The fingerprint identifies the file
SHA-256 turns any file into a fixed string. Two different files give different fingerprints, and changing a single byte changes the whole fingerprint. The file cannot be rebuilt from it.
Proof of existence
Sellat records your file’s fingerprint, anchors it in public networks and hands you a proof that is checked with open tools, without relying on Sellat.
We take you to the tool: you choose the file and receive the proof by email.
What it is
A proof of existence answers a single question: did these exact bytes already exist before this moment?
SHA-256 turns any file into a fixed string. Two different files give different fingerprints, and changing a single byte changes the whole fingerprint. The file cannot be rebuilt from it.
That fingerprint is recorded in public networks nobody can rewrite after the fact. From then on the date does not depend on trusting Sellat, nor on Sellat still existing.
You receive a proof.json with everything needed to verify: the fingerprint, the Merkle path to the anchored root and the public references. The verifier is open source.
Inside the package
Not a promise and not a screenshot: the real list of files Sellat puts in your ZIP. What you see here is generated by the same module that builds the package.
original/<archivo> If the original is kept The exact photo you sealed, in a folder of its own so no other file in the package can be mistaken for it. It travels inside when the original is available: the upload that created the proof, or custody.
certificado-<id>.pdf Always The PDF you show a person or attach to a filing. It is an informative document: what actually gets checked is the file, not the PDF. If the file carried Content Credentials (C2PA), the certificate records them too — who signed, with which tool and whether they declare AI use — exactly as your browser read them when you protected it.
proof.json Once the batch is anchored Your file fingerprint, its Merkle leaf and inclusion path, the batch root and the public transaction that records it. This is the piece that lets anyone check everything without Sellat.
sello-cualificado-<id>.tsr With a qualified seal The RFC 3161 response from the qualified timestamping authority, exactly as it was issued. This is the file that fixes the date under eIDAS.
autoridad-sellado.pem With a qualified seal That authority signing certificate, with its SHA-256 written into the README. It travels inside so the check works offline and nobody has to go looking for it.
anclaje-bitcoin.ots Once the batch is anchored The OpenTimestamps proof of the batch root. It may still be waiting for a block: it is a valid file and whoever receives it can upgrade it themselves.
LEEME.txt / README.txt Always What each file is, what it proves and what it does not, and the exact commands to check it. In Spanish and English, so an expert or a lawyer never has to ask you anything.
With the seal and the authority certificate inside the ZIP, the date is verified with standard tools on the machine of whoever receives it. If Sellat disappeared tomorrow, your package would still check out.
The package proves that this exact file existed on that date and has not been modified. It does not prove who created it, who took the photo, or what happened in front of the camera.
How it works
The original is not needed to prove anything: its fingerprint is enough.
A document, a design, a dataset, a build, an export: anything that is a file.
The fingerprint joins a batch, the batch is anchored in public networks and your proof keeps the path that links the two.
With the proof.json and the open verifier, or by looking the anchor up directly in the public network.
With a free account you can use Sellat Local: the fingerprint is computed on your device and the original file is not uploaded at any point.
The layers
Saying “timestamp” on its own is not enough: several times coexist in one proof, and each means something different.
The time the proof was accepted. It is our own record and on its own proves nothing to third parties.
Your fingerprint is grouped with others in a tree. The root is what gets anchored; the path from your fingerprint to that root travels in your proof.
The root is written in a public transaction. The time that counts is the block’s, and it is shown only once confirmed.
The same anchor, aggregated and confirmed in Bitcoin. It takes longer, and until it confirms it is reported as pending rather than taken as done.
The optional layer: a qualified authority signs the time over your fingerprint and adds a legal presumption across the EU.
Scope
That these exact bytes existed before the moment of the anchor, and that they have not changed since. It is proof of priority and integrity, checkable by anyone.
It does not prove authorship or ownership, it does not prove that the content is true, and it does not say when the file was created: the time it records is the anchor’s, not the file’s.
Price
Creating the proof, the public anchor and the certificate cost nothing. The qualified timestamp is the only layer you pay for. Your first qualified timestamp is free. One per account, on the proof you choose. After that, €6 per timestamp.
If you need a legal presumption, add a qualified timestamp issued by the FNMT-RCM: the first one is free → Create a proof of existenceFrequently asked questions
That an exact content already existed before a given moment. It does not say who made it or whether what it contains is true: it says that these bytes, and no others, were there before that date.
For the proof, no: all that is needed is its fingerprint. Without an account the file is uploaded so that the certificate and the package can be generated for you; with a free account, Sellat Local computes the fingerprint on your device and the original does not leave it.
The proof can still be verified. The proof.json holds the data needed and the anchor is in public networks we do not control; the verifier is open source and does not call our servers.
OpenTimestamps is one of the layers Sellat uses to anchor in Bitcoin. The difference is what surrounds it: the readable certificate, the evidence package, public verification and the option of the qualified timestamp.
Against a third party, the one that does not depend on us: the block in which the root was anchored. The record time is internal and the proof says so. With a qualified timestamp you also have the time signed by the authority.
No. It proves priority and integrity, which is often what a claim needs to stand on, but it does not attribute the work to anyone. Whoever claims otherwise is promising too much.
That is why the engine works in batches. The API accepts fingerprints in volume and returns an individual proof for each one, without sending the originals.
You will see the proof, the anchor and the verifier working in under a minute.
Create a proof of existence