The passport changes after the audit
Months pass between the audit and a market inspection. A recycled-content figure that was right at sign-off may have been quietly corrected since - and the record does not show it.
A battery passport is a claim until someone can check it. Here every stored version gets a fingerprint containing the fingerprint of the previous version - and once a day we publish a root hash over all of them. Your market surveillance authority, your auditor and your customer can recompute it themselves. No account, no asking us.
Annex XIII requires data. Art. 78 additionally requires that it is authentic and unaltered. That is exactly where verifiability stops in most solutions.
Months pass between the audit and a market inspection. A recycled-content figure that was right at sign-off may have been quietly corrected since - and the record does not show it.
Whoever runs the database can write to it. A compliance tick set and checked by the same vendor proves only that they set it.
Under Art. 77(4) the economic operator is responsible for the passport. If you cannot show in a dispute what the data looked like at a given date, your vendor's software does not help you.
No blockchain, no wallet, no token. A published hash chain does the same job here and can be verified with ordinary tools.
On save, the database computes a SHA-256 value over the complete record plus the previous version's value. It happens in a database trigger - below the application, below the API, below every import path. There is no write path that gets around it.
If someone alters an old version afterwards, not one following link still fits. The public check recomputes the whole chain and reports exactly where it tears.
Once a day we form a root hash over all new links, chained to the previous day's root, and publish it. A published value cannot be made to fit afterwards - not by us either.
Every anchor is openly retrievable, including the ordered list of that day's chain links. Anyone who wants to can recompute the root hash in three lines of code.
A passport address from a QR code, a ten-character short code, or a passport identifier. The check runs on the public passport site and needs no account.
An image that shows the real status. If the chain becomes invalid, the badge says so - which is what makes it evidence rather than a sticker.
The badge links to that passport's verification page. Whoever clicks it sees the result in plain words and can download the report as a PDF.
…The proof is included in every plan, the free pilot included. There is nothing to book and nothing to configure - it is created when you save.