original/<archivo> If the original is kept
Your file, byte for byte
The exact photo you sealed, in a folder of its own so no other file in the package can be mistaken for it. It travels inside when the original is available: the upload that created the proof, or custody.
certificado-<id>.pdf Always
The readable certificate
The PDF you show a person or attach to a filing. It is an informative document: what actually gets checked is the file, not the PDF. If the file carried Content Credentials (C2PA), the certificate records them too — who signed, with which tool and whether they declare AI use — exactly as your browser read them when you protected it.
proof.json Once the batch is anchored
The portable proof
Your file fingerprint, its Merkle leaf and inclusion path, the batch root and the public transaction that records it. This is the piece that lets anyone check everything without Sellat.
sello-cualificado-<id>.tsr With a qualified seal
The qualified seal
The RFC 3161 response from the qualified timestamping authority, exactly as it was issued. This is the file that fixes the date under eIDAS.
autoridad-sellado.pem With a qualified seal
Who signed the seal
That authority signing certificate, with its SHA-256 written into the README. It travels inside so the check works offline and nobody has to go looking for it.
anclaje-bitcoin.ots Once the batch is anchored
The Bitcoin anchor
The OpenTimestamps proof of the batch root. It may still be waiting for a block: it is a valid file and whoever receives it can upgrade it themselves.
LEEME.txt / README.txt Always
The instructions, in two languages
What each file is, what it proves and what it does not, and the exact commands to check it. In Spanish and English, so an expert or a lawyer never has to ask you anything.