← All Blog articles

Archiving Product Development

A startup should archive product development by hashing each milestone artifact (specs, design files, source snapshots, release builds, test results) with SHA-256 and anchoring those hashes to a public blockchain at the time each artifact is finished.

How Startups Can Archive Every Stage of Product Development

A startup should archive product development by hashing each milestone artifact (specs, design files, source snapshots, release builds, test results) with SHA-256 and anchoring those hashes to a public blockchain at the time each artifact is finished. The result is a dated, tamper-evident record that shows what existed on a given day and proves it has not changed since. Because only the hash is anchored, nothing confidential leaves the company. The archive then supports patent disputes, investor due diligence, tax credit claims, and acquisition reviews, all of which ask the same question years later: what did you have, and when did you have it?

Why Git History and Shared Drives Don't Settle the Question

Most early teams assume their tools already keep the record. Git, Notion, Figma, and Google Drive all store history, but none of them was built to serve as evidence against a skeptical third party.

Git is the most common false comfort. A commit's author date is a field the committer sets, and anyone can change it with a single flag or rewrite history with a rebase and a force-push. The commit hash proves the content is internally consistent, but it says nothing reliable about when the commit was made. Hosted platforms add their own server-side timestamps, yet those live inside a company's database, and the startup has no control over how long they persist or how they are exported.

Shared drives and wikis have a similar gap. Edit histories can be pruned by retention settings, lost during workspace migrations, or erased when a departing employee's account is deleted. If the account that owns the folder disappears, the history often goes with it.

The practical risk shows up at specific moments. A competitor files a patent covering something you built eight months earlier. A former contractor claims they wrote the core module before signing an assignment agreement. An acquirer's counsel asks for proof that the prototype predates the financing round. In each case, the side with an independent, dated record has a much easier conversation than the side asking everyone to trust its internal logs.

What a Dated Archive Means Technically

The mechanism has three parts, and each one is small enough to audit.

Local hashing. The file is processed by the SHA-256 algorithm in the browser, producing a 64-character fingerprint. Change a single byte of the file, even a comma in a spec, and the fingerprint changes completely. The file itself is never uploaded, which matters when the artifact is unreleased source code or a design under NDA.

Anchoring. The fingerprint is written into a blockchain transaction. Once that block is confirmed, the transaction carries the network's block time, which no single party, including the startup and the timestamping provider, can alter afterward. Decentralized consensus is what makes the date independent of anyone's database.

Verification. Later, anyone with the original file can hash it again and compare the result against the on-chain value. A match proves two things at once: the file existed no later than the block time, and it is bit-for-bit identical to what was anchored. The verifier does not need to trust the startup, the platform, or a notary. They need the file, a hash calculator, and a block explorer.

This is also why the record survives company turnover. The proof lives on the ledger, not in an account someone has to keep paying for.

What to Archive at Each Stage

The goal is not to timestamp every file every day. It is to anchor the artifacts that would matter in a dispute, at the moment they stabilize. A reasonable cadence follows the product's lifecycle:

Concept and discovery: the problem statement, early architecture sketches, whiteboard photos, and the first written description of the core technical approach. These are the documents that establish who thought of what, and when.

Prototype: a source snapshot (exported as a single archive), the bill of materials for hardware, and recorded demos. A zip file or tarball of the repository at a given commit gives you one stable object to hash.

Design iterations: exported design files at each major revision, plus the user research notes that justified the changes.

Alpha and beta releases: the compiled build, the release notes, the dependency manifest, and the test results from that build.

Production milestones: each tagged release, security audit reports, and any model weights or training dataset manifests if the product involves machine learning.

Decisions: the written rationale for pivots, vendor selections, and architecture changes. Teams rarely preserve these, yet they are exactly what lawyers ask for when reconstructing intent.

One habit makes this sustainable: attach the archiving step to an event that already happens. A release tag, a sprint review, or a signed-off design freeze are natural triggers. A quarterly "archive day" tends to be forgotten within two quarters.

A Workable Routine for a Small Team

Keep the process short enough that nobody skips it.

1-Package the milestone. Export the artifact as one file. For code, create an archive from a tagged commit. For design, export the full file rather than screenshots.

2-Hash and anchor it. Open the timestamping tool, select the file, and let the browser compute the SHA-256 fingerprint locally. Submit the fingerprint for blockchain anchoring.

3-Save the certificate with the file. Store the proof record next to the original in your internal archive, using a consistent name such as the release tag plus the date.

4-Log it in one index. A single spreadsheet or markdown file listing the artifact name, hash, anchor date, and storage location is enough. When counsel asks for a chronology, this index becomes the first exhibit.

5-Verify once. After the first anchoring, run the verification step end to end so someone on the team knows how it works before it is needed under pressure.

For teams that ship constantly, a timestamping API can automate step 2 inside the CI pipeline, so every tagged release is hashed and anchored without anyone remembering to do it.

One caution on scope: the proof covers the exact bytes you hashed. If the archive is a zip containing ten files, the proof covers that zip. Re-zipping the same files produces a different hash because archive metadata changes, so keep the original archive file rather than regenerating it later.

Where the Record Carries Legal Weight

A blockchain timestamp establishes existence and integrity. It does not establish authorship or novelty by itself, and it should be presented as one piece of a larger evidentiary picture alongside employment agreements, commit logs, and correspondence. Within that role, it does real work.

Patent disputes >> Under the first-inventor-to-file system in the United States, filing date is what counts for priority, so a dated record does not replace a filing. It does help in derivation proceedings and in showing that your own earlier work existed, which can matter for prior user defenses and for challenging claims in other jurisdictions that recognize prior art disclosures.

Trade secrets >>Courts looking at misappropriation claims want to see that the owner took reasonable steps to protect the information and can identify precisely what the secret was and when it existed. A hash-anchored archive does both without exposing the secret.

Admissibility>> In U.S. federal courts, Federal Rules of Evidence 902(13) and 902(14) allow electronic records and data copied from a device to be authenticated by a qualified person's certification, including by comparing hash values. A matching SHA-256 value against an independently anchored hash fits that framework well, though admissibility always depends on the court and the facts. In the European Union, eIDAS gives qualified electronic time stamps a legal presumption of accuracy, while other electronic time stamps cannot be denied legal effect solely because of their form, so a blockchain-based record can still be offered as evidence and weighed on its merits.

Tax credits and audits>> R&D credit claims in the U.S. and similar incentives elsewhere depend on contemporaneous documentation showing that qualifying technical work happened in the claimed period. Records dated at creation are far more persuasive than documents assembled during an examination.

Financing and exits>> Technical due diligence increasingly asks for proof of development timeline and code provenance, particularly where open-source components or contractor contributions are involved. An anchored archive answers those questions quickly.

For any specific dispute, counsel should decide how to present the evidence. The archive's job is to make sure the evidence exists in the first place.

Start the Archive With the Next Release

Pick the most recent stable build, export it as a single file, and timestamp it on Certelo today. Then add the same step to your release checklist so each future milestone gets anchored when it ships. Within a few months, you will hold a verifiable chronology of your product that no one, including you, can rewrite.

Written by Celine