PROOF PACKAGE · SELLAT
======================

Package state: COMPLETE.

Sealed file:        parquet-en-mal-estado.webp
SHA-256 fingerprint: 27524c9669b7ee9773af7a95fdd3369a6708c861ef044d68430e81ae09fa8306
Sealed at:          14 September 2026 at 08:25:40 (UTC)
Package built at:   30 September 2026 at 23:55:21 (UTC)
Identifier:         3cdf0d38-8312-475d-8f36-b95fc857c214
Certificate page:   https://sellat.app/en/certificate/3cdf0d38-8312-475d-8f36-b95fc857c214

The sealing date never changes. The package date only describes this copy: it
moves every time you download the package again, and the proof stays the same.

WHAT IS IN HERE
---------------
- original/parquet-en-mal-estado.webp
    The sealed file, byte for byte. This is the essential piece: without these
    exact bytes nothing can be checked.
- certificado-3cdf0d38-8312-475d-8f36-b95fc857c214.pdf
    The human-readable certificate, to attach to a filing or show to a person.
    It is an informative document: what gets checked is the file.
- proof.json
    The portable proof (sellat-proof/2 format): the file fingerprint, its Merkle
    leaf and inclusion path, the batch root and the public transaction that
    records it. This is what allows verification without Sellat.
- anclaje-bitcoin.ots
    OpenTimestamps proof of the batch root, already confirmed in Bitcoin (block 966942).
- sello-cualificado-3cdf0d38-8312-475d-8f36-b95fc857c214.tsr
    Qualified timestamp (RFC 3161) issued on 14 September 2026 at 08:25:47 (UTC)
    by AUTORIDAD DE SELLADO DE TIEMPO FNMT-RCM-TSU 2025, over the file's SHA-256.
    Serial 0B59D38532AB7D856AA7AF8B8122FF51.
- autoridad-sellado.pem
    The certificate that authority signed the timestamp with, as embedded in the
    token itself.
- LEEME.txt / README.txt
    This document, in Spanish and in English.

WHAT TO KEEP
------------
Keep this whole ZIP, in two different places (your computer and a cloud copy,
for instance), next to the documents of the matter it belongs to.

The one thing that must not be lost is the sealed file: the exact bytes in the
"original" folder. Everything else can be obtained again from the certificate
page.

What affects the check and what does not:
- Modifying the sealed file, even by one byte: its fingerprint changes and no
  longer matches the proof. Do not open it with programs that rewrite the file
  when saving, and do not re-export it.
- Renaming the ZIP, re-compressing it, moving or copying it: no effect on the
  proof. What is checked is the content of the sealed file.
- Editing or deleting this README, or the PDF certificate: no effect on the
  proof. It may stop Sellat from reading the ZIP automatically; in that case
  verify by uploading the sealed file directly.

HOW TO CHECK IT AT SELLAT (quickest)
------------------------------------
1. Open https://sellat.app/verify
2. Upload this ZIP as it is and choose the "Sellat ZIP" option; or upload the
   file inside the "original" folder and choose "Exact sealed file".
3. If the fingerprint matches you get the proof date. No account needed.

HOW TO CHECK IT WITHOUT RELYING ON SELLAT
-----------------------------------------
1. The file fingerprint. In a terminal:
     sha256sum "original/parquet-en-mal-estado.webp"
   Must print exactly: 27524c9669b7ee9773af7a95fdd3369a6708c861ef044d68430e81ae09fa8306
   (macOS: shasum -a 256. Windows: certutil -hashfile <file> SHA256.)
2. The qualified timestamp, with OpenSSL:
     openssl ts -reply -in "sello-cualificado-3cdf0d38-8312-475d-8f36-b95fc857c214.tsr" -text
   Shows the time (genTime), the policy and the authority. To verify the
   signature against that authority:
     openssl ts -verify -in "sello-cualificado-3cdf0d38-8312-475d-8f36-b95fc857c214.tsr" -data "original/parquet-en-mal-estado.webp" \
       -CAfile autoridad-sellado.pem -partial_chain
   Must answer "Verification: OK".
   And check the authority is who it claims to be: the SHA-256 of
   autoridad-sellado.pem must equal the certificate published in the EU
   trusted list for the service
     "Qualified timestamps issued by Autoridad de Sellado de Tiempo FNMT-RCM-TSU 2025"
   Certificate SHA-256: 56cab2cd977b47c14f0067d304b8554a0e31ba1d21b0f15bdf7faa819da03176
   Trusted list: https://eidas.ec.europa.eu/efda/tl-browser/
   (Spain -> FNMT-RCM -> qualified timestamps).
   Authority, per the certificate: C=ES, L=MADRID, O=FNMT-RCM, organizationIdentifier=VATES-Q2826004J, CN=AUTORIDAD DE SELLADO DE TIEMPO FNMT-RCM-TSU 2025
3. The portable proof, with the open-source verifier:
     npx sellat-verify --file "original/parquet-en-mal-estado.webp" --proof proof.json
   Source: https://github.com/skanthemore/sellat-verify
   What it does: recomputes the leaf from the fingerprint, walks the Merkle
   path up to the batch root and checks that this root is the one recorded in
   the public transaction named in proof.json.
4. This certificate's Polygon Mainnet transaction, in any public explorer. Its
   data field contains the identifier and the fingerprint above, as text:
     0xe2bbc746c7d32967affbadbd612280e5ec67a853951ecf1fbc1fb05aeeb61447
     https://polygonscan.com/tx/0xe2bbc746c7d32967affbadbd612280e5ec67a853951ecf1fbc1fb05aeeb61447
   This is a different check from the previous one, and not every Sellat proof
   has it: here the fingerprint is written into the transaction itself, whereas
   proof.json anchors the root of a batch and gives you the path that links
   your fingerprint to that root. Either one stands on its own.
5. The Bitcoin proof, with an OpenTimestamps client:
     ots verify "anclaje-bitcoin.ots"
   The .ots attests the batch root (the merkle.root field of proof.json), not
   the file directly: the Merkle path is what links your file to that root.

WHAT IT PROVES AND WHAT IT DOES NOT
-----------------------------------
It proves that a file with exactly this SHA-256 fingerprint existed at the
stated times and has not been modified since.
It does not prove who authored or owns the file, nor the content of any
agreement, nor who is right in a dispute.

The qualified timestamp enjoys a legal presumption of the accuracy of the date
and time it indicates and of the integrity of the data it is bound to
(art. 41(2) of Regulation (EU) 910/2014, eIDAS).

The Polygon and Bitcoin anchors are public, independent corroboration:
anyone can look it up without anybody’s permission.

Sellat is neither a trust authority nor an official registry: it is the tool
that created the proof. Everything above can be checked even if Sellat no
longer exists.
