self-hosted evidence layer · available now · demos on request
Proof that travels with the data.
BitProvenance binds a commercial dataset’s integrity, declared lineage, quality evidence, and producer identity into a portable data passport a buyer can verify independently — while raw data stays inside your environment.
customer environment · private
v1 · source extract
root 9c41…e07b- anonymize · signed
v2 · anonymized
root 4d88…12af- aggregate · signed
v3 · delivered dataset
root a3f2…91c4
Checkpoint
c c7d1…08aamany records, one commitment
Checkpoint
c c7d1…08aamany records, one commitment
Data passport
- integrity evidence
- declared lineage
- quality results
- privacy assessment
- producer signatures
travels with the delivered dataset
bitcoin block
Anchored checkpoint
t 2026-04-30 11:02Zone transaction anchors many records
Buyer verifies independently
re-computes the delivered dataset’s root, checks signatures and Bitcoin inclusion — matches the committed root ✓
the trust gap
Data products are sold on trust that neither side can demonstrate.
Valuable datasets change hands on the strength of documents and contracts. Neither side can point to evidence that binds the claims to the exact data delivered.
If you sell data
You can’t demonstrate the history and controls behind a dataset without opening up the private systems it came from. The stronger your governance, the more frustrating it is that buyers can’t see it.
If you buy data
You receive files, documentation, and contractual assurances — and almost nothing you can verify independently. Diligence means taking the seller’s word for how the data was sourced and prepared.
where the evidence breaks down
Quality reports and lineage live in documents that drift apart from the exact dataset that was delivered.
Provenance records can be rewritten after a dispute begins — and it is hard to show that they weren't.
A dataset can be modified or silently re-exported after it was evaluated, with nothing binding the file to its review.
Generic “blockchain verified” badges often claim far more than what was actually proven.
the workflow
How BitProvenance works
BitProvenance is built around one ordered sequence. Each step produces evidence the next step builds on.
step 01 / 05
Capture locally
A self-hosted engine runs inside your environment and observes declared sources, transformations, schemas, and checks as your pipelines run. Nothing is sent out to be watched.
step 02 / 05
Commit each version
Deterministic commitments bind every dataset state and signed provenance event into a hash-linked, tamper-evident record — without publishing the data itself.
step 03 / 05
Assemble the passport
The evidence relevant to one data product — integrity commitments, declared lineage, quality results, privacy assessments, and signatures — is packaged into a portable passport that travels with the delivered dataset.
step 04 / 05
Anchor the checkpoint
Many records aggregate into one minimal checkpoint commitment, and that single value is anchored to Bitcoin. One transaction can anchor an entire history; no data, names, or schemas go on-chain.
step 05 / 05
Verify independently
A recipient re-computes the delivered dataset's commitment and checks the signatures, the evidence chain, and the Bitcoin inclusion proof — without needing access to your systems or an account with us.
evidence boundaries
What a data passport can prove — and what it can’t
Different claims rest on different evidence. A passport shows the strength and source of each one, instead of hiding everything behind a single “verified” badge.
Cryptographically verifiable
Anyone with the passport can check these mathematically.
The delivered file matches the committed dataset state
deterministic hash + Merkle verification
The evidence chain was not altered after commitment
signed, hash-linked provenance records
The producer stands behind each record
cryptographic signatures over every event
The commitment existed by a point in time
Bitcoin anchor + inclusion proof
Supported by attestations and assessments
These rest on people and process — named, signed, and bound to the dataset, but not reducible to math.
The source was authentic operational data
chain of custody + producer or auditor attestation
The dataset resulted from the declared transformations
reproduction, controlled execution, or independent attestation
Quality and privacy assessments were performed
assessment reports bound into the passport
The data is legally anonymized and saleable
privacy assessment + legal governance — never a hash alone
A Bitcoin timestamp proves a commitment existed by a point in time — it does not prove the committed claim is true. BitProvenance is designed to keep that boundary visible, so “verified” always means something specific: which claim, checked against which evidence, asserted by whom.
privacy & deployment
Your data stays where it is. Only proof moves.
The engine runs self-hosted, inside your infrastructure. Evidence is created where the data lives — it doesn't have to be shipped somewhere to be trusted.
Passports are portable and designed for independent verification: a recipient can check one without a BitProvenance account, and exported evidence remains verifiable even if BitProvenance is unavailable in the future.
designed to stay in your environment
- Raw records, schemas, and credentials
- Transformation logic and pipeline details
- Full provenance records and evidence packages
- Signing keys, under customer custody
leaves for anchoring — nothing else is required
- One blinded, aggregate checkpoint commitment — a short hash that reveals nothing about the data behind it
No personal data, customer names, dataset names, schemas, or row-level hashes belong on Bitcoin — ever.
who it's for
Built around three sides of every data transaction
data owners & sellers
Turn internal data into a product buyers can trust
Package operational datasets with evidence of how they were prepared — without exposing the private systems behind them. The outcome: faster diligence, stronger positioning against unverifiable alternatives.
data buyers
Verify what you received before you build on it
Check that a delivery matches the state its evidence describes, see the declared lineage, and inspect who attested to what. The outcome: clearer disputes and fewer surprises in datasets feeding analytics or AI training.
auditors & governance
Review one consistent, tamper-evident evidence package
Work from signed, hash-linked records instead of screenshots and spreadsheets, and add independent attestations that strengthen a passport's assurance level. The outcome: portable chain of custody your clients can hand to their counterparties.
design partners
Help define what proof should look like
BitProvenance is built alongside organizations that create, acquire, or audit valuable datasets. The evidence model comes from real transactions, not from a whiteboard.
what it involves
Direct input into the evidence model and what a passport must prove for your industry
Architecture discussions on deployment, custody of signing keys, and anchoring modes
Priority scheduling for pilot deployments
Direct access to the verification tooling and new capabilities as they ship
request a demo
See it on a real workflow
See the evidence workflow end to end — how a dataset state is committed, how the passport is assembled, and how a recipient verifies a delivery independently.
what to expect
A short, focused walkthrough with the team building the product. We’ll show the passport a buyer receives, what each piece of evidence proves — and where its limits are. Bring questions about your own data products.
Demos available now
Pick a time that suits you. Scheduling opens on Calendly, an external booking page, in a new tab.
Prefer email? Write to contact@bitprovenance.com. This page doesn’t collect any information.
faq
Direct answers to the fair questions
Is BitProvenance available today?
Yes. BitProvenance is operational and ready to demonstrate — book a demo and we'll walk through the evidence workflow with you. Deployments are scheduled with a small number of organizations at a time, so discovery conversations start early.
Does customer data leave its environment?
BitProvenance keeps raw data, schemas, credentials, and transformation details inside your infrastructure. For managed anchoring, only a minimal blinded, aggregate commitment — a short hash — leaves your environment.
What does the Bitcoin anchor prove?
That a specific commitment existed no later than the time its anchoring transaction was confirmed. It is an independently verifiable timestamp and integrity anchor — it does not prove the committed data is accurate, lawful, or truthful.
Is data written to Bitcoin?
No. One transaction carries a single checkpoint commitment aggregating many provenance records. No personal data, customer names, dataset names, schemas, row hashes, or internal identifiers belong on-chain.
Does BitProvenance prove that a dataset is accurate or legally anonymized?
No. Cryptography can prove integrity, ordering, and existence timing. Quality and anonymization rest on assessments and attestations, which a passport binds to the exact dataset they describe — and legal compliance decisions belong to your data controller, DPO, auditors, and counsel.
Can a recipient verify evidence without a BitProvenance account?
Yes — passports are portable and independently verifiable with open tooling, and exported evidence remains checkable even if BitProvenance is unavailable in the future.
What does becoming a design partner involve?
A short discovery conversation about how you create, buy, or audit data products, followed by input into the evidence model and architecture. Design partners get priority scheduling for pilots and direct access to the verification tooling.