Skip to main content
BitProvenance

self-hosted evidence layer · available now · demos on request

Proof that travels with the data.

BitProvenance binds a commercial dataset’s integrity, declared lineage, quality evidence, and producer identity into a portable data passport a buyer can verify independently — while raw data stays inside your environment.

customer environment · private

  1. v1 · source extract

    root 9c41…e07b
  2. anonymize · signed
  3. v2 · anonymized

    root 4d88…12af
  4. aggregate · signed
  5. v3 · delivered dataset

    root a3f2…91c4

Checkpoint

c c7d1…08aa

many records, one commitment

commitment only — no data crosses

Data passport

  • integrity evidence
  • declared lineage
  • quality results
  • privacy assessment
  • producer signatures

travels with the delivered dataset

checkpoint root

bitcoin block

Anchored checkpoint

t 2026-04-30 11:02Z

one transaction anchors many records

Buyer verifies independently

re-computes the delivered dataset’s root, checks signatures and Bitcoin inclusion — matches the committed root ✓

Illustrative — how a data passport is assembled inside the owner’s environment and anchored to Bitcoin. Hashes are examples, not real commitments.

the trust gap

Data products are sold on trust that neither side can demonstrate.

Valuable datasets change hands on the strength of documents and contracts. Neither side can point to evidence that binds the claims to the exact data delivered.

If you sell data

You can’t demonstrate the history and controls behind a dataset without opening up the private systems it came from. The stronger your governance, the more frustrating it is that buyers can’t see it.

If you buy data

You receive files, documentation, and contractual assurances — and almost nothing you can verify independently. Diligence means taking the seller’s word for how the data was sourced and prepared.

where the evidence breaks down

  • Quality reports and lineage live in documents that drift apart from the exact dataset that was delivered.

  • Provenance records can be rewritten after a dispute begins — and it is hard to show that they weren't.

  • A dataset can be modified or silently re-exported after it was evaluated, with nothing binding the file to its review.

  • Generic “blockchain verified” badges often claim far more than what was actually proven.

the workflow

How BitProvenance works

BitProvenance is built around one ordered sequence. Each step produces evidence the next step builds on.

  1. step 01 / 05

    Capture locally

    A self-hosted engine runs inside your environment and observes declared sources, transformations, schemas, and checks as your pipelines run. Nothing is sent out to be watched.

  2. step 02 / 05

    Commit each version

    Deterministic commitments bind every dataset state and signed provenance event into a hash-linked, tamper-evident record — without publishing the data itself.

  3. step 03 / 05

    Assemble the passport

    The evidence relevant to one data product — integrity commitments, declared lineage, quality results, privacy assessments, and signatures — is packaged into a portable passport that travels with the delivered dataset.

  4. step 04 / 05

    Anchor the checkpoint

    Many records aggregate into one minimal checkpoint commitment, and that single value is anchored to Bitcoin. One transaction can anchor an entire history; no data, names, or schemas go on-chain.

  5. step 05 / 05

    Verify independently

    A recipient re-computes the delivered dataset's commitment and checks the signatures, the evidence chain, and the Bitcoin inclusion proof — without needing access to your systems or an account with us.

evidence boundaries

What a data passport can prove — and what it can’t

Different claims rest on different evidence. A passport shows the strength and source of each one, instead of hiding everything behind a single “verified” badge.

Cryptographically verifiable

Anyone with the passport can check these mathematically.

  • The delivered file matches the committed dataset state

    deterministic hash + Merkle verification

  • The evidence chain was not altered after commitment

    signed, hash-linked provenance records

  • The producer stands behind each record

    cryptographic signatures over every event

  • The commitment existed by a point in time

    Bitcoin anchor + inclusion proof

Supported by attestations and assessments

These rest on people and process — named, signed, and bound to the dataset, but not reducible to math.

  • The source was authentic operational data

    chain of custody + producer or auditor attestation

  • The dataset resulted from the declared transformations

    reproduction, controlled execution, or independent attestation

  • Quality and privacy assessments were performed

    assessment reports bound into the passport

  • The data is legally anonymized and saleable

    privacy assessment + legal governance — never a hash alone

A Bitcoin timestamp proves a commitment existed by a point in time — it does not prove the committed claim is true. BitProvenance is designed to keep that boundary visible, so “verified” always means something specific: which claim, checked against which evidence, asserted by whom.

privacy & deployment

Your data stays where it is. Only proof moves.

The engine runs self-hosted, inside your infrastructure. Evidence is created where the data lives — it doesn't have to be shipped somewhere to be trusted.

Passports are portable and designed for independent verification: a recipient can check one without a BitProvenance account, and exported evidence remains verifiable even if BitProvenance is unavailable in the future.

designed to stay in your environment

  • Raw records, schemas, and credentials
  • Transformation logic and pipeline details
  • Full provenance records and evidence packages
  • Signing keys, under customer custody

leaves for anchoring — nothing else is required

  • One blinded, aggregate checkpoint commitment — a short hash that reveals nothing about the data behind it

No personal data, customer names, dataset names, schemas, or row-level hashes belong on Bitcoin — ever.

who it's for

Built around three sides of every data transaction

data owners & sellers

Turn internal data into a product buyers can trust

Package operational datasets with evidence of how they were prepared — without exposing the private systems behind them. The outcome: faster diligence, stronger positioning against unverifiable alternatives.

data buyers

Verify what you received before you build on it

Check that a delivery matches the state its evidence describes, see the declared lineage, and inspect who attested to what. The outcome: clearer disputes and fewer surprises in datasets feeding analytics or AI training.

auditors & governance

Review one consistent, tamper-evident evidence package

Work from signed, hash-linked records instead of screenshots and spreadsheets, and add independent attestations that strengthen a passport's assurance level. The outcome: portable chain of custody your clients can hand to their counterparties.

design partners

Help define what proof should look like

BitProvenance is built alongside organizations that create, acquire, or audit valuable datasets. The evidence model comes from real transactions, not from a whiteboard.

what it involves

  • Direct input into the evidence model and what a passport must prove for your industry

  • Architecture discussions on deployment, custody of signing keys, and anchoring modes

  • Priority scheduling for pilot deployments

  • Direct access to the verification tooling and new capabilities as they ship

request a demo

See it on a real workflow

See the evidence workflow end to end — how a dataset state is committed, how the passport is assembled, and how a recipient verifies a delivery independently.

what to expect

A short, focused walkthrough with the team building the product. We’ll show the passport a buyer receives, what each piece of evidence proves — and where its limits are. Bring questions about your own data products.

Demos available now

Pick a time that suits you. Scheduling opens on Calendly, an external booking page, in a new tab.

Prefer email? Write to contact@bitprovenance.com. This page doesn’t collect any information.

faq

Direct answers to the fair questions

Is BitProvenance available today?

Yes. BitProvenance is operational and ready to demonstrate — book a demo and we'll walk through the evidence workflow with you. Deployments are scheduled with a small number of organizations at a time, so discovery conversations start early.

Does customer data leave its environment?

BitProvenance keeps raw data, schemas, credentials, and transformation details inside your infrastructure. For managed anchoring, only a minimal blinded, aggregate commitment — a short hash — leaves your environment.

What does the Bitcoin anchor prove?

That a specific commitment existed no later than the time its anchoring transaction was confirmed. It is an independently verifiable timestamp and integrity anchor — it does not prove the committed data is accurate, lawful, or truthful.

Is data written to Bitcoin?

No. One transaction carries a single checkpoint commitment aggregating many provenance records. No personal data, customer names, dataset names, schemas, row hashes, or internal identifiers belong on-chain.

Does BitProvenance prove that a dataset is accurate or legally anonymized?

No. Cryptography can prove integrity, ordering, and existence timing. Quality and anonymization rest on assessments and attestations, which a passport binds to the exact dataset they describe — and legal compliance decisions belong to your data controller, DPO, auditors, and counsel.

Can a recipient verify evidence without a BitProvenance account?

Yes — passports are portable and independently verifiable with open tooling, and exported evidence remains checkable even if BitProvenance is unavailable in the future.

What does becoming a design partner involve?

A short discovery conversation about how you create, buy, or audit data products, followed by input into the evidence model and architecture. Design partners get priority scheduling for pilots and direct access to the verification tooling.