Architecture
How ProofFlow works
Why storing hashes — instead of files — protects privacy while preserving verifiability.
01
Your data
A file or text record on your device. It never leaves the browser — no upload, no server copy.
OFF-CHAIN · PRIVATE02
Browser SHA-256
WebCrypto digests the bytes locally into a 256-bit fingerprint. Same input → same hash, always.
LOCAL COMPUTE03
Smart contract
createProof(dataHash, label) stores the fingerprint + timestamp + your address. Duplicates are rejected.
ON-CHAIN · MINIMAL04
Public verification
Anyone re-hashes the original and compares it with the anchored proof. Math, not trust.
OPEN · PERMISSIONLESSWhy is a blockchain actually necessary?
- Timestamping without a trusted party. A database admin can backdate rows; a public chain's ordering is secured by thousands of independent validators.
- Censorship-resistant availability. The fingerprint + timestamp survive even if ProofFlow's own servers disappear — anyone can query the contract.
- Binding identity to data. The creator address in the anchor proves which wallet committed to which bytes at which time.
Anything a centralized timestamping service can do cheaper is done off-chain here. The chain stores the one thing only it can provide: an immutable, publicly-ordered commitment.
Why hashes protect privacy
- One-way. SHA-256 can't be reversed — the fingerprint reveals nothing about the document.
- Avalanche effect. Flipping one bit changes ~half the digest, so tampering is always detectable.
- Deterministic. Anyone with the original reproduces the exact same hash — that's what makes independent verification possible.
sha256(any_bytes) → 32 bytes → anchored
raw file → never on-chain
raw file → never on-chain
Security boundaries (read before demoing)
- “Transaction confirmed” = the anchor reached the chain. “Verified” = the re-computed hash additionally matches. ProofFlow never conflates them.
- Nothing shown as blockchain-confirmed comes from mock data — demo records are always labeled DEMO DATA.
- File size is capped at 25 MB, inputs are validated, private keys never enter the app, and secrets live only in server-side env vars.