{"id":"profile-pgd-wst-v1","title":"Preservation profile pgd-wst-v1","version":1,"status":"in_force","in_force_from":"2026-10-11","url":"https://trustbeat.eu/preservation/profile/pgd-wst-v1","markdown":"# Preservation profile `pgd-wst-v1`\n\nWritten to ETSI TS 119 511 V1.1.1 §6.4. Once published, this text does not change (OVR-6.4-13): changes\ngo into the evidence policy, or into a new profile.\n\n| Element (OVR-6.4-04) | Value |\n|---|---|\n| **a) Identifier** | `https://trustbeat.eu/preservation/profile/pgd-wst-v1` |\n| **e) Storage model** | **WST**, preservation service with storage |\n| **f) Preservation goal** | **PGD**, preservation of general data: proof of existence and integrity of submitted hash values |\n| **d) Validity period** | Active from **2026-10-11**. No end date. Also covers earlier submissions from 2026-09-14 on whose batch has an RFC 4998 evidence record (see *Scope*). |\n| **c) Technical policies** | Preservation evidence policy: `https://trustbeat.eu/preservation/evidence-policy` ([version 1](evidence-policy-v1.md); versioned; the version in force at each date is public, OVR-6.4-14). No signature validation policy: the goal is not PDS. |\n| **g) Evidence formats** | RFC 4998 Evidence Record (DER) |\n| **h) Specification** | This document |\n| **i) Description** | Below, in English. A Czech translation will follow; the English text takes precedence (OVR-6.5-02 by analogy). |\n| **j) Preservation scheme** | None referenced |\n\n## Description\n\nTrustBeat receives **hash values only**, never the data they were computed from. For each submitted\nhash it creates evidence that the hash existed at a certain time and has not changed since, and keeps\nthat evidence valid for the **preservation period**.\n\n- **The proof covers the hash, not the data.** It proves the existence of the data the hash was\n  computed from only as long as the hash algorithm stays collision-resistant. Keeping the data, and\n  computing the hash correctly, is the subscriber's responsibility (OVR-6.2-08, TS 119 511 §4.2).\n- **Evidence.** Hashes received in the same 10-minute cycle are combined in a hash tree. The tree root\n  is time-stamped by an EU qualified time-stamping authority. Each hash gets an RFC 4998 evidence record\n  linking it to that time-stamp.\n- **Preservation period.** **30 years from submission**, on every plan, free included. A subscriber\n  agreement may set a different period. Time-stamp renewal keeps the evidence verifiable for the whole\n  period. SHA-256 may weaken within 30 years, and TrustBeat cannot re-hash the data: it holds only the\n  submitted SHA-256 hash, which proves the original data only while SHA-256 stays collision-resistant\n  (OVR-6.2-08). Protection against that needs new hash values from the subscriber (evidence policy §4).\n- **Renewal (augmentation).** During the preservation period TrustBeat renews the evidence before it\n  stops being verifiable, by RFC 4998 time-stamp renewal (§5.2), before the time-stamping certificate\n  expires or its algorithms weaken. Hash-tree renewal (§5.3) needs the data re-hashed, which TrustBeat\n  cannot do from a hash alone. When and how is stated in the evidence policy (OVR-6.5-07).\n- **End of the preservation period.** When a record's period ends, TrustBeat notifies the subscriber\n  by email and makes its export-import package available (hashes, evidence records and validation\n  data). **30 days later** TrustBeat removes the record's link to the subscriber and its metadata and\n  stops serving its evidence, whether or not the package was downloaded; the batch's shared hash tree\n  and time-stamps are deleted once every record of the batch has reached that point. Renewal stops at\n  the end of the period (OVR-6.1-09). There is no deletion before the end of the period, also not on\n  request (practice statement §6).\n\n## Scope\n\nThe profile covers every submission accepted from **2026-09-14** on whose batch has an RFC 4998\nevidence record, and every submission after publication. 2026-09-14 is when TrustBeat began creating\nRFC 4998 evidence records; earlier submissions have none and are not covered. For a covered submission\nthe preservation period counts from the submission date, also when it predates publication.\n\n## Supported operations (OVR-6.4-04 b, PRP-8.1)\n\nTrustBeat uses its own REST API, documented at `https://api.trustbeat.eu/docs`, rather than the\nTS 119 512 protocol (PRP-8.1-02 is a recommendation).\n\n| Operation | TS 119 512 equivalent | Endpoint | Input formats | Output formats |\n|---|---|---|---|---|\n| Preserve | `PreservePO` | `POST /v1/anchor`, `POST /v1/anchor/batch` | A hash value, hex-encoded: **SHA-256** only (64 hex characters; anything else is rejected). | Preservation object identifier (`id`) |\n| Retrieve evidence | `RetrievePO` | `GET /v1/public/proof/{id}/evidence-record.ers` | Identifier | RFC 4998 evidence record (DER) |\n| | | `GET /v1/anchor/{id}/proof` | Identifier | Additional output format: RFC 3161 token over an RFC 6962 Merkle root, with the inclusion proof (JSON) |\n| Retrieve profiles | `RetrieveInfo` | `GET /v1/preservation/profiles` | None | This profile and every earlier one (JSON) |\n| Retrieve profile and period of an object | (PRP-8.1-04) | `GET /v1/anchor/{id}/status` (`preservation`) | Identifier | Profile identifier and end of the preservation period |\n| Delete | `DeletePO` | **Not offered.** A subscriber cannot delete a preservation object; TrustBeat deletes it only at the end of its preservation period (see *Description*). | | |\n| Export-import package | (§7.16) | `GET /v1/preservation/export` (format: practice statement §5) | Submission window (at most 31 days) | ZIP: manifest with hashes and preservation metadata, RFC 4998 evidence records with embedded validation data, Trusted Lists in force; every release recorded |\n| Validate evidence (optional) | `ValidateEvidence` | `GET /v1/anchor/{id}/verify`, `POST /v1/public/verify` | Identifier, or hash + evidence | Validation result |\n\nThe RFC 6962 inclusion proof is an **additional output format** (OVR-6.4-04 b), not the preservation\nevidence: only the RFC 4998 evidence record is renewed.\n","html":"<h1>Preservation profile <code>pgd-wst-v1</code></h1>\n<p>Written to ETSI TS 119 511 V1.1.1 §6.4. Once published, this text does not change (OVR-6.4-13): changes\ngo into the evidence policy, or into a new profile.</p>\n<table>\n<thead>\n<tr>\n<th>Element (OVR-6.4-04)</th>\n<th>Value</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><strong>a) Identifier</strong></td>\n<td><code>https://trustbeat.eu/preservation/profile/pgd-wst-v1</code></td>\n</tr>\n<tr>\n<td><strong>e) Storage model</strong></td>\n<td><strong>WST</strong>, preservation service with storage</td>\n</tr>\n<tr>\n<td><strong>f) Preservation goal</strong></td>\n<td><strong>PGD</strong>, preservation of general data: proof of existence and integrity of submitted hash values</td>\n</tr>\n<tr>\n<td><strong>d) Validity period</strong></td>\n<td>Active from <strong>2026-10-11</strong>. No end date. Also covers earlier submissions from 2026-09-14 on whose batch has an RFC 4998 evidence record (see <em>Scope</em>).</td>\n</tr>\n<tr>\n<td><strong>c) Technical policies</strong></td>\n<td>Preservation evidence policy: <code>https://trustbeat.eu/preservation/evidence-policy</code> (<a href=\"/preservation/evidence-policy\">version 1</a>; versioned; the version in force at each date is public, OVR-6.4-14). No signature validation policy: the goal is not PDS.</td>\n</tr>\n<tr>\n<td><strong>g) Evidence formats</strong></td>\n<td>RFC 4998 Evidence Record (DER)</td>\n</tr>\n<tr>\n<td><strong>h) Specification</strong></td>\n<td>This document</td>\n</tr>\n<tr>\n<td><strong>i) Description</strong></td>\n<td>Below, in English. A Czech translation will follow; the English text takes precedence (OVR-6.5-02 by analogy).</td>\n</tr>\n<tr>\n<td><strong>j) Preservation scheme</strong></td>\n<td>None referenced</td>\n</tr>\n</tbody>\n</table>\n<h2>Description</h2>\n<p>TrustBeat receives <strong>hash values only</strong>, never the data they were computed from. For each submitted\nhash it creates evidence that the hash existed at a certain time and has not changed since, and keeps\nthat evidence valid for the <strong>preservation period</strong>.</p>\n<ul>\n<li><strong>The proof covers the hash, not the data.</strong> It proves the existence of the data the hash was\ncomputed from only as long as the hash algorithm stays collision-resistant. Keeping the data, and\ncomputing the hash correctly, is the subscriber's responsibility (OVR-6.2-08, TS 119 511 §4.2).</li>\n<li><strong>Evidence.</strong> Hashes received in the same 10-minute cycle are combined in a hash tree. The tree root\nis time-stamped by an EU qualified time-stamping authority. Each hash gets an RFC 4998 evidence record\nlinking it to that time-stamp.</li>\n<li><strong>Preservation period.</strong> <strong>30 years from submission</strong>, on every plan, free included. A subscriber\nagreement may set a different period. Time-stamp renewal keeps the evidence verifiable for the whole\nperiod. SHA-256 may weaken within 30 years, and TrustBeat cannot re-hash the data: it holds only the\nsubmitted SHA-256 hash, which proves the original data only while SHA-256 stays collision-resistant\n(OVR-6.2-08). Protection against that needs new hash values from the subscriber (evidence policy §4).</li>\n<li><strong>Renewal (augmentation).</strong> During the preservation period TrustBeat renews the evidence before it\nstops being verifiable, by RFC 4998 time-stamp renewal (§5.2), before the time-stamping certificate\nexpires or its algorithms weaken. Hash-tree renewal (§5.3) needs the data re-hashed, which TrustBeat\ncannot do from a hash alone. When and how is stated in the evidence policy (OVR-6.5-07).</li>\n<li><strong>End of the preservation period.</strong> When a record's period ends, TrustBeat notifies the subscriber\nby email and makes its export-import package available (hashes, evidence records and validation\ndata). <strong>30 days later</strong> TrustBeat removes the record's link to the subscriber and its metadata and\nstops serving its evidence, whether or not the package was downloaded; the batch's shared hash tree\nand time-stamps are deleted once every record of the batch has reached that point. Renewal stops at\nthe end of the period (OVR-6.1-09). There is no deletion before the end of the period, also not on\nrequest (practice statement §6).</li>\n</ul>\n<h2>Scope</h2>\n<p>The profile covers every submission accepted from <strong>2026-09-14</strong> on whose batch has an RFC 4998\nevidence record, and every submission after publication. 2026-09-14 is when TrustBeat began creating\nRFC 4998 evidence records; earlier submissions have none and are not covered. For a covered submission\nthe preservation period counts from the submission date, also when it predates publication.</p>\n<h2>Supported operations (OVR-6.4-04 b, PRP-8.1)</h2>\n<p>TrustBeat uses its own REST API, documented at <code>https://api.trustbeat.eu/docs</code>, rather than the\nTS 119 512 protocol (PRP-8.1-02 is a recommendation).</p>\n<table>\n<thead>\n<tr>\n<th>Operation</th>\n<th>TS 119 512 equivalent</th>\n<th>Endpoint</th>\n<th>Input formats</th>\n<th>Output formats</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Preserve</td>\n<td><code>PreservePO</code></td>\n<td><code>POST /v1/anchor</code>, <code>POST /v1/anchor/batch</code></td>\n<td>A hash value, hex-encoded: <strong>SHA-256</strong> only (64 hex characters; anything else is rejected).</td>\n<td>Preservation object identifier (<code>id</code>)</td>\n</tr>\n<tr>\n<td>Retrieve evidence</td>\n<td><code>RetrievePO</code></td>\n<td><code>GET /v1/public/proof/{id}/evidence-record.ers</code></td>\n<td>Identifier</td>\n<td>RFC 4998 evidence record (DER)</td>\n</tr>\n<tr>\n<td></td>\n<td></td>\n<td><code>GET /v1/anchor/{id}/proof</code></td>\n<td>Identifier</td>\n<td>Additional output format: RFC 3161 token over an RFC 6962 Merkle root, with the inclusion proof (JSON)</td>\n</tr>\n<tr>\n<td>Retrieve profiles</td>\n<td><code>RetrieveInfo</code></td>\n<td><code>GET /v1/preservation/profiles</code></td>\n<td>None</td>\n<td>This profile and every earlier one (JSON)</td>\n</tr>\n<tr>\n<td>Retrieve profile and period of an object</td>\n<td>(PRP-8.1-04)</td>\n<td><code>GET /v1/anchor/{id}/status</code> (<code>preservation</code>)</td>\n<td>Identifier</td>\n<td>Profile identifier and end of the preservation period</td>\n</tr>\n<tr>\n<td>Delete</td>\n<td><code>DeletePO</code></td>\n<td><strong>Not offered.</strong> A subscriber cannot delete a preservation object; TrustBeat deletes it only at the end of its preservation period (see <em>Description</em>).</td>\n<td></td>\n<td></td>\n</tr>\n<tr>\n<td>Export-import package</td>\n<td>(§7.16)</td>\n<td><code>GET /v1/preservation/export</code> (format: practice statement §5)</td>\n<td>Submission window (at most 31 days)</td>\n<td>ZIP: manifest with hashes and preservation metadata, RFC 4998 evidence records with embedded validation data, Trusted Lists in force; every release recorded</td>\n</tr>\n<tr>\n<td>Validate evidence (optional)</td>\n<td><code>ValidateEvidence</code></td>\n<td><code>GET /v1/anchor/{id}/verify</code>, <code>POST /v1/public/verify</code></td>\n<td>Identifier, or hash + evidence</td>\n<td>Validation result</td>\n</tr>\n</tbody>\n</table>\n<p>The RFC 6962 inclusion proof is an <strong>additional output format</strong> (OVR-6.4-04 b), not the preservation\nevidence: only the RFC 4998 evidence record is renewed.</p>\n"}