External chain-head anchoring

Proofroom's hash chain proves that recorded rows were not altered after they were written. It does not, by itself, prove the whole chain was not deleted and rebuilt, because we control ingestion, storage and verification.

Once a day (and on demand) we publish a Merkle-rooted manifest of every chain head to the public repository proofroom-anchors. Subjects are SHA-256 digests of each room's public id (slug), so private and unclaimed rooms are never named. Public rooms also list their slug for convenience. When OpenTimestamps calendars are reachable, the Merkle root is stamped and the .ots proof is stored beside the day's file.

How to check a room independently

See the live guide at /verify. In short: take the room's head hash, hash the public id, find the entry in the anchors repo, confirm the git commit timestamp, and optionally verify the OpenTimestamps proof.

Honest limitation

External anchoring proves this chain head existed at the anchor time. It bounds any retrospective alteration to the period since the last anchor. It does not prove that events recorded before an anchor were genuine at the moment they were reported.

Never repair

If a stored row was wrong, Proofroom does not rewrite hashes to make the chain look continuous. Corrections append forward. An explained discontinuity may appear as chain_broken_explained with a published correction_recorded. An older anchor can be honest history for a head that no longer matches after an irreversible past mistake; see /verify.

Related