Interactive · runs in your browser · nothing is uploaded

Seal-It

A record is trustworthy when you can tell whether it changed. Seal-It hashes whatever you give it into a SHA-384 Merkle chain, entirely in your browser, then lets you break it: change a single character and the affected leaf, every node above it, and the root all light up at once. Export a small JSON receipt and anyone can re-verify the same input against it later.

SEALED
reference root (receipt)
—
current root
—

Leaves

    Merkle chain

    What a Merkle chain is

    Every record is hashed into a fixed-length fingerprint called a leaf. Pairs of leaves are hashed together, then pairs of those, and so on up to a single value at the top: the root. A hash is one-way and collision-resistant, so a leaf stands in for its record, and the root stands in for the whole ordered set. Because each parent is computed from its children, a change anywhere below the root propagates all the way up — you cannot alter a record, or reorder the set, without changing the root.

    Why one byte breaks it

    SHA-384 is designed so that flipping a single bit of input produces a wholly different, unpredictable output. Change one character of one record and its leaf no longer matches; the parent that was computed from that leaf no longer matches; and so on to the root. The tool highlights exactly that path. This is what “tamper-evident” means: not that tampering is impossible, but that it cannot pass unnoticed.

    The receipt

    A receipt is a small JSON file recording the algorithm (SHA-384), the number of records, every leaf hash, and the root, with a timestamp. It contains no secret and no original content — only fingerprints. Anyone holding the receipt and a copy of the input can recompute the root and confirm, independently, whether the two agree. That is the whole idea behind chain-of-custody for evidence: the record can travel, and its integrity can be checked by anyone, at any time, without trusting the party who produced it.

    This page demonstrates the evidence-integrity concept only. Hashing uses the browser’s built-in Web Crypto API; no input, receipt, or file ever leaves your device.