Daily consent proof, sealed by TÜBİTAK every night.
Permbot builds a deterministic hash chain from every consent record you store each day, then requests an official TÜBİTAK Kamu SM timestamp on the manifest. The result is independent, third-party evidence you can download for audits and legal review.
Timestamp authority
TÜBİTAK Kamu SM Zamane KS
hash_1
a3f8…c21d
hash_2
b7e2…9f04
hash_3
c91a…44be
hash_4
d4c0…77a1
chain_root
e2b5…root
chain-manifest.json.zd
TÜBİTAK Kamu SM · RFC 3161
What it is
More than consent logs: cryptographically sealed daily batches
Each visitor consent row already carries an integrity hash at ingestion. Permbot rolls those hashes into a daily chain, stamps the manifest with TÜBİTAK, and keeps a downloadable archive for your billing account.
Independent custodian
Records are stored outside your website infrastructure, aligned with GDPR, KVKK, and comparable evidence requirements.
Automatic nightly batches
No panel button to press. When your plan includes timestamping, batches are created on schedule per data location.
Audit-ready exports
Completed batches expose chain root, consent counts, stamped time, and a ZIP archive with manifest, .zd stamp, and summary PDF.
Built for disputes
If a consent decision is challenged months later, you can show a third-party timestamp tied to the exact hash chain of that day.
How it works
From consent row to TÜBİTAK-sealed archive
The pipeline is deterministic and read-only in the panel. Permbot never asks you to recompute hashes client-side; proof lives on the backend and with the timestamp authority.
If a day has zero consent records, no batch row is created for that date. Multi-location accounts may see separate batches per region for the same calendar day.
Every consent row gets an integrity hash
When a visitor accepts or rejects categories, Permbot stores the decision together with policy version, anonymized IP, and a tamper-evident integrity hash calculated at ingestion.
Nightly deterministic hash chain
For each billing account and data location, the backend collects that day's consent hashes, orders them by record ID ascending, and links them into a single chain ending in a chain root digest.
#1hash_1
a3f8…c21d
#2hash_2
b7e2…9f04
#3hash_3
c91a…44be
#4hash_4
d4c0…77a1
rootchain_root
e2b5…root
chain-manifest.json.zd
TÜBİTAK Kamu SM · RFC 3161
Chain manifest file
The full ordered list and chain metadata are written to chain-manifest.json. This JSON file is the primary evidence artifact; the PDF report is a human-readable summary only.
TÜBİTAK Kamu SM timestamp
Permbot submits the manifest to TÜBİTAK Kamu SM Zamane KS (RFC 3161) and stores the returned .zd timestamp file alongside the manifest.
Downloadable ZIP archive
When stamping completes, the panel lists the batch as completed and lets you download integrity-timestamp-{location}-{date}-{id}.zip containing manifest, stamp, and PDF.
Inside the panel
Browse history, inspect chain roots, download proof
Agencies and site owners get a read-only Integrity timestamps area. Filter by period, region, and status; open a batch for details; download the archive when stamping finishes.
Panel preview
Integrity timestamps
| Period | Location | Status | Records | Chain root | |
|---|---|---|---|---|---|
| 29 May 2026 | Türkiye | Completed | 1,842 | a1b2c3d4…abcdef12 | ZIP |
| 28 May 2026 | Türkiye | Completed | 1,756 | f4e5d6c7…98765432 | ZIP |
Tamper-evident
Hashes are fixed at ingestion; the nightly chain binds the full day.
Full archive
Manifest, .zd stamp, and PDF travel together in one ZIP.
One-click export
Download when status is completed and has_download is true.
ZIP contents
One archive, three files
Each completed batch ships the full audit set. Investigators can verify the manifest hash against the TÜBİTAK stamp without trusting your website servers.
chain-manifest.json
Full consent hash chain for the day. This is the authoritative dataset.
chain-manifest.json.zd
Official TÜBİTAK timestamp file (.zd) binding the manifest to a trusted time.
report.pdf
Human-readable summary with the first 500 sample rows. Full data remains in the JSON manifest.
Legal & audit use
Evidence you can hand to counsel or regulators
Integrity timestamps complement your consent log UI. They answer a different question: was this day's record set frozen at a specific time, independently of the site operator?
- Manifest JSON preserves the complete hash chain for the period.
- TÜBİTAK .zd file proves the manifest existed at the stamped time.
- PDF helps stakeholders review samples quickly before deep technical verification.
Available on eligible plans
Turn nightly consent records into audit-ready proof
Upgrade to a plan with daily TÜBİTAK integrity hash timestamping, or ask your agency to enable it on your managed account.