Proof of Delivery

For when “I sent it” has to be more than your word

Email tells you a message left your outbox. It does not tell you the attachment was opened, when, or by whom - and if that ever matters, you find out too late. GCN.ONE records the delivery of every transfer and can issue a signed certificate for it that anyone can check, without an account and without having to trust us.

Send a file now See pricing
What proof of delivery is here

Two things, working together. First, a record: every time your share link is opened and every time a download starts, that event is stored with a timestamp, the share it came through, and the size of what was fetched. Never any file content - the files are encrypted and we cannot read them.

Second, a certificate: for any file that has actually been delivered, you can have a delivery certificate issued. It states what was delivered, to whom - as a deliberately partial hint rather than a full identity - when the delivery was confirmed and how the file was encrypted, and it is signed with our Ed25519 key over exactly that set of facts.

How it works, end to end
1
The transfer is opened
Your recipient opens the share link and the download begins. Both events are recorded with timestamps as they happen - you do not have to switch anything on, and by default you are notified the moment the download starts.
2
A certificate is issued
Once a download is confirmed, you can issue a delivery certificate for that file from the transfer view. You get a code in the form GCN-CERT-2026-09-01-… . Asking twice returns the same certificate rather than minting a new one, so a code you have already handed out stays the code.
3
Anyone verifies it
Send the code to whoever needs it. They open the Verify page, or call the public verification endpoint, and the signature is checked against our published signing key. No GCN.ONE account, no login, and no request back to you.
What we can and cannot attest to

We are precise about this on purpose. The encrypted bytes travel straight from the storage node to your recipient and never pass through us, so what we can attest to is that the download started - not that a person read the document, understood it, or agreed with it. A delivery certificate is evidence of delivery, not of reading.

It is also not a legal instrument. The certificate is cryptographically signed and independently verifiable, and that is exactly what we claim for it. Whether a specific statutory form of service applies in a given proceeding is a question for the applicable law; we make no claim to be a qualified delivery service under eIDAS.

Why the record cannot be quietly rewritten

A signed certificate is only as good as the record behind it. If the operator could edit the delivery event afterwards and re-sign, the signature would prove nothing more than that the operator agreed with themselves. So the record sits in a tamper-evident log, in three layers.

A hash chain
Every event commits to the one before it with a BLAKE3 hash, so nothing can be inserted, removed or reordered without breaking the chain from that point on. The certificate itself is written into this chain, and its hash is bound into the signed payload.
A Merkle root
Every fifteen minutes the current chain tips are rolled into a single Merkle root, and each root is chained to the one before it. One 32-byte value then commits to everything in that window.
A public anchor
Each root is timestamped through OpenTimestamps, which anchors it to the Bitcoin blockchain - a reference point outside our own infrastructure, and one that stays checkable whether or not we are still around.

A freshly returned proof is a pending calendar attestation; it becomes a full Bitcoin proof once it is upgraded, and that upgrade is performed with the standard ots client rather than reported by us. The chain commits to ciphertext rather than to readable content, which is why erasing a user’s data under GDPR does not break it.

One honest limit: anchoring establishes that a particular log state existed at a particular time and has not been altered since. It does not prove the entries were truthful when they were written. Anchoring makes the past immutable; it cannot police the present.

Check a certificate

Have a code someone sent you? Enter it here. Verification is public - you do not need a GCN.ONE account, and the sender is not told that you checked.

Codes look like GCN-CERT-YYYY-MM-DD- followed by twelve characters. Verification checks the signature against our published signing key, so a certificate stays verifiable even after the transfer itself has expired and been deleted.
Send something that can be proven
Proof of delivery is included on every plan, the free one included.