A hash and a signature answer different questions
Integrity, provenance and factual truth are three separate checks.

The mechanism
A cryptographic hash produces a digest from data. A signature adds a statement that a corresponding signing key authorised particular bytes. Neither process independently proves that a sensor reading, service claim or document was truthful before it was recorded.
Put it into practice
Imagine a report containing an incorrect temperature. Hashing it can expose later changes; signing it can bind it to a key. Neither operation repairs the reading. A sound evidence review checks the input collection process, record integrity and signer attribution separately. Avoid using the word “verified” without naming which of those checks was performed.
Separate three verification questions
Ask first whether the bytes match the expected record, second whether the signature validates against the expected public key, and third whether the original measurement deserves trust. A positive answer to the first two questions does not force a positive answer to the third. The measurement method, instrument, observation window and reporting process still matter.
A practical receipt checklist
Keep the original file, its format version, the expected digest and the public verification material. Document exactly which bytes are checked. Do not reformat the file and assume that its digest should remain unchanged unless the format specifies a canonical representation. Record a failed comparison as a failure to match; it is not, by itself, proof of who changed the record or why.
Keep the evidence in view.
csrc.nist.gov — source & further reading ↗Checked for this edition on 7 October 2026. Examples are illustrative unless stated otherwise. Read our editorial standards.
Another angle.
Can an API be paid without building a profile of its user?
zkAPI separates metered API payments from the billing identity behind individual requests.
An AI benchmark starts with the dataset
The score is only meaningful when the evaluation conditions are clear.
A green status page is not an SLA measurement
A service-wide indicator and your own request history describe different things.


