | The content has not changed since sealing | Who made it, or whether they had the right to |
| Existence at a point in time | This exact content existed no later than that moment | Who authored it, unless identity is bound in |
| All three, bound together | A named party held this content at this time | Any dispute about the underlying rights |
The combination you need depends on the problem. A contract needs signer identity. A design file or a manuscript usually needs existence at a time plus integrity, because under the Berne Convention copyright arises automatically when a work is created and does not require registration in order to exist. What a creator lacks is rarely a registration. It is a dated, checkable record of what existed and when.
Who issues the attestation
There's a real difference between a vendor asserting something in its own logs and an attestation issued under a supervised legal framework. Under Regulation (EU) No 910/2014, known as eIDAS, Article 41 gives a qualified electronic timestamp a presumption of the accuracy of the date and time it indicates and of the integrity of the data it covers. In Switzerland, ZertES governs qualified certificate services, and equivalence with a handwritten signature sits in the Code of Obligations at OR Art. 14 para. 2bis.
For a buyer, that changes who has to argue. So ask two plain questions: who is the trust service provider behind this, and under which supervisory scheme is it listed? A vendor built on an accredited provider names it without hesitating.
The questions to send in writing
Nothing said in a demo is retrievable six months later. Send these by email and keep the reply.
- Send a sample artifact we can verify offline, on a machine with none of your software installed.
- Name the trust service provider behind the attestation and the scheme that supervises it.
- State what each artifact attests: identity, integrity, existence at a time, or a combination.
- Describe what happens to artifacts we have already created if our account closes.
- Describe what a third party can verify if your service is unavailable.
- Confirm we can export every artifact in bulk in a documented format, and whether the export carries the verification material or only a summary.
- Explain how evidence can be renewed as cryptographic algorithms age.
Apply that list to every candidate, including the one you already like. Swiss Trust Layer answers all seven: its artifacts carry qualified Swiss timestamps and signatures that verify in ordinary PDF software with no account anywhere, and the how it works page sets out that path. The list matters more than any single answer to it. A vendor that'll only answer these on a call has told you something about how the evidence behaves the day you need it.





