How it works

The engineering of trust

What happens when you record a file, why the proof is solid, and how anyone can check it — even without Docmint.

The recording flow

  1. 1

    Hash on your device

    When you pick a file, your browser computes its SHA-256 — a 64-character fingerprint. The file's content is not transmitted.

  2. 2

    Metadata on IPFS

    The hash, title and description you provide form a small public document, published on IPFS, a distributed storage network.

  3. 3

    On-chain record

    We mint a record token (NFT) on our smart contract on Base, an Ethereum layer 2, pointing to that metadata. The token goes to your wallet.

  4. 4

    Block timestamp

    The date and time of the block that included the transaction is the official date of the proof. Nobody — not even Docmint — can change it.

Avalanche effect

A hash isn't random: it's computed from every bit of the file. Changing one comma yields a completely different result, and it's practically impossible to craft another file with the same hash.

What keeps or breaks the hash

Change the hash

  • Editing the content, however small the change
  • Opening and saving again in editors (Word, Photoshop, Acrobat), which rewrite internal metadata
  • Compressing or converting, including sending as media on messaging apps or online compressors

Keep the hash

  • Renaming the file
  • Opening it just to view
  • Copying, moving or backing it up
  • Sending it as an email attachment or as a “document” in messengers

Batch records

When you record several files together, we hash each one and arrange them in a Merkle tree. Only the tree's root goes into the transaction — more efficient and equally secure.

Each file gets its own Merkle proof, included in the public metadata and in the receipt. With it, any file in the batch can be verified on its own, without exposing the others.

root (on-chain)hash(A+B)hash(A+B)file 1file 2file 3file 4

Independent verification

The proof doesn't depend on our website. With the original file and the receipt, any expert can confirm the record using public tools:

  1. 01Compute the original file's SHA-256 (Windows, then macOS/Linux):certutil -hashfile file.pdf SHA256 shasum -a 256 file.pdf
  2. 02Open the token listed on the receipt in the network explorer (BaseScan) and read the contract's tokenURI.
  3. 03Open the metadata on IPFS and check that the hash matches. For batches, validate the Merkle proof against the root.
  4. 04The transaction's block date is the proof's timestamp.

Best practices

  • Keep the original file in its own folder (e.g. “Recorded originals”) and back it up.
  • Always work on copies; never edit the recorded original.
  • Download the PDF receipt and keep it with the file.
  • Write titles and descriptions without sensitive data — they are public.