Transparency

How verification works

Steek signatures are built to be checked by anyone, without trusting us. Here is exactly what we sign, what we never see, and how you can verify a document yourself — no account, offline, in your own browser.

Verify a document or certificate
01

What we sign

When you sign a document in Steek, your device first computes a SHA-256 fingerprint of the file — a short, fixed-length code derived from every byte in it. Change a single character and the fingerprint changes completely.

Your device then signs that fingerprint with a signing key only you hold. The fingerprint — not the document — is what gets signed, timestamped, and notarized. That is enough to prove this exact file existed and that you stood behind it, without the file itself having to travel anywhere to be signed.

02

What we never see

Steek never receives the contents of your document. Files are encrypted on your device, to your own keys, before anything is stored. That is what zero-knowledge means here: we cannot read your documents, and neither can anyone who gains access to our servers.

What we hold is deliberately minimal — fingerprints, identities, and timestamps. A fingerprint cannot be turned back into the original file, so even a complete breach of Steek would reveal no document content.

03

Hybrid post-quantum signatures

Every signature is produced twice, with two independent algorithms: a classical Ed25519 signature and a post-quantum ML-DSA-65 signature. Both are attached, and both must verify for a signature to count as valid.

This is a hedge against the future. If a weakness is ever found in one algorithm — including the arrival of a quantum computer able to break classical curves — the other half still stands, so your signature survives.

On top of the signer's two signatures, a Steek notary key countersigns each attestation with a trusted timestamp, recording when the fingerprint was seen.

04

How you verify

Anyone can check a signature independently — no account, and no need to trust Steek's servers. Verification runs entirely in your browser and works offline, against our published keys.

The check is straightforward:

  • Recompute the SHA-256 fingerprint of your own copy of the file.
  • Verify the classical Ed25519 and post-quantum ML-DSA-65 signatures against the published keys.
  • Verify the Steek notary countersignature and its timestamp.
  • Confirm the fingerprint carried in the signature matches the file in front of you.
05

Why it's trustworthy

Trust here does not rest on taking our word for it. It rests on things you can check for yourself:

  • Published keys. Steek's notary keys are published as a stable trust anchor, so signatures can be checked against a known reference.
  • Tamper-evident ledger. Signing events are recorded in an append-only audit ledger, so history cannot be quietly rewritten.
  • Verified identities. Signers — and, where relevant, their organizations — are identity-verified, so a signature ties back to a real, checked identity.
  • In your browser. The whole check runs on your device, so you never have to trust a server to get an honest answer.

Try it

Verify it yourself

Don't take our word for it. Drop a proof bundle or a signed PDF into the verifier and watch every signature checked, live, against our published keys.

Verify a document or certificate

Steek's published notary keys are served, unauthenticated, from the public endpoint /trust/notary-keys.