Signed certificate: forensic proof for music disputes
When the time comes to file a claim with a distributor that rejected your track by mistake, report an unauthorized copy, or defend your credits in a dispute — you need technical evidence, not an email from you. DistroShield's certificate is a signed PDF with a verifiable SHA-256 hash. Here's how it works and why the hash is what turns it into real proof.
What exactly is a signed certificate
When you pay for an analysis (PAYG credit or Pro+), you get access to download two separate PDFs from the result page:
- Full technical report — detailed analysis with verdict, signals, catalog matches, generator attribution if applicable, etc. Meant for you.
- Signed certificate — a one-page PDF, formatted as an official document, containing: identified track, verdict, model version, UTC timestamp, unique certificate ID, and a verifiable SHA-256 hash. Meant to present to a third party.
The critical difference: the report is information. The certificate is auditable evidence.
Why the hash is what turns it into proof
Anyone can make a PDF that looks official. Copy the design, add a logo, print it. A distributor / DSP / lawyer receiving a PDF like that has no way to know if it's real or fake.
Our certificate includes:
- A unique certificate ID with the
cert_prefix - A SHA-256 hash of the content — 64 hex characters representing the cryptographic signature of the analysis's key fields (verdict, ai_score, model version, ISRC, timestamp)
- A public verification URL:
https://distroshield.com/verify
Anyone with the certificate ID can go to that URL, paste it, and instantly confirm whether the hash matches what we issued. If it matches: green, valid certificate. If it doesn't (because someone altered the PDF): red, not recognized.
The key: you don't have to prove the certificate is real. The third party can verify it themselves against our public endpoint. That's what makes it useful evidence in a real dispute.
Five variants depending on the case
The certificate adapts to the actual analysis context. Five types:
1. Human-origin certificate
When the analysis came back likely human with no cross-distributor duplicates. Useful as technical evidence of human authorship — for research, due diligence before licensing, or as backup if someone marks the track as AI-generated by mistake in the future.
2. Cross-distributor duplicate certificate
When the same recording appears in multiple catalogs under different artist names. The certificate documents each occurrence — ready to file a takedown request with the infringing distributor or DSP.
3. AI-generated content certificate
When the analysis identified AI content. Useful as an internal moderation record, communication with the artist, or evidence if the artist claims human origin.
4. Cross-distributor AI-content certificate
Critical combination: AI content + cross-distributor duplicates. This is the coordinated fraud scenario. Certificate + technical report ready for a coordinated takedown or DSP moderation report.
5. Technical certificate (uncertain verdict)
When the model was ambiguous. The certificate documents exactly which signals produced that ambiguity — useful for later review with human context.
In each case the certificate copy adapts to the actual analysis. It doesn't oversell or overaccuse. It documents what was detected and offers the right words for the use case.
How to use it in practice
Typical flow:
- You analyze the track. Pay $5 (credit) or use your Pro+.
- Download the signed certificate from the result page.
- Attach the PDF to your email/claim to the distributor, DSP, or rights team. In the body of the email include the certificate ID and the verification URL (
https://distroshield.com/verify). - The recipient opens the URL, pastes the ID, and confirms in 2 seconds that the document is authentic.
- The conversation starts with audited technical evidence, not with an assertion from you.
Scope and limitations
To be honest:
- The certificate is not a legal determination. It's a technical signal of our model's result at issuance time. A judge can give it whatever weight they decide.
- The hash proves document integrity, not authenticity of the underlying facts. That the certificate is real doesn't prove whoever generated it has rights — it proves DistroShield performed that analysis with that result.
- AI detection has inherent uncertainty. The certificate documents the model's verdict, not an absolute truth.
All of that is written in the certificate itself, in the "Scope" section. No inflated language.
When it's worth having one
Concrete cases where $5 for one pays off:
- A distributor rejected your track flagging it as AI when it's human — you download the certificate and attach it in your appeal.
- You discovered someone uploaded a copy of your song to another distributor — you download the certificate with duplication details and send it to the infringing distributor.
- A DSP marks your track as AI-generated and asks for backup — the certificate documents the technical analysis.
- You're about to license a catalog and need due diligence on each track — each certificate stays in your archive.
- Your legal team needs auditable technical evidence for a formal dispute — the certificate is exactly that.
Certificates are part of the PAYG and Pro+ plans and their use is subject to the Terms. No certificate replaces professional legal advice.