Sigillum

Dynamic Sites Engine → Vellum

Vellum — document provenance

Proof that a document has not changed.

Vellum seals engineering and quality records into a bundle, signs that bundle with your organisation's key, and gives anyone who receives it a way to check both — without access to your systems or ours.

Seal record Signature valid
Bundle digest
e3f1a7c92b4d0865fa17c30e9d2b5481c6ae70f3b9d84c2517ae6b0f34d91c02
Issuer
Example Manufacturing Ltd
Key
a41f9c72e8b03d16 · Ed25519
Files sealed
14

Illustrative record. A real seal is checked against the issuer's published key, not against this page.

How it works

Three steps, in order, each one checkable on its own.

01 — Seal

Fix the contents

Your documents are gathered into a bundle and a digest is taken over it. Change one byte afterwards and the digest no longer matches.

02 — Sign

Attach your identity

The sealed bundle is signed with your organisation's key. The signature says who issued this bundle, not merely that it exists.

03 — Verify

Let the recipient check

Anyone holding the bundle can confirm the contents and the issuer. Verification needs no account and no access to your systems.

Why it matters

A certificate is only worth the trust placed in the copy you received.

For the issuer

Quality records leave your hands and are forwarded, re-saved and re-sent. A sealed bundle stays checkable through every one of those hops, so a document claiming to come from you can be shown to have come from you.

For the recipient

An auditor, a customer or a regulator can test the document in front of them rather than trusting its route. Failure is explicit: a bundle that has been altered does not verify, and says so.

Underneath

Vellum is the engine pointed at controlled documents.

The same gate, one domain

Every claim Vellum publishes traces to the manufacturer's own controlled documents, and anything that cannot be traced is dropped rather than softened. That behaviour is not Vellum's — it belongs to the engine underneath, which other applications share.

Where it sits

Vellum is one application of the Dynamic Sites Engine. The same gate, pointed at published standards and issued certificates, becomes quality-system conformance; pointed at issuer registers, it becomes provenance-ranked discovery.

How the engine works · Where else it applies

Availability

Vellum comes in two editions.

Both seal the same way and produce the same kind of record. The difference is where your documents go, and what a stranger reading the record can be told.

Hosted

Where it runs
Your browser, at vellum.sigillum.uk
Getting it
Sign in, nothing to install
Extraction
Cell contents are read by a model on our service
With no network
Not available
What a reader is told
Your enrolled key confirms the issuer, so the record reads verified
Independent timestamp
On every signed record
A link you can share
Yes, a public address anyone can open

Desktop

Where it runs
Your own Windows machine
Getting it
Download and install
Extraction
Optional, under your own Anthropic key. Or seal with no extraction at all, and nothing leaves the machine.
With no network
Seal, sign, verify and read all work
What a reader is told
The signature is valid and the issuer name is self-asserted: stated by you, confirmed by nobody
Independent timestamp
Optional, and needs a connection at the moment you seal
A link you can share
No, the record is readable on that machine

The installer hash is published beside the download. If you are evaluating Vellum for a regulated process and want to talk it through first, write to [email protected].