External chain-head anchoring
Proofroom's hash chain proves that recorded rows were not altered after they were written. It does not, by itself, prove the whole chain was not deleted and rebuilt, because we control ingestion, storage and verification.
Once a day (and on demand) we publish a Merkle-rooted manifest of every chain
head to the public repository
proofroom-anchors. Subjects
are SHA-256 digests of each room's public id (slug), so private and unclaimed
rooms are never named. Public rooms also list their slug for convenience. When
OpenTimestamps calendars are reachable, the Merkle root is stamped and the
.ots proof is stored beside the day's file.
How to check a room independently
See the live guide at /verify. In short: take the room's head hash, hash the public id, find the entry in the anchors repo, confirm the git commit timestamp, and optionally verify the OpenTimestamps proof.
Honest limitation
External anchoring proves this chain head existed at the anchor time. It bounds any retrospective alteration to the period since the last anchor. It does not prove that events recorded before an anchor were genuine at the moment they were reported.
Never repair
If a stored row was wrong, Proofroom does not rewrite hashes to make the chain
look continuous. Corrections append forward. An explained discontinuity may
appear as chain_broken_explained with a published correction_recorded. An
older anchor can be honest history for a head that no longer matches after an
irreversible past mistake; see /verify.
Related
- Live guide: /verify
- Scope as commitment: /docs/scope-and-drift
- Signed Action Receipts (offline receipt checks)
- Open schemas: proofroom-anchors/schema
- Platform intake incidents: /status