Technical overviewA technology by

Cryptographic assurance, engineered for enterprise trust.

HashOrigin™ is the cryptographic foundation underpinning document integrity across the Twala platform. It combines advanced cryptography, blockchain anchoring, and established digital signature standards to deliver a tamper-evident, independently verifiable chain of trust for every document processed through Twala.

  • SHA
  • ECC
  • Merkle tree
  • X.509
  • TLS 1.3
  • AES-256
Publisher
Twala
Scope
Every document processed through Twala
Assurance
Tamper-evident · independently verifiable

How HashOrigin works

HashOrigin turns every document into verifiable evidence. Five stages each add a layer of assurance — and together they form a tamper-evident chain of trust that anyone can verify independently.

Fig. 01The HashOrigin pipeline, from a document’s fingerprint to independent verification.

Cryptographic Fingerprinting

Every document processed by Twala is assigned a unique cryptographic hash — a fixed-length digital fingerprint generated using Secure Hash Algorithms (SHA). Even the smallest edit produces an entirely different hash, providing a reliable way to confirm that every document remains exactly as intended.

₱1,250,000.00 → ₱7,250,000.00
SHA-256 fingerprint
Original32576d0f790343493746abb37586725c6f65eb3ecfe2e87b406fa81c3d5709e2
Current32576d0f790343493746abb37586725c6f65eb3ecfe2e87b406fa81c3d5709e2
Bits changed0 / 256 (0%)

Fingerprint matches the original

Computed privately in your browser — your text stays on this page.

Fig. 02Live fingerprint. Change a single character and roughly half of the 256 output bits flip — the avalanche effect that makes every change instantly visible.

Digital Signature Integration

Prior to incorporation into the Merkle Tree, every document hash is sealed with Twala’s own digital signature. This platform seal is applied by Twala using Twala’s private key, cryptographically binding every sealed document to the Twala platform. The process is aligned with the requirements of electronic signature laws, including the Philippine Electronic Commerce Act, the Supreme Court Rules on Electronic Evidence, and comparable regulatory frameworks internationally.

The seal certifies that each document was processed through Twala and preserves its integrity, so any modification is immediately detectable.

Seal
Document fingerprintSHA · 5e014c…9e4b
Twala’s private keyECC · held by the Twala platform
Twala platform sealApplied to every document
Verify
Twala’s certificateX.509 · carries Twala’s public key
Recompute & compare5e01…e4b = 5e01…e4b
Seal verifiedSealed by Twala · content intact
Seal verified.
Fig. 03Twala’s platform seal binds each document’s fingerprint to Twala. Verification recomputes the fingerprint and confirms it against the seal using Twala’s public key, so every change is caught instantly.
Aligned with
  • Philippine Electronic Commerce Act (RA 8792)
  • Supreme Court Rules on Electronic Evidence
  • Comparable international e-signature frameworks

Merkle Tree Architecture

To secure these fingerprints at scale, HashOrigin organizes document hashes into a Merkle Tree, a cryptographic structure purpose-built for efficiently validating large volumes of data. Individual document hashes form the base of the tree; these are progressively paired and hashed together to form a single root hash representing a cryptographic summary of all documents within the structure.

This architecture enables the integrity of any single document to be independently verified by tracing it back to the root hash — any change to a document is immediately reflected in the root hash, making it instantly detectable.

Merkle rootab961bc2…bbb5ea
Hash(A+B)64d8a…d64
Hash(C+D)2f823…ff0
Doc Ae39e3d
Doc B80d6f4
Doc C90eafc
Doc D8fb7d0
Anchored rootab961bc2…bbb5ea

Recomputed root matches the anchored root.

Fig. 04Interactive Merkle tree, simplified to four documents (in HashOrigin each leaf is a sealed document hash). Switch scenarios to trace a proof path or to see how an edit is detected.

Blockchain Anchoring

The root hash of each Merkle Tree is recorded on a blockchain — a decentralized, immutable ledger. Once recorded, the root hash is permanent, establishing an enduring and independently auditable chain of trust.

Each root hash is cryptographically linked to the one preceding it, forming a continuously extending chain of custody. As this chain grows, every new root adds to the computational assurance behind the records before it, so document security grows stronger over time.

Immutable ledger Root anchored
  1. Your document’s rootroot79bd4b…6f83prevb93622…15a4
  2. +1
  3. Anchorroot9de72c…dcf3prevf97ade…db3c
  4. Anchorroot11bbb0…b233prev9de72c…dcf3
  5. Newest anchorroot82a80b…eb1cprev11bbb0…b233

4 anchors now reinforce your document’s root — and every new anchor makes it stronger.

Fig. 05Each anchored root carries a reference to the root before it — matching colours show one block’s root reappearing as the next block’s “prev”. Illustrative values.

Underlying Cryptographic Standards

HashOrigin is built on a foundation of internationally recognized cryptographic and digital signature standards, including:

Cryptographic standards used by HashOrigin and the role each one plays
StandardRole in HashOrigin
SHASecure Hash Algorithms (SHA)Tamper-evident document fingerprinting
ECCElliptic Curve Cryptography (ECC)Efficient, secure encryption and signing
CHAINBlockchain cryptographic protocolsGuarantee the immutability of anchored root hashes
PKIDigital signatures (public/private key infrastructure)Seal every document with Twala’s digital signature and ensure legal compliance
X.509X.509 certificate standardsInteroperability with established Public Key Infrastructure (PKI) systems
Platform encryptionTLS 1.3Encryption in transitAES-256Encryption at rest
Table 01The standards HashOrigin is built on, and the role each one plays.

Interoperability with Public Key Infrastructure

While HashOrigin is built on blockchain-based innovation, it remains fully interoperable with traditional PKI systems through support for the widely adopted X.509 certificate standard. As a member of the Cloud Signature Consortium (CSC), Twala adheres to global standards for cloud-based digital signatures, ensuring compatibility with established PKI frameworks and alignment with international regulatory expectations.

Twala’s signatures are designed to be compatible with the Adobe Approved Trust List (AATL), enabling signed documents to display as trusted and verified the moment they are opened in Adobe Acrobat and Adobe Reader — with zero certificate setup for recipients.

Twala also supports Long-Term Validation (LTV), embedding the certificate, revocation status, and timestamp information required to verify a signature’s validity directly within the signed PDF. This ensures that signatures remain independently verifiable long after the signing certificate itself has expired — a critical requirement for documents that must retain legal and evidentiary value over extended periods.

Embedded in the signed PDF

  • Twala’s certificateThe X.509 certificate behind the platform seal
  • Revocation statusProof the certificate was valid when the document was sealed
  • TimestampWhen the seal was applied

Independently verifiable long after the signing certificate expires

Fig. 06What Long-Term Validation embeds in a signed PDF: everything required to verify the signature travels with the document.
  • CSCMember, Cloud Signature Consortium
  • AATLCompatible with the Adobe Approved Trust List
  • LTVLong-Term Validation support
  • X.509Standard PKI certificates

This combination of blockchain anchoring, PKI interoperability, AATL compatibility, and LTV support allows enterprise clients to adopt Twala’s document security while staying fully compatible with existing digital certificate infrastructure and long-term document validity requirements.

Infrastructure & Resilience

Twala’s platform operates on secure, enterprise-grade cloud infrastructure engineered for high availability and operational resilience. The infrastructure strategy incorporates a formal Disaster Recovery Plan and Business Continuity Plan, designed to maintain service continuity and safeguard data integrity.

Recovery capabilities span multiple geographic regions, keeping business-critical operations highly available for enterprise clients.

Region APrimary
Serving
Region BSecondary
Ready
  • Disaster Recovery PlanFormal plan that safeguards data integrity and service continuity
  • Business Continuity PlanKeeps business-critical operations running smoothly
Fig. 07Resilience spans geographically separate regions, backed by formal DR and BC plans. Schematic.

Enterprise Value

HashOrigin delivers a set of assurances designed to meet the standards expected by regulated enterprises:

  • Legal compliance

    Aligned with the Philippine Electronic Commerce Act, Supreme Court Rules on Electronic Evidence, and comparable international electronic signature frameworks.

  • Tamper-evidence

    Every change to a document is immediately detectable, so integrity is always provable.

  • Independent verifiability

    Blockchain anchoring lets any third party verify document integrity independently, directly against the anchored record.

  • Long-term security

    The chained structure of root hashes, combined with LTV support, ensures the integrity and verifiability of records grows stronger over time.

  • Standards interoperability

    Seamless compatibility with blockchain-based, traditional PKI-based, and Adobe-native signature ecosystems.

HashOrigin™ is how Twala secures every document.

Sign, notarize, and manage documents on Twala — each one carries a tamper-evident, independently verifiable HashOrigin chain of trust.

Any further questions? Feel free to reach out.

Contact us