What does it actually mean when DAAvern says that a disclosure is “provable”?

Every published disclosure creates three separate pieces of evidence:
1️⃣ A hash proving what was published.
The relevant disclosure fields are serialised in a defined format and hashed using SHA-256. Not included is the publication time: the hash only proves what was said; not when.
A disclosure-specific secret is added when generating the hash. The issuer retains it and can provide it, where full verification is required.
2️⃣ An independent timestamp proves when the hash existed.
At publication, the hash is submitted to a time-stamping authority, which returns a signed RFC 3161 timestamp token. DAAvern verifies that the returned token relates to the submitted hash before accepting it.
This creates independently verifiable evidence that the value existed no later than the certified timestamp.
3️⃣ Public blockchain anchors supporting that evidence.
The same hash is recorded through registry contracts on several public blockchains. Each disclosure links to the relevant transactions. The platform's independent verification function also queries the chains directly rather than merely reproducing data held in DAAvern's database.
🇪🇺 What DAAvern is particularly proud of is the infrastructure behind this: The entire DAAvern platform is built on European infrastructure: The servers hosting the platform and disclosure data are located in Europe and run by a German provider. All other technical components and external service providers are European-based as well. Even attachment malware scanning takes place on the same European-hosted infrastructure rather than sending documents to an external global scanning service.
This was a conscious architectural decision. For regulatory infrastructure, DAAvern believes it matters not only what a system does, but also where its critical dependencies sit and who controls them.
DAAvern therefore combines European infrastructure with evidence that does not require users simply to trust DAAvern: timestamps can be inspected independently, blockchain transactions checked publicly and queried directly.
🧨 The next major feature extends the same principle to a related compliance workflow: the decision to delay disclosure of inside information.
Under MiCAR, delaying disclosure requires a documented assessment of the legal conditions for delay, ongoing monitoring, confidentiality safeguards and documentation supporting the notification to the competent authority.
The forthcoming DAAvern delay workflow will structure and preserve that process - creating a contemporaneous audit trail from the initial decision to delay through to publication.
❗ That is the infrastructure we want to build: European regulatory technology that does not merely facilitate compliance, but creates evidence that the right steps were taken, at the right time, for the right reasons.
(Text & image created with AI assistance, reviewed, edited, and approved by human author)


