PRI · Applied Product — Proof of Authorship
Prima Evidence — Source Code
Source code for a proof-of-authorship web service: files are hashed in the browser, the hash is recorded on Arweave, and a Cloudflare Workers backend handles accounts, Flutterwave payments and an admin console.
Maturity. Every proof writes the registrant's email address in plain text into its public Arweave record, where it can never be deleted (finding PRI-3, open). This conflicts with data-erasure rights under laws such as the GDPR and Nigeria's NDPA, and with the privacy wording in the shipped docs. Change the record format before you write any proofs. The critical payment flaw found in review is fixed in the source you receive.
Overview
Prima Evidence records that a file existed at a point in time. The browser computes the file's SHA-256 hash with the Web Crypto API, so the file itself is not uploaded. When a proof is confirmed (paid, from a credit balance or as a free trial), the backend writes a JSON record holding the hash, the proof id, a timestamp and the registrant's email to Arweave. It uses the Irys bundler first and falls back to a direct Arweave transaction.
The source has six packages. The backend is a Cloudflare Worker built with Hono, using KV, four Durable Objects, a queue for Arweave uploads and a five-minute cron. There are two web front ends: a React 18 and Vite app with a user dashboard and admin pages, and a Next.js 15 website in English and Japanese. There are Node and Python client SDKs. There is also a marketing-automation worker (prima-agent) that uses the Anthropic API, X and Resend.
It ships with the Prima Evidence brand. The code references the primaevidence.com domain 135 times across 78 files, and the website and agent carry Vlaander contact addresses. A buyer running it under its own name must replace these and rewrite the legal pages.
The problem
A document-timestamping service needs client-side hashing so files stay private, a permanent public record, accounts and payments, and an operator console. This source provides a working implementation of each, built for Cloudflare Workers, Flutterwave and Arweave.
What it does
- Client-side SHA-256 hashing in the browser; files are not uploaded.
- Proof records written to Arweave through the Irys bundler, with a direct Arweave transaction as fallback and a circuit breaker around both.
- Public lookup by hash. It reads the backend's own store, not the chain. A separate endpoint checks an Arweave transaction against the service wallet's address.
- Accounts with scrypt password hashing, JWT sessions (jose), optional TOTP two-factor login, and hashed developer API keys for a versioned API.
- Flutterwave payments for single proofs, batches and prepaid credit packs, with a constant-time webhook secret check; a free trial proof; printable certificate pages.
- Admin routes and pages for proofs, users and statistics, plus Resend or SendGrid email and KV-based rate limiting.
- GitHub Actions: CI type-checks and tests the backend, website and agent; the deploy workflow deploys the backend and website.
Performance
No benchmark figuresPRI publishes no benchmark figure, so its value rests on the assurance and scope below rather than on a number to reproduce.
Value in your own metrics
- File confidentiality
- Only the hash leaves the browser. The file content never reaches the backend or the chain.
- Permanence
- Each paid proof becomes a public Arweave record that the operator cannot alter or delete afterwards.
- Serverless operation
- Backend, uploads and scheduled jobs run on Cloudflare Workers, KV, Durable Objects and Queues, so there are no servers to manage.
- Developer access
- Proofs can be created through a versioned HTTP API with API keys, or through the Node and Python SDKs.
Assurance and build
- Language
- TypeScript (strict mode in every TypeScript package) · Python SDK
- Frameworks
- Hono on Cloudflare Workers · React 18 with Vite · Next.js 15.5.2 via @cloudflare/next-on-pages
- Edge runtime
- Cloudflare Workers · KV · Durable Objects · Queues · Cron Triggers; D1 for the agent
- External services
- Flutterwave · Irys and Arweave · Resend or SendGrid · Anthropic API, X and Resend (agent)
- Integrity
- Client-side SHA-256 · records on Arweave
- Tests
- Backend: 621 of 621 Vitest cases passing in the Cloudflare Workers pool, run by Vlaander's quality gate on 7 October 2026 and again from the delivered archive on 8 October 2026, with tsc clean. Agent: 323 of 323 passing (Vlaander, 5 October 2026; agent code unchanged since). In the same run, 4 of the Next.js website's pricing tests failed. The React app's unit and Playwright tests are not run by CI and were not re-run by Vlaander. The SDKs have no tests
- Internal review
- Vlaander quality gate, 7 October 2026: 1 critical and 6 high findings. Fixed in the delivered source (8 October 2026): any successful Flutterwave transaction could mark any proof as paid; credit packs could be bought in a cheaper currency; the Node SDK hashed the wrong bytes. Open: customer emails written permanently to Arweave; a stored cross-site-scripting sink in the website's articles; deploy settings (reported, not reproduced): npm run deploy and the runbook use the development configuration, and CI deploys to a differently named production worker. About 16 medium findings were reported and not fixed.
Releases are not yet cryptographically signed, and no release manifests or external audit summaries are published. Check the source tarball you receive against its SHA-256 in Schedule 1 of your Sale and Assignment Agreement, which you see before you sign.
Scope and maturity
What is real today, what is deliberately excluded, and what is pending — published unprompted.
Included today
- Backend: a Cloudflare Worker (Hono, KV, Durable Objects, Queues, JWT, Flutterwave, Arweave and Irys), with its Vitest suite.
- Front ends: a React 18 and Vite app with user dashboard and admin pages, and a Next.js 15 website in English and Japanese.
- Node and Python client SDKs, a marketing-automation worker (prima-agent), GitHub Actions workflows, a runbook and setup guides for Arweave and Flutterwave.
Explicitly scoped out
- A focused proof-of-authorship service, not a general document-management platform.
- The purchase delivers the source archive only. Domain names, any running Prima Evidence deployment with its users and data, and third-party accounts, keys and wallets are not included.
Pending
- Open review findings: emails in public Arweave records (PRI-3), the website's article XSS sink (PRI-5) and the deploy configuration (PRI-6). Reported, not fixed: an email recoverable from a file hash, incomplete Arweave verification, a non-atomic credit idempotency check, and Next.js 15.5.2, which is inside the range of a December 2025 advisory fixed in 15.5.7.
- Lookup by hash does not check the chain. Verification against Arweave returns 503 until the operator sets the service wallet address.
- Rebranding: primaevidence.com, Vlaander contact addresses and a personal email address in the runbook must be replaced.
- Live operation, scaling and any regulatory posture are the acquirer's responsibility.
Who it's for
- Legal technology and intellectual-property services firms adding a timestamping product line.
- Notarisation, registry and records businesses digitising evidentiary services.
- Creative-industry platforms serving authorship and provenance claims.
Before you buy
- Decide how the proof record should identify a registrant without plain-text email (for example, a salted hash) before any proofs are written.
- Read Vlaander's review report and confirm the open findings are fixed before launch.
- Run wrangler deployments list and check the production worker name, vars and prices before any redeploy.
- Confirm the Arweave and Irys cost per proof and who funds the upload wallet at your projected volume.
- Establish, with counsel, the evidentiary weight a hash timestamp carries in your target jurisdictions.
- Review the Flutterwave integration against your payment and acquirer requirements.
- Review the prima-agent worker before enabling it: auto-approval of posts from the brand X account is on by default, and it ships seed data aimed at the Japanese and Nigerian markets.
What transfers
- The asset's sourceSubject to the Sale and Assignment Agreement, Vlaander assigns to the verified Buyer the transferable right, title and interest that Vlaander owns in the specified Asset. The assignment excludes Third Party Materials, open-source components, Vlaander’s pre-existing tools, generic know-how, development methods, trademarks, confidential information and any rights that cannot lawfully be assigned.
- Its testsThe test suite the published assurance claims rest on, as delivered in the source archive.
- Its audit artefactsSpecifications, model-checking output, reviews and the software bill of materials, where the asset has them.
- Not includedThird-party and open-source materials are not sold or assigned by Vlaander. They remain under their own licences, listed in each asset’s software bill of materials (SBOM.md in the archive), and the Buyer is responsible for complying with those licences.
First described in: VLA-GEN catalogue, 3 August 2026, §3.9. Revised by Vlaander against the delivered source; every figure is labelled with its basis.
From test to source
- 01
Check
Read the engine's page: what Vlaander measured and on which hardware, what it has not measured, and the open review findings. Nothing runs before purchase.
- 02
Buy
Verified businesses only. Place the order, give your company's details, have your authorised signatory sign the Sale and Assignment Agreement, then pay the invoice in naira by bank transfer, or in USDC on Polygon. Once the payment is verified, your account shows Paid.
- 03
Receive
We confirm the funds and release the source tarball to you. Delivering, then Download ready. Check it against the SHA-256 in Schedule 1, then rerun the tests and benchmarks yourself.