How to Prove You Had It First: Protecting Your Preprint and Dataset Before Submission
Preprints establish priority — but posting exposes your work before it is published. Here is how researchers create timestamped, tamper-evident proof of a paper, dataset, or code before it goes out for review.
ScriptShield Team
ScriptShield
We build tools that give screenwriters and creators cryptographic proof of authorship. Because your work deserves evidence as strong as your story.

Every researcher knows the quiet fear behind the word scooped. You have spent two years on a result. You are weeks from posting the preprint. And somewhere, in a lab you have never visited, someone is closing on the same finding.
The academic answer to that fear is priority: whoever can show they had it first, wins the claim. But priority creates a paradox. To establish it, you usually have to make your work public — post the preprint, present the poster, submit to the journal. And the moment your work becomes visible, it becomes exposed: to reviewers who are also competitors, to conference audiences, to anyone who reads faster than you can publish.
What you actually want is a way to prove a specific version of your work existed, in your hands, at a specific moment — before you exposed it to anyone. That is a provenance problem, and it has a clean technical answer.
Copyright is automatic. Priority is not.
The moment you fix a manuscript in tangible form, copyright exists — automatically, in the 180-plus countries bound by the Berne Convention. That is true of your paper, your figures, and the written expression of your analysis.
But copyright protects expression, not the underlying finding — and in research, the finding is the prize. There is no registry that stamps "this person discovered this first." Priority is established by the evidentiary record: the timeline of drafts, submissions, and disclosures that shows when you knew what you knew. In a dispute, seniority and institutional weight often fill the gap where documentation should be. A timestamped record is how you stop that from happening.
Where the standard tools fall short
Researchers already reach for a few things to mark their territory. Each helps, and each leaves a gap:
- The preprint itself. Posting to a server such as arXiv or bioRxiv is the single best public priority marker we have — but it only timestamps the moment of posting, and posting is the moment of exposure. It does nothing for the months of work, and the sensitive dataset, that came before.
- Emailing yourself a copy. The academic cousin of the "poor man's copyright." A timestamp on an email you control is weak evidence — trivially backdated, easily disputed.
- Submission receipts. A journal's acknowledgement proves you submitted on a date, but it lives inside a system the other party can question, and it says nothing about the underlying data or code.
None of these gives you an independent, tamper-evident record of the work as it stood before it left your desk.
What actually works: a cryptographic fingerprint with an independent timestamp
The mechanism is the same one that has underpinned digital evidence for decades. You take the exact bytes of your work — the manuscript PDF, the dataset, the analysis script — and run them through a SHA-256 hash. Out comes a 64-character fingerprint that is unique to those exact bytes. Change a single comma in your data and the fingerprint changes completely.
That fingerprint is then sealed with an RFC 3161 trusted timestamp issued by an independent third party. The result is a record that says: this exact content existed at this exact moment — and neither you nor anyone else can move the date, because the timestamp comes from outside your control.
Crucially, the fingerprint reveals nothing about the content. That is what makes it safe to timestamp work you are not ready to show anyone.
Timestamp the whole record, not just the paper
The manuscript is the obvious thing to protect. The things that actually get contested are often everything around it:
- The dataset. Your raw and processed data — the part that is hardest to reproduce and easiest to appropriate.
- The code. Analysis scripts, models, and pipelines that encode your method.
- The methodology. Pre-registration plans and protocols that show your design predated your results.
- The figures. Key visualisations, often the first thing lifted.
Fingerprint each of these before you submit, and you hold a version chain that shows the full development of your thinking — from methodology to data to draft — with every step independently dated.
For sensitive data, the file never has to leave your device
This is the point that matters most for unpublished datasets. Because the fingerprint is computed from the content, you can generate it locally and register only the hash. Your data is never uploaded, never stored on anyone's server, never exposed — and you still walk away with an independent timestamp proving that exact dataset existed on that day. Your first proof receipt is free, and it works exactly this way: the file stays on your machine.
Tie it to your scholarly identity, not an anonymous file
A timestamp is stronger when it points unambiguously at you. Two identifiers do that work in academia, and ScriptShield records both on the certificate:
- Your ORCID iD — the persistent identifier that links a piece of work to you across everything you publish, disambiguating you from every other researcher who shares your name.
- The DOI — added once your preprint or paper is registered, so the private, pre-submission evidence links directly to the public, citable record.
And because research is rarely a solo act, every certificate can name all co-authors — each with their own ORCID iD where they have one. The record reflects the team that did the work, not just the account that uploaded the file.
The AI-disclosure question you now have to answer
Journals and funders are moving quickly to require disclosure of how AI tools were used in producing a manuscript, its analysis, or its figures. A vague "AI was used somewhere" satisfies no one. ScriptShield records a structured, three-tier declaration — Human, AI-Assisted, or AI Creative Work — timestamped and bound to the work's fingerprint, so your disclosure is part of the same tamper-evident record as your priority claim. Here is how the declaration works.
A word on what this is and is not. ScriptShield is evidence tooling, not a copyright registration and not legal advice. It records facts — what existed, when, declared by whom — in a form that is hard to dispute. Whether those facts settle a given priority question is for you, your co-authors, your institution, and, if it comes to it, a journal's integrity office to weigh.
A workflow you can run before your next submission
- Before you post or submit anything, fingerprint the current manuscript, the dataset, and the analysis code. Use hash-only mode for anything sensitive.
- Add your ORCID iD, your co-authors, and — if the work already has one — its DOI so the record points at your scholarly identity.
- Declare AI use honestly, at the tier that fits.
- Then post your preprint or submit to the journal. Your public priority marker now sits on top of a private, independently timestamped record that predates it.
- Re-fingerprint on each major revision. The version chain becomes the story of how the work developed — dated, in order, and yours.
You cannot stop someone else from working on the same question. What you can do is make sure that, if it ever comes down to who had it first, the timeline is not a matter of memory or seniority — it is a matter of record.
Establish Priority Before You Post
Fingerprint your manuscript, dataset, and code — with your ORCID iD, co-authors, and DOI on the certificate. Your first proof receipt is free, and your file never leaves your device.
See ScriptShield for AcademicsProtect Your Creative Work
Generate cryptographically sealed authorship certificates and track who sees your scripts, manuscripts, and creative works.
Get StartedScriptShield provides evidence documentation tools for creators. It is not a law firm and does not provide legal advice.