The document vault is a tamper-evident store for exam evidence. A document is written once and never edited: a correction is a new upload, and the chain keeps both, in the order they arrived. Institutional and above
Tamper evidence by hash chain on standard storage. Not SEC Rule 17a-4 WORM media, and not described as such. The product says this on both the vault and its verification page, and the guide repeats it rather than softening it.
How the chain works
Every upload hashes the bytes and appends one entry that links to the entry before it. Each chain hash is computed from the document hash, the previous chain hash and the upload timestamp, so changing anything in the middle breaks every link after it. There is one independent chain per FDIC certificate.
What a document row carries
Its title and sequence number, its type and exam area, its retention class with the citation behind that class, its size, a short content hash, any restriction, and how many obligations cite it as evidence. Evidence links are made in the Work ledger, not here — see Dashboard.
Purge, and what it does not do
Purging marks a document purged and removes it from the list and from download. It does not remove the chain entry — removing a link would break every entry after it. Your reason is written to the access log. Purge is restricted to account administrators and administrators.
What the register counts
Documents on file, entries in the chain, documents cited as evidence, and the chain verification verdict. Where your role cannot see restricted documents, the register names both numbers — what you can see, and what exists. A count that quietly excludes what you are not allowed to see is a count you would misread.
What verification actually proves
The verify page recomputes every chain hash from the values on record and reports one of three verdicts:
- Chain recomputes — all entries recompute to the hashes on record.
- No chain entries — and this deliberately does not pass. A walk over zero entries succeeds trivially; that is not a result about your records. An empty chain is not a clean chain.
- Chain break — named at the sequence where it happened. Entries before the break stand. Entries after it are unverified, not failed: the chain cannot be carried across the gap to check them. The page tells you not to delete or re-upload anything, because the break location is part of the record.
Each result names what it establishes and, separately, what it does not. The one thing it does not do: it never opens a stored object and re-hashes the bytes. It verifies the chain of record, not the file on disk, and it says so.