Back to home
Official timestamping

Daily consent proof, sealed by TÜBİTAK every night.

Permbot builds a deterministic hash chain from every consent record you store each day, then requests an official TÜBİTAK Kamu SM timestamp on the manifest. The result is independent, third-party evidence you can download for audits and legal review.

TÜBİTAK logo

Timestamp authority

TÜBİTAK Kamu SM Zamane KS

Fully automated · No manual steps

hash_1

a3f8…c21d

hash_2

b7e2…9f04

hash_3

c91a…44be

hash_4

d4c0…77a1

chain_root

e2b5…root

chain-manifest.json.zd

TÜBİTAK Kamu SM · RFC 3161

What it is

More than consent logs: cryptographically sealed daily batches

Each visitor consent row already carries an integrity hash at ingestion. Permbot rolls those hashes into a daily chain, stamps the manifest with TÜBİTAK, and keeps a downloadable archive for your billing account.

Independent custodian

Records are stored outside your website infrastructure, aligned with GDPR, KVKK, and comparable evidence requirements.

Automatic nightly batches

No panel button to press. When your plan includes timestamping, batches are created on schedule per data location.

Audit-ready exports

Completed batches expose chain root, consent counts, stamped time, and a ZIP archive with manifest, .zd stamp, and summary PDF.

Built for disputes

If a consent decision is challenged months later, you can show a third-party timestamp tied to the exact hash chain of that day.

How it works

From consent row to TÜBİTAK-sealed archive

The pipeline is deterministic and read-only in the panel. Permbot never asks you to recompute hashes client-side; proof lives on the backend and with the timestamp authority.

If a day has zero consent records, no batch row is created for that date. Multi-location accounts may see separate batches per region for the same calendar day.

Step 1

Every consent row gets an integrity hash

When a visitor accepts or rejects categories, Permbot stores the decision together with policy version, anonymized IP, and a tamper-evident integrity hash calculated at ingestion.

Step 2

Nightly deterministic hash chain

For each billing account and data location, the backend collects that day's consent hashes, orders them by record ID ascending, and links them into a single chain ending in a chain root digest.

#1

a3f8…c21d

#2

b7e2…9f04

#3

c91a…44be

#4

d4c0…77a1

root

e2b5…root

chain-manifest.json.zd

TÜBİTAK Kamu SM · RFC 3161

Step 3

Chain manifest file

The full ordered list and chain metadata are written to chain-manifest.json. This JSON file is the primary evidence artifact; the PDF report is a human-readable summary only.

Step 4

TÜBİTAK Kamu SM timestamp

Permbot submits the manifest to TÜBİTAK Kamu SM Zamane KS (RFC 3161) and stores the returned .zd timestamp file alongside the manifest.

Step 5

Downloadable ZIP archive

When stamping completes, the panel lists the batch as completed and lets you download integrity-timestamp-{location}-{date}-{id}.zip containing manifest, stamp, and PDF.

Inside the panel

Browse history, inspect chain roots, download proof

Agencies and site owners get a read-only Integrity timestamps area. Filter by period, region, and status; open a batch for details; download the archive when stamping finishes.

app.permbot.net/dashboard/integrity-timestamps

Panel preview

Integrity timestamps

TÜBİTAK Kamu SM
PeriodLocationStatusRecordsChain root
29 May 2026TürkiyeCompleted1,842a1b2c3d4…abcdef12ZIP
28 May 2026TürkiyeCompleted1,756f4e5d6c7…98765432ZIP

Tamper-evident

Hashes are fixed at ingestion; the nightly chain binds the full day.

Full archive

Manifest, .zd stamp, and PDF travel together in one ZIP.

One-click export

Download when status is completed and has_download is true.

ZIP contents

One archive, three files

Each completed batch ships the full audit set. Investigators can verify the manifest hash against the TÜBİTAK stamp without trusting your website servers.

chain-manifest.json

Full consent hash chain for the day. This is the authoritative dataset.

chain-manifest.json.zd

Official TÜBİTAK timestamp file (.zd) binding the manifest to a trusted time.

report.pdf

Human-readable summary with the first 500 sample rows. Full data remains in the JSON manifest.

Legal & audit use

Evidence you can hand to counsel or regulators

Integrity timestamps complement your consent log UI. They answer a different question: was this day's record set frozen at a specific time, independently of the site operator?

  • Manifest JSON preserves the complete hash chain for the period.
  • TÜBİTAK .zd file proves the manifest existed at the stamped time.
  • PDF helps stakeholders review samples quickly before deep technical verification.

Available on eligible plans

Turn nightly consent records into audit-ready proof

Upgrade to a plan with daily TÜBİTAK integrity hash timestamping, or ask your agency to enable it on your managed account.

Create free account