IRON ID Platform · Storage
Early accessProtect sensitive data. Prove it has not changed.
Encrypted storage where every version carries its own fingerprint, timestamp and audit record. Verifiable by anyone, without an account and without IRON ID.
What is IRON ID Storage?
Encrypted document storage that can prove what it holds.
Storage is where your organization keeps the documents it cannot afford to lose or dispute: contracts, invoices, board minutes, personnel files, evidence. Encrypted, versioned, searchable.
Every version gets a fingerprint, an electronic timestamp and a provenance manifest at upload, and every action joins a tamper evident log. Later, anyone can verify a document, on the public page or offline, without an account.
What happens to every document
- Uploadfile streams in, encrypted
- Sealedfingerprint per version
- Attestedtimestamp · provenance
- Verifiableby anyone, without IRON ID
Storage is the surface. The value is that a third party can check all of this without trusting IRON ID.
Six months later
Everything works. Until someone asks a question.
A client disputes an invoice. A partner insists a different version of the contract was approved. An auditor asks for the full history.
The same file, six months later
master-agreement.pdf12 March · M. Rossi
master-agreement-v2.pdf14 March · —
master-agreement-final.pdf2 April · A. Sow
master-agreement-final-v2.pdf2 April · —
master-agreement-final-signed.pdf11 April · unknown
And nobody can answer
Who opened it?
When?
Is this the right version?
Your files have a history. Most tools do not preserve it in a way you can truly verify.
The answer, one idea at a time
Three ideas. A question first, the technology last.
Is this the same file?
Every file has a fingerprint.
A string computed from the content itself. Two identical files give the same fingerprint. Two different files never do.
Technology: SHA-256, computed at upload, per version
The fingerprint does not change a little. It changes entirely.
When did this version exist?
A fingerprint tells what. Time tells when.
Submitted to a trusted clock, the fingerprint receives a date nobody can move, not even you. The clock never sees the file.
Technology: RFC 3161 electronic timestamp
- Fingerprint
- sha256 4f2a…81c0
- Timestamped
- 12 Mar 2026 09:01:44 UTC
- Authority
- Timestamping authority · RFC 3161
- Sees the file
- never · only the fingerprint
What happened afterwards?
Every action joins a history that cannot be quietly edited.
Each line of the log carries the fingerprint of the one before it. Removing a line does not erase it: it breaks the chain.
Technology: Merkle chained audit log, checkpoints anchored
Line removed: the next link no longer matches. The break is immediately visible.
How it works
From upload to independent verification.
- 1UploadThe file streams into encrypted storage. Its fingerprint is computed on the way in.
- 2SealedThe version is frozen. It now has an identity that any change would break.
- 3AttestedA timestamp authority dates the fingerprint. A provenance manifest is bound to the content.
- 4AnchoredThe fingerprint is submitted to a public ledger and confirmed within hours.
- 5VerifiedAnyone can check the proof: on the public page, by file, or offline with the verifier.
Legal value is acquired at the timestamp, in under a second. Anchoring reinforces durability; it never gates the proof.
The evidence bundle
Your proofs outlive your supplier.
Every certified document exports as a self sufficient bundle in a public, documented format. Verify it with the open source tool; nothing in it needs IRON ID to exist.
It guarantees
Content unchanged since sealing
A fingerprint existed at a date
Which issuer produced each attestation
The audit log was not rewritten
It does not guarantee
That the document says the truth
Who the depositor really was
That the issuer is trustworthy
Nothing was omitted before sealing
Features
What Storage does to every document.
- Encrypted storageAES-256-GCM envelope encryption with a distinct key per version; the key service never sees content.Built
- Immutable versionsEvery change creates a new version; nothing overwrites the previous one.Built
- Folders and searchOrganize documents in folders; full text search inside your organization.Built
- Fingerprint and timestampSHA-256 at upload, dated by an RFC 3161 electronic timestamp.Built
- Provenance manifestA C2PA manifest bound to the content records declared origin and transformations.Built
- Public anchoringFingerprint anchored on Bitcoin through OpenTimestamps, confirmed within one to six hours.Built
- Proof certificateA PDF certificate presenting fingerprint, verdict, timestamp and provenance.Built
- Evidence bundleEverything needed to verify, in an open format, checkable offline with the open source verifier.Built
- Public verificationAnyone verifies by file or by token on the public page, without an account.Early access
- GDPR erasureErase a document's content and keep its fingerprint, timestamp and audit entries.Built
- Tamper evident audit logAppend only log with sealed checkpoints; the application cannot rewrite it.Built
- Controlled sharingShare a document with access policies and a record of every access.Early access
Storage is included. 5 GB of storage is shared across all IRON ID products; you pay only for storage beyond that.
See pricingFAQ
Questions buyers ask first.
Can a third party verify a document without IRON ID?
Yes. Export the evidence bundle and run the open source verifier, or use the public verification page. Neither needs an account.
What exactly is proven?
That a given content existed at a given date, that it has not changed since, and which attestations were issued by which issuer. Not that the document says the truth.
Is the timestamp qualified?
Storage issues RFC 3161 electronic timestamps. Qualified timestamps from a named provider are planned and will be announced when the contract is in place.
What happens to a document I erase?
Its content is erased and can no longer be downloaded. Its fingerprint, timestamp and audit entries remain, so the proof still holds.
Get started
See IRON ID for your organization.
Request a demo of the Platform, join early access to be onboarded in the first cohorts, or request a quote for a KYC or Sign SDK integration.
Reply within two business days · contact@iron-id.io