Security / anchor-spec v2.0.0

How records are hashed, signed, encrypted and anchored

CaseAnchor does not claim certifications it does not hold. What it has is a written specification: how a record is fingerprinted, sealed and stored, and what happens to your data at each step.

Anchor specv2.0.0
See the specification
Technical Architecture

How the data model works

Records are fingerprinted and sealed before they are stored, agreement content is encrypted with the key held outside the application, and what is registered is a fingerprint rather than the content itself.

Hashing and signing

fingerprint and sealed

A finalised agreement is fingerprinted and sealed, so the record you hold can be checked against what was agreed.

fingerprintstandard curve / standard curveencoded assertions

Encryption and key custody

encryption with keys in outside the application

Agreement content is encrypted before it is stored, and the encryption key is held outside the application.

encryptionstreaming encryptionheld outside the app

record register

Commitments, not copies

What gets registered is a fingerprint of the record — not the agreement itself. The agreement stays where it belongs, and what is registered answers whether it exists and whether it has ever been altered.

How records are storedDefined in the specification
①
primary storage
Primary records
Primary
②
records storage
Discussions and files
Payload
③
file storage
Agreements and attachments
Files
④
record register
Append-only register holding commitments only
Commitments
⑤
held outside the app
Encryption key custody
Keys
Need a self-hosted deployment؟ Contact the team