Security & SHA-256 Hash

How Kvisl verifies a locked production record.

Kvisl separates digital-record integrity, provenance and physical linking. This page explains what each layer can and cannot prove.

Digital ID

Each Piece receives a Kvisl Digital ID. It identifies the Kvisl record but, by itself, does not prove that a physical object is genuine.

SHA-256 record integrity

At the record-lock point, Kvisl computes a SHA-256 hash from the Piece's locked core production data, including its Digital ID, maker and client references, title, category, description, dimensions, materials, material origin, technique, finish, intended use, custom requirements, production location and production dates.

Verification recomputes the hash from the stored locked data and compares it with the saved value. A match means the protected Kvisl production data still corresponds to the hash generated when the record was sealed.

What the hash does not cover

Later delivery events, receipt confirmations, certificate presentation, timeline images and other sovereign media are not all part of that core SHA-256 payload. Kvisl therefore describes the result as verification of the locked production record, not verification of every later event or file.

Physical Link

A Physical Link is a long-lived, hard-to-enumerate Kvisl URL that can be placed on or inside the work using NFC, QR, engraving or another carrier chosen by the maker. Kvisl provides the URL and resolver; it does not require proprietary NFC hardware or a particular writing tool.

Ordinary QR codes and standard NFC tags can be copied. Physical Link therefore connects the object to its Kvisl record but is not, by itself, a hardware anti-cloning guarantee.

Maker-defined physical confirmation

Where available, makers can strengthen physical binding by choosing their own private physical mark, word, serial or secret and registering only a protected representation with Kvisl. The maker decides what the physical credential is and where it exists on the work; Kvisl does not generate the secret for them.

No blockchain claim

Kvisl's current verification model is based on its locked database record and SHA-256 integrity checking. It is not a blockchain, public ledger or independent third-party attestation, and Kvisl does not describe it as one.