Skip to main content

IRON ID Platform · Storage

Early access

Protect sensitive data. Prove it has not changed.

Encrypted storage where every version carries its own fingerprint, timestamp and audit record. Verifiable by anyone, without an account and without IRON ID.

What is IRON ID Storage?

Encrypted document storage that can prove what it holds.

Storage is where your organization keeps the documents it cannot afford to lose or dispute: contracts, invoices, board minutes, personnel files, evidence. Encrypted, versioned, searchable.

Every version gets a fingerprint, an electronic timestamp and a provenance manifest at upload, and every action joins a tamper evident log. Later, anyone can verify a document, on the public page or offline, without an account.

What happens to every document

  1. Uploadfile streams in, encrypted
  2. Sealedfingerprint per version
  3. Attestedtimestamp · provenance
  4. Verifiableby anyone, without IRON ID

Storage is the surface. The value is that a third party can check all of this without trusting IRON ID.

Six months later

Everything works. Until someone asks a question.

A client disputes an invoice. A partner insists a different version of the contract was approved. An auditor asks for the full history.

The same file, six months later

master-agreement.pdf12 March · M. Rossi

master-agreement-v2.pdf14 March · —

master-agreement-final.pdf2 April · A. Sow

master-agreement-final-v2.pdf2 April · —

master-agreement-final-signed.pdf11 April · unknown

And nobody can answer

Who opened it?

When?

Is this the right version?

Your files have a history. Most tools do not preserve it in a way you can truly verify.

The answer, one idea at a time

Three ideas. A question first, the technology last.

Is this the same file?

Every file has a fingerprint.

A string computed from the content itself. Two identical files give the same fingerprint. Two different files never do.

Technology: SHA-256, computed at upload, per version

BeforeArticle 4.2 — The supplier delivers no later than 30 June.sha256 1ebb 4c09 … c9e4
After · one comma movedArticle 4.2 — The supplier delivers, no later than, 30 June.sha256 e6b1 7a20 … 5c28

The fingerprint does not change a little. It changes entirely.

When did this version exist?

A fingerprint tells what. Time tells when.

Submitted to a trusted clock, the fingerprint receives a date nobody can move, not even you. The clock never sees the file.

Technology: RFC 3161 electronic timestamp

Fingerprint
sha256 4f2a…81c0
Timestamped
12 Mar 2026 09:01:44 UTC
Authority
Timestamping authority · RFC 3161
Sees the file
never · only the fingerprint

What happened afterwards?

Every action joins a history that cannot be quietly edited.

Each line of the log carries the fingerprint of the one before it. Removing a line does not erase it: it breaks the chain.

Technology: Merkle chained audit log, checkpoints anchored

#48206Uploadedprev
#48207Openedprev 4f2a…81c0
#48208Sharedprev a19c…3b7e
#48209Signedprev c803…dd41
#48210Modifiedprev 72e5…0a9fchain broken
#48211Approvedprev e6b1…5c28

Line removed: the next link no longer matches. The break is immediately visible.

How it works

From upload to independent verification.

  1. 1UploadThe file streams into encrypted storage. Its fingerprint is computed on the way in.
  2. 2SealedThe version is frozen. It now has an identity that any change would break.
  3. 3AttestedA timestamp authority dates the fingerprint. A provenance manifest is bound to the content.
  4. 4AnchoredThe fingerprint is submitted to a public ledger and confirmed within hours.
  5. 5VerifiedAnyone can check the proof: on the public page, by file, or offline with the verifier.

Legal value is acquired at the timestamp, in under a second. Anchoring reinforces durability; it never gates the proof.

The evidence bundle

Your proofs outlive your supplier.

Every certified document exports as a self sufficient bundle in a public, documented format. Verify it with the open source tool; nothing in it needs IRON ID to exist.

It guarantees

Content unchanged since sealing

A fingerprint existed at a date

Which issuer produced each attestation

The audit log was not rewritten

It does not guarantee

That the document says the truth

Who the depositor really was

That the issuer is trustworthy

Nothing was omitted before sealing

Features

What Storage does to every document.

  • Encrypted storageAES-256-GCM envelope encryption with a distinct key per version; the key service never sees content.Built
  • Immutable versionsEvery change creates a new version; nothing overwrites the previous one.Built
  • Folders and searchOrganize documents in folders; full text search inside your organization.Built
  • Fingerprint and timestampSHA-256 at upload, dated by an RFC 3161 electronic timestamp.Built
  • Provenance manifestA C2PA manifest bound to the content records declared origin and transformations.Built
  • Public anchoringFingerprint anchored on Bitcoin through OpenTimestamps, confirmed within one to six hours.Built
  • Proof certificateA PDF certificate presenting fingerprint, verdict, timestamp and provenance.Built
  • Evidence bundleEverything needed to verify, in an open format, checkable offline with the open source verifier.Built
  • Public verificationAnyone verifies by file or by token on the public page, without an account.Early access
  • GDPR erasureErase a document's content and keep its fingerprint, timestamp and audit entries.Built
  • Tamper evident audit logAppend only log with sealed checkpoints; the application cannot rewrite it.Built
  • Controlled sharingShare a document with access policies and a record of every access.Early access

Storage is included. 5 GB of storage is shared across all IRON ID products; you pay only for storage beyond that.

See pricing

FAQ

Questions buyers ask first.

Can a third party verify a document without IRON ID?

Yes. Export the evidence bundle and run the open source verifier, or use the public verification page. Neither needs an account.

What exactly is proven?

That a given content existed at a given date, that it has not changed since, and which attestations were issued by which issuer. Not that the document says the truth.

Is the timestamp qualified?

Storage issues RFC 3161 electronic timestamps. Qualified timestamps from a named provider are planned and will be announced when the contract is in place.

What happens to a document I erase?

Its content is erased and can no longer be downloaded. Its fingerprint, timestamp and audit entries remain, so the proof still holds.

Get started

See IRON ID for your organization.

Request a demo of the Platform, join early access to be onboarded in the first cohorts, or request a quote for a KYC or Sign SDK integration.

Reply within two business days · contact@iron-id.io