How HashOrigin works
HashOrigin turns every document into verifiable evidence. Five stages each add a layer of assurance — and together they form a tamper-evident chain of trust that anyone can verify independently.
- 01FingerprintEach document gets a unique SHA hash. Change one character and the hash changes completely.
- 02SealTwala seals the hash with its own digital signature, certifying the document exactly as it was processed.
- 03AggregateSealed hashes are paired and hashed into a Merkle tree that resolves to one root hash.
- 04AnchorThe root is recorded on a blockchain, cryptographically linked to the root before it.
- 05VerifyAnyone can recompute a document’s hash and trace it back to the anchored root.
Cryptographic Fingerprinting
Every document processed by Twala is assigned a unique cryptographic hash — a fixed-length digital fingerprint generated using Secure Hash Algorithms (SHA). Even the smallest edit produces an entirely different hash, providing a reliable way to confirm that every document remains exactly as intended.
32576d0f790343493746abb37586725c6f65eb3ecfe2e87b406fa81c3d5709e232576d0f790343493746abb37586725c6f65eb3ecfe2e87b406fa81c3d5709e2Fingerprint matches the original
Computed privately in your browser — your text stays on this page.
Digital Signature Integration
Prior to incorporation into the Merkle Tree, every document hash is sealed with Twala’s own digital signature. This platform seal is applied by Twala using Twala’s private key, cryptographically binding every sealed document to the Twala platform. The process is aligned with the requirements of electronic signature laws, including the Philippine Electronic Commerce Act, the Supreme Court Rules on Electronic Evidence, and comparable regulatory frameworks internationally.
The seal certifies that each document was processed through Twala and preserves its integrity, so any modification is immediately detectable.
- Philippine Electronic Commerce Act (RA 8792)
- Supreme Court Rules on Electronic Evidence
- Comparable international e-signature frameworks
Merkle Tree Architecture
To secure these fingerprints at scale, HashOrigin organizes document hashes into a Merkle Tree, a cryptographic structure purpose-built for efficiently validating large volumes of data. Individual document hashes form the base of the tree; these are progressively paired and hashed together to form a single root hash representing a cryptographic summary of all documents within the structure.
This architecture enables the integrity of any single document to be independently verified by tracing it back to the root hash — any change to a document is immediately reflected in the root hash, making it instantly detectable.
Recomputed root matches the anchored root.
Blockchain Anchoring
The root hash of each Merkle Tree is recorded on a blockchain — a decentralized, immutable ledger. Once recorded, the root hash is permanent, establishing an enduring and independently auditable chain of trust.
Each root hash is cryptographically linked to the one preceding it, forming a continuously extending chain of custody. As this chain grows, every new root adds to the computational assurance behind the records before it, so document security grows stronger over time.
- Your document’s rootroot
79bd4b…6f83prevb93622…15a4 - +1
- Anchorroot
9de72c…dcf3prevf97ade…db3c - Anchorroot
11bbb0…b233prev9de72c…dcf3 - Newest anchorroot
82a80b…eb1cprev11bbb0…b233
4 anchors now reinforce your document’s root — and every new anchor makes it stronger.
Underlying Cryptographic Standards
HashOrigin is built on a foundation of internationally recognized cryptographic and digital signature standards, including:
| Standard | Role in HashOrigin |
|---|---|
| SHASecure Hash Algorithms (SHA) | Tamper-evident document fingerprinting |
| ECCElliptic Curve Cryptography (ECC) | Efficient, secure encryption and signing |
| CHAINBlockchain cryptographic protocols | Guarantee the immutability of anchored root hashes |
| PKIDigital signatures (public/private key infrastructure) | Seal every document with Twala’s digital signature and ensure legal compliance |
| X.509X.509 certificate standards | Interoperability with established Public Key Infrastructure (PKI) systems |
Interoperability with Public Key Infrastructure
While HashOrigin is built on blockchain-based innovation, it remains fully interoperable with traditional PKI systems through support for the widely adopted X.509 certificate standard. As a member of the Cloud Signature Consortium (CSC), Twala adheres to global standards for cloud-based digital signatures, ensuring compatibility with established PKI frameworks and alignment with international regulatory expectations.
Twala’s signatures are designed to be compatible with the Adobe Approved Trust List (AATL), enabling signed documents to display as trusted and verified the moment they are opened in Adobe Acrobat and Adobe Reader — with zero certificate setup for recipients.
Twala also supports Long-Term Validation (LTV), embedding the certificate, revocation status, and timestamp information required to verify a signature’s validity directly within the signed PDF. This ensures that signatures remain independently verifiable long after the signing certificate itself has expired — a critical requirement for documents that must retain legal and evidentiary value over extended periods.
Embedded in the signed PDF
- Twala’s certificateThe X.509 certificate behind the platform seal
- Revocation statusProof the certificate was valid when the document was sealed
- TimestampWhen the seal was applied
Independently verifiable long after the signing certificate expires
- CSCMember, Cloud Signature Consortium
- AATLCompatible with the Adobe Approved Trust List
- LTVLong-Term Validation support
- X.509Standard PKI certificates
This combination of blockchain anchoring, PKI interoperability, AATL compatibility, and LTV support allows enterprise clients to adopt Twala’s document security while staying fully compatible with existing digital certificate infrastructure and long-term document validity requirements.
Infrastructure & Resilience
Twala’s platform operates on secure, enterprise-grade cloud infrastructure engineered for high availability and operational resilience. The infrastructure strategy incorporates a formal Disaster Recovery Plan and Business Continuity Plan, designed to maintain service continuity and safeguard data integrity.
Recovery capabilities span multiple geographic regions, keeping business-critical operations highly available for enterprise clients.
- Disaster Recovery PlanFormal plan that safeguards data integrity and service continuity
- Business Continuity PlanKeeps business-critical operations running smoothly
Enterprise Value
HashOrigin delivers a set of assurances designed to meet the standards expected by regulated enterprises:
Legal compliance
Aligned with the Philippine Electronic Commerce Act, Supreme Court Rules on Electronic Evidence, and comparable international electronic signature frameworks.
Tamper-evidence
Every change to a document is immediately detectable, so integrity is always provable.
Independent verifiability
Blockchain anchoring lets any third party verify document integrity independently, directly against the anchored record.
Long-term security
The chained structure of root hashes, combined with LTV support, ensures the integrity and verifiability of records grows stronger over time.
Standards interoperability
Seamless compatibility with blockchain-based, traditional PKI-based, and Adobe-native signature ecosystems.