Sealed deposit
A document once deposited can no longer be modified or deleted before its due date, including by a system administrator.
A vault where a document arrives, receives its fingerprint and its timestamp, stops moving, and deletes itself once the legal period has run.
Status : In preparation. Sold alongside the processing register rather than on its own. Sheet updated 11 September 2026.
Swiss accounting law requires books, accounting records and the annual report to be kept for ten years. The ordinance on the keeping and preservation of account books adds a less familiar requirement: where the medium can be altered, integrity must be guaranteed by a technical means, timestamping for instance.
A folder on a shared drive meets neither condition. It can be changed without a trace, and it proves nothing on the day it is asked to prove something.
Modules that do this correctly do exist, but inside an enterprise resource planning suite, which means taking the suite along with them.
Immutability is not a setting an administrator can lift. It is a property of the vault, and the log shows it was not lifted.
A document once deposited can no longer be modified or deleted before its due date, including by a system administrator.
Every entry receives its fingerprint and its timestamp. That pair is what demonstrates, years later, that the document is the one that was deposited.
Who deposited, who consulted, when, and what was attempted without succeeding. The log is itself tamper-evident.
A sealed export with its integrity evidence, in a format the audit firm can open without our software.
Once the legal period has run, the document is deleted. Keeping it longer is not more prudent, it is a different breach.
Archives already accumulated come in as a batch, with the original date preserved and the deposit date recorded separately.
Platforms
Audit-proof archiving demonstrates that a document has not changed. It says nothing about what it contained on the day it was created.
It keeps, but it does not prove. The question asked during an inspection is not whether the document still exists, it is whether it is the same one. Without a fingerprint and a timestamp, the answer rests on the word of whoever runs the storage.
On infrastructure located in Switzerland, with a copy in a second Swiss data centre. The location is in the contract.
The sealed export exists for that and runs at any time. It opens without our software, otherwise the archive would depend on our survival, which is a poor idea for a ten-year obligation.
Early access goes to organisations willing to be involved in getting it right. Tell us which one concerns you and what you do instead today.
Write to us