In the end, records are kept to be shown to someone — an examiner, an auditor, a court. nanalStamp has four proof instruments, all starting from a note's proof & timeline. Pick by who's receiving.
1. Certificate PDF — when they want paper
"Issue certificate (PDF)" saves to nanalStamp/certificates/ and opens it.

A certificate under the nanalLabs issuer name — issue number, SHA-256 hash, sealing time, Bitcoin anchor, issuer signature, and a public verification URL with QR. Need proof as of a past version? Choose the reference point in the submission-package flow.
2. Public verification link — facts public, content private
"Create public verification link" copies a nanalstamp.com/v/… URL — the same one printed on the certificate.

What the recipient sees, no login required — "🔒 original content is not disclosed." Hash, time, and block only; once anchored, "✅ sealed in Bitcoin block #N · no tampering" with a block-explorer link. You prove "the record existed that day" without showing a word of it.
3. Verifying without our server — the offline bundle
Choose "this note only" in the submission package and you get the original plus a .nanalproof bundle (original, proof, VERIFY.md instructions). Drop both into np-verify:

"📝 Sealed (chain verified OK)" — bundle-original match, chain integrity, and server signature all judged entirely inside your browser; nothing is sent anywhere. You never have to hand us a confidential document to verify it.
Does it catch tampering? Change one character of the original and re-check:

"❌ This original does not match the proof bundle" — same character count, different hash. Chain and signature still pass, which is exactly what isolates the change to the original.
4. The submission package — one zip for audits
For bundled submissions — patent examination, project audits — use ribbon → "Create submission package (.zip)": originals, the seal chain, Bitcoin evidence, RFC 3161 trusted timestamps (.tsr), certificate PDFs, and a verifier program in one zip.
The core design is the disposition ledger: inside the zip, every sequence number in the chain is listed with its disposition — included / superseded / after-cutoff / awaiting-anchor / out-of-scope. Submitted material is a subset of the chain, and silence about omissions would be indistinguishable from hiding unfavorable records. The recipient's verifier computes the "should exist" list from the chain itself — catching even the forgery that deletes a note and its ledger entry together.
Which instrument, when
| Situation | Instrument |
|---|---|
| They want a document | Certificate PDF |
| One link should settle it | Public verification link |
| They don't trust our service | Offline bundle + np-verify (or standard tools) |
| Bundled audit/examination submission | Submission package (.zip) |
nanalLabs Blog