Zero-Storage Policy

Không lưu nội dung tài liệu gốc trong Registry.

Trong flow sign-and-stamp hiện tại, client gửi document_hash cùng metadata. Database lưu fingerprint và metadata để tạo Evidence; original file bytes không được insert vào bảng documents. Đây là “zero-storage cho content”, không phải “zero data”.

SHA-256Metadata onlyOTS proof ≠ original file

Lưu gì?

  • document_hash
  • file_name / file_size
  • author_metadata
  • identity/key fingerprints
  • Evidence events / status

Không lưu gì?

  • Raw content bytes của file gốc trong bảng documents.
  • File gốc trong Evidence Package.
  • Private key của người dùng trong public artifact.
Important distinction

Zero-Storage không có nghĩa là “không có artifact”.

PAdES PDF

Certificate PDF được tạo để phục vụ verification, và hash của PDF được ghi vào Evidence metadata.

OTS proof

Proof nhỏ của timestamp có lifecycle riêng. Khi đủ điều kiện, proof có thể được stage lên R2 với signed URL và retention.

Operational logs

Audit/admin logs vẫn tồn tại để vận hành và truy vết. Privacy policy cần mô tả retention của từng nhóm.

User verification model

Verifier tự giữ file gốc.

Muốn chứng minh một file khớp Evidence, verifier tính SHA-256 của file đang có và so với hash public. Registry không cần nhận lại content bytes chỉ để thực hiện phép so sánh.

# Local verification
sha256sum your-file.pdf

# Compare with public evidence
SHA256 == evidence.document.sha256

# Then verify
public-key → signature → timestamps → OTS → package inventory