Verification

How verification works

A Lyricsmit record is a fingerprint and a timestamp. Anyone with the link can check it. Nobody needs an account to verify.

What is stored

The SHA-256 fingerprint of the file you chose, an RFC 3161 timestamp from an independent timestamp authority where present, and the details you entered — typically a title, a creator name, and a creative field. Optional location or AI-creation notes can be added later. They are not required to issue the record, they are not independently verified, and they were not included in the Timestamp Authority stamp of the file fingerprint.

What is not stored

The file itself is not retained. It transits Lyricsmit so SHA-256 can be computed on the server, then it is discarded. Your browser computes the same hash first; a mismatch is rejected. Lyricsmit cannot play the file back, download it, or recover it. If you lose the original file, the record still shows that a file with that fingerprint existed at that time — it does not replace your copy. Owners can download an Evidence Pack with the full hash, the RFC 3161 token, a claims log, and openssl instructions.

How the RFC 3161 timestamp works

RFC 3161 is a public standard for trusted timestamps. A timestamp authority receives a fingerprint, records the time, and signs that pairing. The stamp does not depend on Lyricsmit remaining online to be checked against the public TSA infrastructure. It shows when that fingerprint was presented — not who wrote the song or who owns the rights.

How a recipient verifies a record

  1. Open the verification link you send them. No login is required.
  2. They see the record ID, fingerprint preview, timestamp, and whether the record is still active.
  3. If they still have the original file, they can hash it independently and compare. The same file always produces the same SHA-256 fingerprint.

Go to verify →

What Lyricsmit does not prove

Lyricsmit creates proof-of-existence records. It does not determine ownership, authorship, originality, copyright status, or legal rights. A verification page is not a copyright registration, a contract, or a court finding. Anyone who possesses a file can create a record of its fingerprint. The earliest Lyricsmit record is not proof of original creation or ownership.

Example only — not a live registry record

What a recipient sees

This is a labeled illustration of the verification screen. It is not a saved Creative Record. Lyricsmit does not publish fabricated proof data.

Status
Record found — example
Fingerprint
abcd1234… · example preview
Timestamp
Independent RFC 3161 time — shown on a real record
File
Discarded after hashing — transits the server