Export fingerprints
What the SHA-256 fingerprint printed on documents is for, how to read it and how to verify a file or an archive.
Every export carries a fingerprint: a string of characters calculated from the data of the document. It lets you verify, months or years later, that a statement still matches the original data and that an archived file has not been modified.
Two fingerprints, two uses
| Fingerprint | Calculated on | Where to find it | What it proves |
|---|---|---|---|
| Statement fingerprint | The accounting data of the statement (lines, amounts, totals) | Footer of the PDFs (first 16 characters), title rows of the Excel files, audit trail | Two issues carry the same data |
| File fingerprint | The binary content of a file of the archive | manifest.json and table of files of the cover PDF of the full dossier |
The file has not been modified since generation |
Both use the SHA-256 algorithm.
The statement fingerprint
The statement fingerprint depends only on the data. It depends neither on the issue date, nor on the author, nor on the format. In practice:
- the same statement issued twice on unchanged data carries the same fingerprint, in PDF as in Excel;
- if a single entry of the period has been added or reversed between the two issues, the fingerprint changes.
It is a simple way to answer the question "is this general ledger still up to date?": issue it again and compare the 16 characters in the footer.
When you hand a trial balance to a client or a bank, note the fingerprint in your covering e-mail. In the event of a later discussion, you will know immediately whether the document presented is the one you issued.
Where the full fingerprint is recorded
The footer only shows the beginning of the fingerprint, to remain readable. The full 64-character value is kept in two places:
- in the audit trail of the company file: every export generated is recorded there with its type, its format, the user, the date and the full fingerprint;
- in the
manifest.jsonfile of the full dossier, for each file of the archive.
The audit trail can itself be exported from the Data group of the Exports tab.
Verifying a file from an archive
- Unzip the full dossier.
- Open
manifest.jsonand find the file to verify: its fingerprint and its size in bytes are listed there. - Calculate the fingerprint of the file on your computer.
On macOS and Linux:
shasum -a 256 "01-Livres/grand-livre.pdf"
On Windows (PowerShell):
Get-FileHash "01-Livres\grand-livre.pdf" -Algorithm SHA256
- Compare the result with the value in the manifest. The two must be strictly identical.
The exact name of the files is the one given in the manifest of your archive.
A PDF saved again by a PDF reader, even without any visible change, no longer has the same file fingerprint. Keep the files as they come out of the archive.
What the fingerprint does not prove
The fingerprint attests to integrity: the content is identical to what was generated. It says nothing more.
- It is not an electronic signature: it does not legally identify a signatory.
- It is not a qualified timestamp: the generation date recorded in the manifest is that of the server, without a trusted third party.
- It does not protect against the simultaneous falsification of a file and of the manifest. This is why it is useful to keep the fingerprint of the manifest itself in a separate place, for example in your permanent file or in a covering e-mail.
If you need reinforced evidential value, for example for a dispute, supplement the archive with a qualified electronic signature or a timestamped deposit with a trust service provider. NovaFisko does not provide this service.
Frequently asked questions
Why has the fingerprint changed although I have not entered anything?
A Novadesko synchronisation, the automatic booking of a recurring entry or the action of a colleague may have added entries in the period. The History tab tells you who changed what and when.
Do CSV files carry a fingerprint?
The statement fingerprint is returned by the server for all formats and recorded in the audit trail. It is not written in the CSV file itself, so as not to disturb its import into another tool.