Protect files
Create a verifiable proof in seconds.
Select the files you want to protect. Sellat calculates each exact fingerprint and creates its proof.
The file never leaves your browser. Only the SHA-256 fingerprint is sent.
To protect several files at once you need to sign in.
Sign inTo use Sellat Local you need to sign in. This keeps the seal saved in your account.
Sign inWhat happens next
What you receive once the proof is ready.
The proof identifies the exact version of the file. Keep what you receive: it is what lets you check it later.
- 01
A certificate with the proof data
It includes the file name, its SHA-256 fingerprint, the moment Sellat created the proof and the record reference.
- 02
A verification ZIP by email
It contains the exact file that was protected. That is the safest thing to keep: a re-exported copy can have a different fingerprint.
- 03
The ability to check it whenever you want
Anyone can verify a file or the ZIP and check whether it matches the proof exactly.
Frequently asked questions
Before you ask.
Which file should I keep as proof?
Keep the Sellat ZIP: its "original" folder holds the exact version that was sealed, and that is what lets you check the proof. Bear in mind that a screenshot, a format conversion or forwarding through an app that recompresses images produces a different file with a different fingerprint. Your Sellat record still exists, but checking it needs the exact version, not the transformed copy. On mobile devices, especially iPhone, a photo can be converted when shared; in PDFs and documents, Word or Acrobat can rewrite metadata even if the file looks visually the same.
What does the Sellat verification ZIP contain?
The exact file that was sealed (in the "original" folder), the PDF certificate and a README with the instructions to check it. Once the batch is anchored the package also carries proof.json — the portable proof with the Merkle path — and, where they exist, the OpenTimestamps Bitcoin proof and the qualified timestamp. To check the proof, upload the full ZIP to sellat.app/en/verify and select “Sellat ZIP”.
Why can verification fail if I use a loose copy of the file?
When verifying, the file must be exactly the same as the one that was sealed. Some phones and programs like Word, Acrobat or photo editors can convert files, recompress images or change metadata when opening them. Even if they look visually the same, the hash changes and no longer matches. That is why we recommend verifying with the Sellat ZIP: renaming it, moving it or re-compressing it does not affect the proof; modifying the sealed file does.
Can anyone see my file?
It depends on the mode. In the normal flow the file is uploaded to Sellat only to calculate its SHA-256 fingerprint and prepare the proof; afterwards it is not retained. With a free account, Sellat Local calculates the fingerprint on your own device and the original is never uploaded. And if you turn on custody — optional, and only with an account — Sellat does keep the original, checked against its fingerprint, until you remove it. In all three cases the only thing in the public record is the hash, a code that cannot be used to read or rebuild the content.
What happens if I do not receive the email or I lose the ZIP?
The PDF certificate and proof.json can be downloaded again any time from your certificate page, and the complete package from your account. The original file cannot: in the normal flow Sellat does not keep it, so that exact copy is yours to keep (unless you turned on custody). If the email does not arrive, contact us so we can review the case.
Can I add the qualified timestamp to several files at once?
No. Each qualified timestamp is issued over the fingerprint of a single file, so when you protect several files at once the timestamp is switched off. You can add it afterwards, file by file, from each file’s certificate page.
Can I timestamp a ZIP with all the photos?
Yes. A ZIP is a single file, so you can protect it and add the qualified timestamp to it. Bear in mind what that means: the fingerprint and the timestamp belong to the ZIP, not to each photo. The certificate will name the ZIP and its fingerprint, not its contents; to prove one photo you will have to produce the whole ZIP and have it checked that it contains it. And keep exactly that ZIP: compressing the same photos again produces a file with a different fingerprint. To check it at sellat.app/verify, upload it with the “Upload exact sealed file” option, not as a Sellat ZIP.
What does the qualified timestamp add?
A qualified electronic timestamp issued by the FNMT-RCM (Fábrica Nacional de Moneda y Timbre), a qualified trust service provider under Regulation (EU) 910/2014 (eIDAS). It enjoys a legal presumption of the accuracy of the date and time it indicates and of the integrity of the data it is bound to (art. 41.2), across the European Union. It is issued over your file’s SHA-256 fingerprint and included in your proof; anyone can verify it with standard tools (RFC 3161) against the EU trusted list, without relying on Sellat. It does not attest who the author or owner of the file is, nor the content of any agreement: it attests that this exact file existed at that moment.