A log about yourself isn't evidence.
Every record an agent keeps about its own conduct is testimony from an interested party. It can be complete, tamper-proof, beautifully signed — and still be the keeper's own word about the keeper. The one thing a self-issued record cannot manufacture is a second signature from someone with nothing to win. That second signature, hash-chained and anchored so anyone can check it without trusting the keeper, is what Tersign is.
The challenge splits in two
When someone disputes your record, they ask two different questions.
Most "trust" products answer only the first. Answering the first without the second is why a self-hosted audit log, however tamper-evident, does not settle a dispute — the party asking already knows you kept it.
Is it independent?
Was the record made by someone outside the transaction? A third-party catalog or trust-score can clear this bar — it observed you from the outside. Vantage alone is cheap, and it is not enough.
Can I verify it without trusting the keeper?
Is it counter-signed, hash-chained, complete against an unforgeable sequence, and anchored in time — so I can check every claim myself? A published score fails here: to believe it, I still have to trust whoever published it.
Tersign is the only answer that clears both: a neutral counter-signer that is outside your transaction, whose every record you — or a regulator, or the counterparty — can verify without trusting Tersign either. Independence of vantage and independence of verification.
Four properties structure supplies, and independence does not
What a second signature actually has to carry.
These are stated as evaluator-side disqualifications — what a record must not be read as — in the open compliance-fields extension (x402 #2853), and each is executable as a two-sided conformance vector anyone can run.
A signature from a non-party
A record composed and signed only by the payer, the payee, or their operators evidences the shape those parties assert — not that an outside observer would concur. Tersign counter-signs as a party to neither side.
Omission is visible, not just ordering
An issuer-attested sequence proves ordering, never no-omission — quietly drop the failures and the record still looks clean. A counter-signed sequence 1..N under an anchored commitment makes any gap arithmetically visible to anyone.
The clock is not the keeper's to move
A signature proves integrity, not when a record came into being. Tersign anchors chain commitments to Bitcoin: "existed no later than block N" is checkable with public tooling, and block time is not the keeper's to backdate.
/v1/anchors →Funding is not delivery is not settlement
A record of one economic phase says nothing about a later one. A funding receipt is not proof of delivery; a delivery attestation is not proof of settlement. Tersign keeps them distinct so none is misread as another.
Why this is the demand, not a nicety
The obligation is increasingly to demonstrate, not to assert.
Disclosure and conduct rules tell you what you must do. A growing number then ask a second thing: show, to someone who does not have to take your word, that you did it. US broker-dealer record-keeping (SEC 17a-4(f), FINRA 4511) requires preserved, time-stamped, reproducible records today — and since the 2022 amendments a firm may keep them on its own audit-trail systems. The rule sets the duty; it does not make your attestation checkable by the party challenging it. Assurance frameworks are converging on exactly that harder bar — independent verifiability, not self-attestation, is what separates a demonstrated control from a claimed one.
A record you keep about yourself demonstrates your record-keeping. It cannot demonstrate the fact to a party who assumes you are interested — because you are.
Tersign closes exactly that gap: the demonstration a self-kept log structurally cannot provide. We are a data provider, not a law firm — an export pack is formatted for a named regime (Art 50 disclosure, VAT 226b, HK s.51C, MAS SAFR alignment), and its worth is that the reader can verify it independently, not that we certify anything.
Don't trust this page — run it
The genesis record is public. Verify it yourself.
One record on the ledger is public by design. Recover its counter-signature and its position in the chain — no account, no trust in us:
npx tersign verify 0xe5874f1ffe87f0a6dd9eb157730f67b86ee4538b125fe30fcc4e165213dd3fc4 \ --ledger https://tersign.ai
To recompute the content address from raw bytes: curl /v1/genesis returns the record — save its artifact object to a file and npx tersign verify <file> recomputes the digest and recovers the seller's signature fully offline. The stdlib-only conformance suite does the same with no dependency on Tersign at all, and /v1/anchors carries the Bitcoin anchor proof (ots info proof.ots, offline). Verify any receipt →
Independence is the one property structure cannot supply. If your evidence has to survive being held by an interested party, that party cannot be you.
See pricing →