Skip to content
ChainProof

How ChainProof works

The mechanism behind the demo, for the auditor who has to trust it and the developer who has to integrate it.

01

Records and custody

A batch is a chain of records. The first one is the producer's registration; every later record (a handoff, a checkpoint, sealed readings) is signed by the organization that made it and includes the hash of the record before it.

Exactly one organization holds custody at any time. Custody is a pointer on the ledger, and it only moves through the handoff protocol below.

02

The handoff protocol

A handoff is two signatures, not one. The sender signs what leaves: the receiver, the count and the seal number. Until the receiver answers, custody stays with the sender, who can still cancel.

The receiver signs what arrives. Accept when everything matches; accept with an exception when something doesn't (the count, the seal, a temperature flag); refuse and custody stays where it was. Either way, the discrepancy is recorded by the party who saw it, at the moment they saw it.

03

Sealing sensor readings

A logger travels with the batch. Its readings stay off-chain; when the custodian seals them, a single root hash of all readings is anchored in one record.

Any stretch outside the batch's allowed range becomes an excursion record in the same transaction. It cannot be removed. Later parties can add a response, and the next receiver sees the flag before signing.

04

How a label is verified

The QR code carries only the lot code. The passport page fetches the batch's records and re-computes each hash from its content and the previous hash, then compares the result with the hash anchored on-chain.

If anyone edits a record after it was signed (a count, a date, a place), that record and every record after it stop matching. A label whose code isn't on the ledger at all is shown as suspect.

05

What stays private

Only fingerprints go on-chain: record hashes, reading roots, signatures and the custody pointer. Prices, contracts, documents and raw readings stay in each party's systems and can be disclosed selectively to an auditor, who checks them against the anchored hashes.

06

The record format

Every record has the same shape. Integrations (ERP, warehouse scanners, GS1 EPCIS feeds) only need to produce this object and sign its hash.

A handoff record, as stored by the demo
{
  "batchId": "HU-2584",
  "seq": 6,
  "kind": "handoff-accepted",
  "actor": "flv",
  "counterparty": "trc",
  "at": "2026-08-19T11:15:00-04:00",
  "place": "Port of Montréal, QC",
  "data": {
    "count": 60,
    "seal": "MSKU-5531907",
    "sealOk": true
  },
  "prevHash": "0x-27a5f8541ca0fbee-1dbba79a7769292016fb5ec5-fd08638-544ff429-64789a9d",
  "hash": "0x-47cd826d-5255cc4d-1e79c730-41c7dc91-6a95a092-471186d077d97da4-2bda17be",
  "txHash": "0x-b5facfa-5305307e5b64afaa29b7617e7a1052af-30f78950-3ab14306-4d364220",
  "block": 4760575
}
Try it in the demo