---
title: ProofIt Security, Privacy & File Protection
description: Learn what ProofIt stores, records publicly, retains and deletes, plus access-control practices.
canonical: https://proofit.biz/security
entity: ProofIt
last_updated: 2026-08-12
---

# How ProofIt Protects Files and Evidence

## What stays private

Original files are not published on-chain and are never sent to the Trusted Timestamp Authority. Only hashes and verification metadata go to external timestamping and blockchain systems.

## What can be checked publicly

Certificate IDs can be verified at https://proofit.biz/verify. Blockchain fingerprint records are independently inspectable. Private certificate and file-view pages are not for public search indexing.

## Access controls

Uploads and certificates require authenticated accounts. Certificates may use optional password protection for file access.

## What is stored

Account data, uploaded files (while retained), certificate metadata, SHA-256 hashes, blockchain transaction references, and RFC 3161 timestamp tokens where enabled.

## Retention after cancellation

- Original files: deleted after 30 days
- Certificate records: accessible for 1 year (re-provide the file to verify original content after deletion)
- SHA-256 hash/record: permanent
- TSA evidence: permanent if you retain the token
- Blockchain record: permanent; not reversed on cancel

## Limits

Evidence of existence, time, and integrity is not automatic legal ownership and does not guarantee court acceptance.

Operated by Global Kingdom International Company Limited, Hong Kong.

See also: https://proofit.biz/technology · https://proofit.biz/privacy · https://proofit.biz/how-it-works
