Handed a pack by one of our customers? Check it here — the file never leaves your browser for step 1, and step 2 sends only a hash, never the file.
Drop or select the exported .zip pack. We recompute its hash locally and compare it to the value it declares in its own manifest.
Paste a 64-character SHA-256 (auto-filled above, or from a certificate PDF / email) to confirm it matches a real export in Protokol's own audit log. Only the hash is sent — never a file, name, or meeting id.
Check 1 proves the file you have is byte-for-byte what its own manifest describes (tamper-evidence). Check 2 proves that exact hash was genuinely recorded by Protokol at export time (provenance) — something only Protokol's server-side audit log can confirm, since a forger controls the file and manifest but not our database. The pack's manifest schema and hashing rule are published as a versioned public spec at /verify-spec — so any third-party tool, not just this page, can implement its own independent version of check 1.