The Sigilbase mark now exists as a physical object — a 25mm brass die that leaves its impression in wax. It connects a centuries-old practice of sealing letters to how modern audit records prove they have not been altered.
To understand why sigilbase mark made brass is more than a design choice, it helps to look at how the die was cut, what a seal actually does, and why an analogue object still matters for a digital ledger.
How it was made
The mark is built around a single letter: an S set in Libre Caslon Text Bold. That is an openly licensed revival of William Caslon's type, and the same family this site is set in.
The constraint was physical. Engraving puts a floor under stroke width. Caslon's hairlines are fine by design, and below a certain width a stroke is simply not cut at all. The team measured the thinnest strokes of the S at several sizes and set it at a 15mm cap height — the smallest size at which the hairlines remain wide enough to engrave cleanly.
The S is surrounded by a single ring, 0.8mm wide at 23mm across, on a 25mm face. The die itself was cut in London by The Little Blue Brush, and like all seal dies, it is cut in mirror — on the brass the S reads backwards, so the wax impression reads correctly.

Image adjusted with ChatGPT from a photograph of the wax impression.

Image adjusted with ChatGPT from a photograph of the die, where the S appears reversed.
Why a seal at all
A wax seal historically did two distinct jobs.
First, the impression said who sent the letter, because only the sender held the die. Second, the wax said whether anyone had opened it, because the envelope could not be opened without breaking the wax. The seal never prevented someone from reading the letter. It made the reading visible.
Sigilbase applies the same principle to audit records, in different materials. Each checkpoint is signed with Sigilbase's key, which attests to who sealed it. Each event is hash-chained to the one before it, so any later change breaks the chain at the exact record where it occurred. Neither step prevents tampering. Both make it evident.
That is the core distinction between tamper-evident and tamper-proof, and the subject of what tamper-evident logs are and why they matter. As noted in context via StartupHub.ai, this is a deliberate design choice: make interference detectable and precisely locatable, rather than claiming it is impossible.
The analogy also holds for its limits, which matter more to the team than the capabilities. A seal tells you nobody opened the letter, and nothing about whether the letter itself is true. A Sigilbase record proves it has not changed since it was received, and nothing about whether it was accurate when it arrived. The project states the second part wherever it states the first.
The name was already pointing here. Sigil comes from the Latin sigillum, meaning seal.
Why analogue in a digital system
The deeper reason why Sigilbase mark made brass comes down to trust and differentiation.
The cryptography behind Sigilbase is standard on purpose. Standard constructions are the ones independent reviewers already trust, and the verifier is open so anyone can check how those primitives are used. The consequence is that the descriptive language — tamper-evident, verifiable offline — is shared across the entire category. Anyone can put those words on a homepage.
An object is harder to share. A die takes a maker and a week to cut, and nobody gets one by editing a page. It cannot be copied by changing copy.
There is a plainer reason as well. The people Sigilbase most wants to reach are assessors, who read evidence for a living and receive a great deal of email. Very little of their post arrives sealed. A physical letter sealed in wax stands out precisely because it is uncommon, and because it signals care in handling evidence.
The letters: sealed twice
Letters are now going out to UK assessors, and each is sealed twice.
The first seal is wax, pressed with the brass die described above. The second is the letter itself, sealed into the Sigilbase ledger before it is posted.
Each letter includes a small record card carrying its number and a private link. At that link, the holder can check that the letter in their hand is the one that was sealed. The ledger holds only the letter's fingerprint — a cryptographic hash — which reveals nothing about who it was sent to or what it says.
The second seal exists because the first can be beaten. Wax can be lifted with a warm blade and pressed back by someone patient enough, and for centuries people did exactly that. Nobody lifts a hash with a knife.
Asking why Sigilbase mark made brass ultimately leads back to that pairing. The wax seal is familiar, tactile, and human-readable. The hash seal is invisible, mathematical, and machine-verifiable. One can be defeated with craft; the other cannot.
The same limit applies here as with the ledger itself. Checking the letter proves it has not changed since it was sealed. Whether its argument holds is for the reader to judge.
What this approach clarifies
1. Tamper-evident is not tamper-proof. The value is not in preventing interference, but in making it undeniably visible and locating exactly where it happened.
2. Provenance is separate from truth. A seal — whether wax or cryptographic — attests to integrity since sealing, not to accuracy at creation. Both claims need to be evaluated independently.
3. Physical artifacts still carry signal. In a digital environment where claims are cheap to replicate, a brass die that required a craftsperson, measurement, and time communicates commitment in a way text on a page cannot.
If one of these letters reaches you, break the wax. That is what it is for.
Top comments (0)