Authors:
S. Rogit, K. N. Nawaz Sheriff, B. Mahesh Bala, V. Nivedita
Addresses:
Department of Computer Science and Engineering, SRM Institute of Science and Technology, Ramapuram, Chennai, Tamil Nadu, India.
When it comes to secure document collaboration in organisational settings, access control is not enough; it also requires end-to-end traceability of every activity that is performed on a document during its entire lifecycle. Researchers introduce TrustFlow, a full-stack framework that integrates cryptographic chain-of-custody (CoC) tracing, steganographic watermarking, Shamir threshold secret sharing, time-lock encryption, and tamper-evident audit logging into a unified document collaboration platform. TrustFlow is a full-stack framework. TrustFlow constructs a hash-linked provenance tree for each document. Within this tree, each node corresponds to an Ed25519-signed state transition, which may include uploading, sharing, revoking, or deleting. Forensic leak identification is made possible by the utilisation of three complementary steganographic watermarking modes: zero-width Unicode, linguistic synonym replacement, and whitespace encoding. All recipients are guaranteed that their documents will be destroyed in a verifiable manner using a deletion-cascade engine equipped with signed tokens and replay prevention. PostgreSQL serves as the system's database, with a Fast-API backend and a React frontend. Additionally, researchers provide an outline of a staged roadmap to complete decentralisation through the use of abstract backend interfaces, blockchain anchoring, and threshold-gated access controls.
Keywords: Chain-of-Custody; Document Traceability; Steganographic Watermarking; Shamir Secret Sharing; Time-Lock Encryption; Tamper-Evident Logging; Access Control Lists.
Received on: 28/03/2025, Revised on: 25/05/2025, Accepted on: 02/09/2025, Published on: 12/06/2026
DOI: 10.69888/FTSCS.2026.000684
FMDB Transactions on Sustainable Computing Systems, 2026 Vol. 4 No. 2, Pages: 78-96