How it Works

Where identity, traceability, and qualified evidence connect.

Most organizations already have identity systems, traceability platforms, and data management infrastructure. None of these, alone or combined, answers the question that regulators and courts ask: which legal entity committed to this exact content, when, and has it changed?

Cryptar connects these layers at the content attribution level, extending qualified non-repudiation for documents and data across versions. Digital Product Passports under ESPR are among the most demanding current implementations. The same architecture applies wherever a digital claim carries legal consequence: across regulated filings, contractual commitments, and cross-border accountability.

Where this matters

Regulatory product compliance

Battery Passport, electronics, textiles, construction: each delegated act requires attributable, verifiable evidence. Recycled content claims, PCF calculations, and material declarations carry the same requirement.

Supply chain accountability

Supplier declarations, material origin attestations, and test reports sealed under each contributing party's legal entity identity. Verifiable at point of receipt, protected against alteration and substitution fraud.

Document validity lifecycle

Approvals, licences, and certifications require qualified proof of current status and withdrawal. Recipients verify validity without contacting the issuer. Superseded documents cannot be presented as current without detection.

Connected assets & data attribution

As digital twins and connected devices accumulate data, it must be attributed to the responsible legal entity. Cryptar adds that attribution and immutable proof without modifying submodel structures.

Cross-border commitments

Where bilateral recognition exists between qualified frameworks, the same evidence record delivers enforceable non-repudiation across jurisdictions from a single record, without structural change.

Long-life records & regulated filings

Building material declarations, end-of-life documentation, and regulated filings must outlast platforms and supplier relationships. Cryptar's portable evidence remains valid independent of any single infrastructure choice.

Layers

Different layers answer different questions.

Connecting them delivers what none provides independently: qualified proof of the full data lifecycle: from the moment of commitment to the withdrawal of validity.

1

Identity & authorization

(EUDI Wallet / LPID / LEI)

Question

Who is acting

What it does

Establishes who is acting and authorized. Does not bind content to a legal entity.

2

Traceability

(EPCIS-based systems)

Question

What moved

What it does

Records what moved where and when. Does not create the content attribution non-repudiation requires.

3

Legal presumption

(QTSP)

Question

The qualifying anchor

What it does

Qualified seals via accredited QTSP establish the legal presumption of integrity and origin under eIDAS Art. 35(2) or equivalent.

4

Qualified content evidence

(Cryptar)

Question

What that entity committed to, legally

What it does

Answers what exact content a legal entity committed to, when, and whether it has changed.

Process

The core technical flow

1

Fingerprint

Every document or data record receives a cryptographic fingerprint that locks its exact content and version state.

2

Sign and chain

Each fingerprint is signed under an x.509 certificate and linked to the previous record, establishing local technical attribution. The chain is tamper-evident and auditable from any point.

3

Anchor

The chain is anchored asynchronously into one or more trust registries: a qSeal or equivalent for legal non-repudiation, a blockchain for public verifiability, a TSA timestamp, or any combination.

4

Apply at the right moments

Anchoring at publication events, third-party inputs, and regulatory submissions keeps economics viable at volume while delivering the legal presumption where it matters.

5

Verify anywhere

The proof travels with the document or data record. Each party verifies against their relevant trust anchor, without platform access.

Capabilities

Core capabilities

U.S. & EU patented

Integrity Layer

Cryptographic fingerprint of exact content states, bound to issuer identity, timestamp, and version status. Current, superseded, and withdrawn states are cryptographically distinguished, providing qualified proof of the full content lifecycle.

Tamper-Evident Audit Trail

Every declaration, certificate, and attestation generates a cryptographic record with legally accepted immutability. No data is held by Cryptar. Only the proof of what existed, when, and under whose authority.

Qualified Sealing

Cryptar integrates with QTSP backends (primary: Swisscom Trust Services, CIR 2025/2160) to enable the legal presumption of integrity and origin at content level under eIDAS Art. 35(2) and equivalent qualified frameworks.

Non-repudiation at Scale

Local x.509 signatures consolidate into a qSeal at configurable intervals. Qualified non-repudiation for every event inside it, at sub-cent cost.

Access Control & Confidentiality

Granular access control across documents and consolidated dataset views via access token. Sensitive datasets stay local; only verifiable references travel to each audience.

Verifiable Selective Disclosure

Privacy-preserving (salted) fingerprints allow restricted datasets to remain local. The evidence record carries only cryptographic references for integrity verification.

What Cryptar is not

Not a vertical application

Cryptar connects to existing platforms via API and adds legally accepted immutability and optionally qualified non-repudiation to whatever they manage. No rip-and-replace.

Not an identity provider

Identity infrastructure establishes who is acting. Cryptar extends that value by binding the exact content of every claim or transaction to the authenticated identity with qualified legal effect.

Not track and trace

Traceability systems record what moved where and when. Cryptar adds content-level attribution and qualified evidence to the same events, giving every record legal-grade provability. Complementary, not competing.

Not a blockchain solution

Cryptar is PKI-first. Distributed ledgers do not attribute content to a legal entity with legal effect. Cryptar adds that layer, with simultaneous anchoring into multiple chains and qualified trust services, each holding the others accountable, scaling trust across networks and jurisdictions.

Compliance

Built to complement recognized frameworks

ESPR (EU 2024/1781) incl. CEN prEN 18239 & 18246 / ESDC

What it requires

Authentic, reliable, verifiable product data; non-repudiation at access and content level

How Cryptar delivers

Attributable content binding + version proof + qualified update receipts + cryptographic audit trail per ESDC

eIDAS: qualified trust services (Art. 35(2), CIR 2025/2160)

What it requires

Legal presumption of integrity & origin; burden-of-proof shift; cross-border EU recognition

How Cryptar delivers

Qualified seals via QTSP backend (Swisscom Trust Services); eIDAS-accredited remote QTSP integration

ETSI EN 319 series

What it requires

High-assurance trust-service security and conformity

How Cryptar delivers

Architecture aligned with ETSI trust-service standards

Global equivalents

What it requires

Comparable qualified frameworks in key trade partner jurisdictions

How Cryptar delivers

ZertES (CH) · UK eIDAS QES/QSeal · ESIGN/UETA + NIST SP 800-63 (USA) · ICP-Brasil · Japan ESA 2001 · South Korea ESA rev. 2020 · Turkey 5070

Compatible with DPP platforms, ERP/PLM systems, EPCIS-based traceability, identity layers, and Asset Administration Shell (AAS / IEC 63278) environments. Standard outputs: W3C Verifiable Credentials and GS1 EPCIS.

Cross-border non-repudiation

Cryptar anchors the same evidence record into multiple trust registries simultaneously. Where bilateral recognition exists between qualified frameworks (the EU-India digital seal cooperation among them), enforceable non-repudiation applies in both jurisdictions from a single record. In cross-border transactions where legal rights are otherwise hard to enforce, composable anchoring provides evidential security single-jurisdiction architectures cannot match.

Transformation

What changes in practice

The shift from reconstruction to retrieval. From burden of proof to presumption of integrity.

Before

Audit response requires manually reconciling logs, screenshots, and version histories across systems.

After

Evidence remains verifiable even if the platform changes or vendor disappears. Audit response becomes retrieval, not reconstruction.

Before

When supplier data is contested, the manufacturer carries the burden of proving what was submitted, by whom.

After

Qualified seals under eIDAS Art. 35(2) bind each claim to its originating entity. The burden shifts to the challenger.

Before

Superseded documents circulate undetected. Recipients cannot verify they hold the current version.

After

Every version carries qualified proof of its status and a cryptographic record of when it was superseded. Outdated versions are immediately identifiable.

Before

Printouts fall outside the digital trust chain. Alterations and version substitutions go undetected.

After

The QR code bridges the physical system break. Recipients retrieve the sealed digital original from a printout scan. Alterations break the cryptographic fingerprint and are detected on verification.

See how the trust and control layer fits your architecture.

Talk to Cryptar about a focused 30-minute architecture review. Bring your stack and compliance context: DPP architecture, supplier declarations, regulated filings, and the accountability requirement you are addressing. Cryptar maps where the trust and control layer fits and what it takes to connect.