SealStack
MechanismConfirmReconcileTrustVerifyField
Sign in

Proof

Prove every delivery arrivedverified intact.

SealStack tracks every seal from the moment it's registered to the moment it's delivered. Every scan is recorded and signed, so you always know who touched a package and when. When something goes wrong, you settle it with the timeline, not with someone's word against another's.

Request access

Lifecycle ledger · live

RS-LAS-2026-0091·STL-LAS-0142

  1. 01

    Stocked

    [STK]Signing...

    Imported into inventory · Lagos Main

    09:11 UTC0xa7f9b001
  2. 02

    Bound

    [BND]

    Sealed to package · device verified

    – –pending
  3. 03

    Pickup

    [PCK]

    Rider scan · GPS captured

    – –pending
  4. 04

    In transit

    [TRN]

    Live signature · offline tolerated

    – –pending
  5. 05

    Delivery

    [DLV]

    Recipient scan · seal intact

    – –pending
  6. 06

    Verified

    [VRF]

    Locked in · published for anyone to check

    – –pending

1/6stations stamped

Locking in at end of day

Hover to pause. Every event signed on-device.

Reconciliation

Know the instant your recordsstop matching.

Every scan is checked against what your business system already expects, automatically. When they agree, nothing happens. When they don't, it's flagged for review right away, before it turns into a customer dispute.

Request access

Reconciliation · live

RS-LAS-2026-0091

Physical scan

Your system

Delivery status

Delivered · recipient confirmed

Delivered

Seal integrity

STL-LAS-0142 · verified intact

Seal ID matches

Evidence

Photo + signature captured

No evidence on record

Exception flagged

Routed for review

Checked against your system in real time.

01 · Problem

What happens without proof

Silent shrinkage

You can't prove when a package was opened. Disputes just get written off as 'driver error', and insurance won't cover something nobody can prove happened.

✕ Losses go unnoticed

Disputed deliveries

The customer says it arrived damaged. The driver says it was fine. Without a real record, you lose that argument, every time.

✕ You take the blame by default

Compliance theatre

PDFs and spreadsheets that nobody actually trusts. No signatures, no proof, nothing an auditor can verify.

✕ Nothing holds up to scrutiny

02 · Mechanism

How it works

Station 01

Intake

Seals are registered and assigned to a branch before they're ever used. Any seal that isn't registered gets rejected automatically.

  • org_id
  • branch_id
  • batch_id
  • file hash
  • uploader

Station 02

Bind

A package is locked to one specific seal. That action is signed by the worker's own registered device.

  • seal_id ⇄ shipment_id
  • device signature
  • GPS optional

Station 03

Scan

Every handover is scanned and signed, even with no internet connection. It syncs and records automatically once back online.

  • client + server ts
  • actor mask
  • chain hash
  • evidence ref

Station 04

Verify

Anyone can check status on a public link. Your team can verify the complete history anytime from the Audit tab.

  • public verify token
  • anchor status
  • publish date

03 · Delivery confirmation

Delivery closes the loop, then the customer can confirm it too.

The delivery scan is the final record in a package's journey. On top of that, dispatch can let the end customer confirm delivery as well, even if they don't have an account.

Customer confirmation never replaces the scan. It adds a second, independent check on the same timeline. If the two don't match, it's flagged right away instead of getting buried in a spreadsheet.

  • Bulk delivery policy

    For each shipment, dispatch decides how thorough scanning needs to be: scan every seal, spot-check some against the manifest, or check the manifest only for high-volume runs.

  • Customer confirmation

    Let customers confirm delivery too, even without an account, with a link they open or a code the rider gives them. It's recorded on the same timeline as everything else.

Sample event · raw payload

[PERSISTED]

{
  "id":               "EVT-2026-LAS-92117",
  "type":             "PUBLIC_RECEIPT_CONFIRM",
  "seal_id":          "STL-LAS-0142",
  "shipment":         "RS-LAS-2026-0091",
  "actor_role":       "receiver",
  "confirm_channel":  "customer_link",
  "code_verified":    true,
  "matches_manifest": false,
  "client_ts":        "2026-05-04T14:26:10Z",
  "server_ts":        "2026-05-04T14:26:11Z",
  "prev_hash":        "0xa7f9b491…",
  "chain_hash":       "0xa7f9b71a…"
}

Chained after DELIVERY_SCAN · unsigned, server-authored · attributable to the receiver's confirmation

04 · Reconciliation

What happened in the field, checked against what's on record.

Every scan is compared against your business system in real time. When they agree, nothing happens: that's the point. When they don't, it's flagged before it becomes a dispute.

  • Checked automatically

    Every scan is compared against what your business system already expects for that shipment. No one has to look it up.

  • Mismatches surface immediately

    If the physical record and your system don't agree, it's flagged for review right then, not discovered weeks later in a complaint.

  • No manual spreadsheet work

    Nobody is cross-checking exports by hand at month-end. The comparison happens as events come in.

Physical scan

Your system

Delivery status

Delivered · recipient confirmed

Delivered

Seal integrity

STL-LAS-0142 · verified intact

Seal ID matches

Evidence

Photo + signature captured

No evidence on record

Exception flagged

Routed for review

05 · Trust model

A record that can't be edited or faked.

Every event is written once and locked in place. Each entry links back to the one before it, so if anyone tried to alter history, it would break the chain and show up immediately. At the end of each day, that day's records are sealed for good.

  • Nothing gets edited

    Corrections are added as new entries that reference the original. The original record never changes.

  • On-device signing

    Every scan is signed by the worker's own registered device. A stolen password can't be used to rewrite the past.

  • Daily lock-in

    Each day's records are sealed together so they can't be altered afterward. Your team can verify this anytime from the Audit tab, or export the full history for an outside auditor.

Sample event · raw payload

[PERSISTED]

{
  "id":         "EVT-2026-LAS-92114",
  "type":       "DELIVERY_SCAN",
  "seal_id":    "STL-LAS-0142",
  "shipment":   "RS-LAS-2026-0091",
  "actor":      "DEV-LAG-RD-013",
  "client_ts":  "2026-05-04T14:21:08Z",
  "server_ts":  "2026-05-04T14:21:11Z",
  "lat_lng":    "[6.4541, 3.3947]",
  "evidence":   "sha256:0x4c91…d7e2",
  "prev_hash":  "0xa7f9b491…",
  "chain_hash": "0xa7f9b5fa…"
}

06 · Public verification

What the recipient sees

A read-only URL anyone can hit. No login. No app. The only thing they need is the seal id or the QR on the package.

Anyone can scan the QR code or open the link and get a clear answer, no guessing: valid · replaced · broken · suspicious · invalid.

The page only shows what you choose to share. Personal details stay hidden. Every event on it comes from the same secure record your team can verify anytime from the Audit tab, and you can export the full history for an outside auditor on request.

  • ›A clear answer: no ambiguity
  • ›Backed by a verifiable record, exportable on request
  • ›You control what's shown
  • ›No app required: pure web

/verify/ssv_live_demo

[STAMPED]

Status

VALID · INTACT

Seal
STL-LAS-0142
Shipment
RS-LAS-2026-0091
Sealed
2026-05-04 09:11 UTC
Pickup
2026-05-04 09:42 UTC
Delivery
2026-05-04 14:21 UTC

Anchor

Anchoring…· today's events settle into a Merkle root end of day

Full chain verifiable in the Audit tab

07 · Field

Built where the seals actually are

SealStack's mobile app is what your riders and warehouse staff actually carry, built for the loading bay, the back of the truck, and the front porch, not just the dashboard.

Works with no signal

Scans are saved with the real time they happened, and sync automatically the moment you're back online.

Never loses a scan

A scan that syncs late still keeps its true timestamp and gets flagged for review. Nothing is ever silently dropped.

On-device signing

Every scan is signed by the worker's own device. A stolen password can't be used to fake one.

GPS evidence

Location is captured automatically with each scan, when available, no extra steps needed.

Begin

Ship with proof. Settle disputes by timeline.

Request access
SealStack· 2026