Long-term preservation
for document hashes
A qualified timestamp proves when a document existed — until the timestamp authority’s certificate expires. TrustBeat keeps that proof verifiable for 30 years: RFC 4998 evidence records, renewed before they expire, designed to ETSI TS 119 511.
Part of Document Anchoring — included on every plan, including Free, with nothing to switch on. You send only the hash — never the document.
30 years
Each document anchor is preserved for 30 years from submission — on every plan, including Free.
RFC 4998 evidence record
Every hash gets a standard evidence record on an eIDAS-qualified timestamp, verifiable with EU DSS.
Renewed before expiry
A new timestamp is added 90 days before the certificate behind the last one expires (RFC 4998 §5.2).
EU Trusted List snapshots
Signed copies of every Trusted List version we load, so a TSA's qualified status on a past date can still be shown.
Export-import package
Download your hashes, evidence records and the Trusted Lists they depend on at any time — no lock-in.
Hash only
You send a SHA-256 hash, never the document. Nothing to leak, nothing to hand over.
Why a timestamp alone is not enough
An RFC 3161 timestamp is verified with the timestamp authority’s certificate. Those certificates last a few years; contracts, invoices, clinical records and source code often have to be provable for decades. Once the certificate has expired, or its algorithms have weakened, a verifier can no longer rely on the timestamp alone.
RFC 4998 solves this with an evidence record: a hash tree over the protected hashes, a timestamp over its root, and a chain of renewal timestamps, each one added while the previous one is still verifiable. ETSI TS 119 511 sets the policy and security requirements for a service that does this over the long term.
How it works
Submit a hash
Your system computes SHA-256 of the document and submits only the hash. The response carries the anchor's identifier.
POST /v1/anchor
{ "hash": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" }Evidence is created
Hashes are batched every 10 minutes into an RFC 4998 hash tree. Its root is timestamped by an EU qualified timestamp authority, and the validation data (certificate path, OCSP or CRL) is embedded.
GET /v1/public/proof/{id}/evidence-record.ers
→ RFC 4998 EvidenceRecord (DER)Evidence is renewed
Before the last timestamp stops being verifiable, a renewal timestamp is added to the record's chain. The status endpoint shows the profile and the end of the preservation period.
GET /v1/anchor/{id}/status
→ "preservation": { "profile": "…/pgd-wst-v1",
"preserve_until": "2056-…" }Validate or export — without us
Validate the record with EU DSS against the EU Trusted Lists, or download an export-import package for up to 31 days of anchors at a time.
GET /v1/preservation/export?from=2026-10-01&to=2026-10-31 → ZIP: manifest + .ers files + signed Trusted Lists
What it is — and what it is not
- Designed to ETSI TS 119 511 — preservation of general data (PGD), with storage (WST), main policy OID 0.4.0.19511.1.1
- Evidence built on qualified electronic timestamps (eIDAS Art. 41) from QTSPs on an EU Trusted List
- Standard formats: RFC 4998 evidence records over RFC 3161 timestamps — no proprietary verifier needed
- Algorithms monitored against ETSI TS 119 312
- Not a qualified preservation service — eIDAS offers that status only for qualified signatures and seals (Art. 34, 40)
- Not assessed by a conformity assessment body (yet)
- Not a document archive — keeping the data and hashing it correctly stays with you
- No deletion before the period ends — each record depends on every hash in its batch
Standards
The binding terms are in Terms of Service §4. Supported preservation profiles are listed at api.trustbeat.eu/v1/preservation/profiles.
Frequently asked questions
Is TrustBeat a qualified preservation service?+
No. The service is designed to ETSI TS 119 511 for the preservation of general data (goal PGD, model WST, policy OID 0.4.0.19511.1.1). eIDAS provides qualified preservation services only for qualified electronic signatures and seals, so qualified status is not available for this goal. The service has not been assessed by a conformity assessment body. The timestamps inside the evidence are qualified electronic timestamps (eIDAS Article 41).
Why does TrustBeat preserve only the hash?+
You never send your data, only its SHA-256 hash, so TrustBeat cannot leak, lose or be compelled to hand over your documents. The evidence proves that the hash existed at a given time. It proves the existence of your data as long as SHA-256 stays collision-resistant and you keep the data the hash was computed from.
What happens when the timestamp authority's certificate expires?+
TrustBeat renews the evidence record with an RFC 4998 time-stamp renewal 90 days before the certificate behind its last timestamp expires, or earlier if ETSI TS 119 312 assesses its algorithms as weakening. The earlier timestamps stay in the record unchanged.
What if SHA-256 becomes weak?+
TrustBeat cannot re-hash data it never received, so it does not offer hash-tree renewal. If SHA-256 is assessed as weakening, TrustBeat will notify you by email and explain whether and how new hash values can be submitted.
How long is evidence kept, and does it survive closing my account?+
30 years from submission, on every plan including the Free plan. Closing your account or ending a subscription does not end the preservation period: the evidence stays retrievable by its identifier from the public endpoints. Download an export-import package first, because you lose authenticated access.
Can I delete a preserved anchor?+
No, not before its preservation period ends. Each evidence record is built from all the hashes in its batch, which belong to many customers; removing one hash would make every other record in that batch unverifiable. The hash reveals nothing about your data.
How do I verify an evidence record without TrustBeat?+
Download the RFC 4998 evidence record (.ers) and validate it with EU DSS, for example the European Commission's DSS demonstration web app, together with your original file. The trust anchors are the EU Trusted Lists; the export-import package also contains the signed Trusted Lists in force at each timestamp.
Which anchors are covered?+
Document anchors submitted on or after 14 September 2026 (UTC) whose batch has an RFC 4998 evidence record. Tamper-Evident Logs, AI decisions and Audit Trail events use the same anchoring but are not covered.
Verify a proof step by step in the manual verification guide.
Ready to anchor your first document?
Start free. No credit card required. Your first 100 hashes are on us.
eIDAS Regulation (EU) No 910/2014 · Art. 41 legal presumption · EU Trusted List QTSP