Preserving Company Board Documents
Preserving board documents means two things: keeping the records for as long as you're required or advised to, and being able to show later that they haven't changed.
How to Preserve Board Documents: Keeping Minutes and Resolutions Verifiable Over Time
Preserving board documents means two things: keeping the records for as long as you're required or advised to, and being able to show later that they haven't changed. Most companies handle the first part reasonably well. The second part usually gets ignored until a dispute, an audit or an investor's due diligence team asks for it.
This guide covers what counts as a board document, how to store them sensibly, and how a cryptographic timestamp can add a verifiable layer without exposing the contents.
What counts as a board document?
The core set is fairly consistent across companies:
>Minutes of board meetings and committee meetings
>Written resolutions and written consents
>Board packs and the papers circulated before meetings
>Approved budgets, strategic plans and major contract approvals
>Conflict-of-interest declarations
>Records of share issuances, option grants and similar decisions
>Signed versions of anything the board formally approved
Drafts matter too, more than people expect. If a dispute arises over what was decided, the draft history can show how the final wording came about.
How long do you need to keep them?
It depends on where the company is incorporated and what sector it operates in. There's no single global answer.
As one example, UK company law requires minutes of directors' meetings and of general meetings to be kept for at least ten years from the date of the meeting. Other jurisdictions set different periods, and tax, employment, securities and industry regulations can add their own. Check the rule that applies to your entity against the primary legislation or with qualified counsel, and then write the answer into a retention policy.
A practical habit: for the core governance record (minutes, resolutions, share records), many companies simply keep them for the life of the company. Storage is cheap, and the cost of not having a record is much higher.
Where should board documents live?
There are a few common options, and most companies end up using more than one.
A board portal: Dedicated governance software gives you access control, approval workflows and a tidy archive. It's a good fit if you have the budget, but you're trusting the provider's logs and your own account administration.
A document management system or shared drive: This is what most small companies use. It works until someone reorganizes folders, a departing employee's account is deleted, or a file is quietly edited.
Signed PDFs in a records folder: Electronic or wet-ink signatures help show that the signers approved a specific version. But a signature doesn't by itself tell you when the document existed, unless it's paired with a trusted timestamp.
Offline or cold backups: Useful for survival of the record, though they don't answer the question of whether the record was altered before it was backed up.
Whatever you choose, keep a few basics in place: a single agreed location for final versions, a naming convention that includes the meeting date, restricted write access, and backups kept separately from the primary system.
The part most guides skip: proving the record hasn't changed
Say a former director challenges a decision five years from now. You produce the minutes. They say, "That's not what we signed." What can you show?
Access logs help, but they're held by a system that your own team administers. A hash and timestamp offer something different: an independent reference point.
Here's the idea in plain terms. A cryptographic hash function such as SHA-256 reads a file and produces a short fixed-length string, a digital fingerprint. Change a single character in the file and the fingerprint changes completely. If you record that fingerprint somewhere that can't be quietly rewritten, together with a reliable time, you've created evidence that a file with exactly that fingerprint existed at or before that time.
Later, anyone can take the minutes you produce, calculate the fingerprint again, and compare. A match indicates the file is bit-for-bit identical to the one that was recorded. A mismatch means something is different.
Where a blockchain timestamp fits
A blockchain is one way to hold that fingerprint in a public record that no single party controls. Because each block builds on earlier ones, rewriting history later would be extremely difficult.
With Certelo, the process works like this:
1. You select the file, for example the signed PDF of the March board minutes.
2. Certelo calculates the SHA-256 hash locally, in your browser, on your device.
3. The original file isn't uploaded just to create the proof. Only the hash is used.
4. The hash is anchored to the Electra Protocol blockchain, and the record carries the blockchain's time.
5. Later, you or anyone you've shared the file with can verify it using the original file, the hash, or the certificate details.
The privacy point deserves attention. Board documents often contain unreleased financial figures, acquisition discussions, or personnel matters. Many timestamping tools need the document itself, or at least pass it through their servers. A client-side hash lets you create the record without handing the document to a third party.
What a timestamp does and doesn't prove
Be clear-eyed about this, particularly with lawyers and auditors in the room.
A blockchain timestamp can help demonstrate that a specific file existed at or before a recorded time, and that a file presented later is identical to it. That's useful for integrity and chronology.
It does not, on its own, prove:
*who wrote or approved the document
*that the meeting took place as described
*that the contents are accurate or that the resolution was validly passed
*that the document is admissible or carries a particular weight in any given court
Those questions are answered by signatures, attendance records, corporate law and the surrounding facts. A timestamp is one piece of an evidentiary record, not a replacement for the rest of it. How such evidence is treated differs by jurisdiction, so take legal advice where the stakes justify it.
It also can't protect a file that was wrong when you stamped it. If the minutes were altered before the hash was created, the timestamp faithfully records the altered version. That's why timing matters: stamp the final signed version promptly, ideally as part of the same step as signing.
A practical workflow for a small company
Nothing here needs to be elaborate:
1.Finalize - Once minutes are approved and signed, export the final PDF. Don't stamp drafts as if they were final, though you can stamp drafts separately if you want a record of the editing history.
2. Name it consistently - For example, 2026-03-14_board-minutes_final-signed.pdf.
3. Store - it in your main records location.
4. Create the timestamp - Hash the file and anchor it. Save the certificate alongside the file.
5. Back up both the document and the certificate separately from the main system.
6. Log it - Add a line to your corporate records register noting the date, the file name and the hash.
7. Spot-check yearly - Pick a few older documents, re-verify them, and confirm they still match.
The same steps work for written resolutions, shareholder consents and approved policy documents.
Why this matters during due diligence?
Investors and acquirers routinely ask for the minute book. A well-organized, consistently named archive tells them the company is run carefully. Being able to show that key records match independently anchored fingerprints is a small additional signal of care, and it can shorten the back-and-forth when questions come up about when a decision was documented.
Frequently asked questions
Can you timestamp board minutes?
Yes. You can create a hash of the final file and anchor it to a blockchain. The timestamp then supports the claim that exactly that version existed at or before the recorded time.
Does Certelo upload my board documents?
No. The SHA-256 hash is calculated locally on your device, and the original file isn't uploaded to create the proof.
Is a blockchain timestamp the same as a legally required record?
No. Legal record-keeping duties come from company law and other regulation in your jurisdiction. A timestamp supports the integrity of the records you keep. It doesn't replace the duty to keep them.
What happens if someone edits the document afterward?
The edited file will produce a different hash, so it won't match the anchored record. The original, unchanged file will still verify.
Can it show who approved the resolution?
Not by itself. Approval is shown through signatures, voting records and attendance. The timestamp helps show when a given version existed.
Should I stamp drafts?
Optionally. Stamping key drafts can document how the wording evolved. Always make clear which version is the final approved one.
How long does the proof last?
It lasts as long as the blockchain record remains accessible and you retain the original file. Keep both, and keep the certificate with them.
In short
Good board record-keeping is about retention and about trust in what you retained. Store the documents properly, follow the retention rules for your jurisdiction, and consider adding an independently verifiable timestamp for the final versions. If you'd like to try it without sending a file anywhere, you can create a record on Certelo and verify it later with the original document.