Two words get used as if they mean the same thing, and the gap between them is where a lot of trust products quietly break their promise.
Tamper-proof says: this record cannot be altered. Tamper-evident says: this record can be altered, but not without leaving a mark anyone can find. The first is a claim about what's possible. The second is a claim about what's detectable. Only one of them is true of the systems actually shipping, and it's the smaller one.
Chain your records together — each entry sealing a fingerprint of the entry before it — and you get a genuinely strong property: change any past entry and every fingerprint after it stops matching. The break is loud and locatable. Anyone holding a later fingerprint can prove an earlier record was altered. That is real, and it's most of what you want.
But notice what it doesn't do. If the same party holds the entire chain and no one else has a copy of any fingerprint, that party can recompute the whole thing after an edit and hand you a clean, internally consistent chain. The math still checks out — because they redid all of it. The chain is tamper-evident to an outsider who kept a fingerprint; it is not tamper-proof against the operator who owns every copy.
Integrity isn't a property of your log. It's a property of who else is holding a copy of its fingerprint.
Which is why the honest architecture has one more move: publish the chain's latest fingerprint somewhere the operator doesn't control — a third-party timestamp, an external witness, a public anchor. Now a later rewrite can't stay hidden, because the outside world is holding a fingerprint from before it happened. You haven't made tampering impossible. You've made it impossible to hide. For evidence, that's the property that counts.
It's tempting, especially in marketing, to round "tamper-evident" up to "tamper-proof," or to reach for "immutable." Resist it — and not only because it's inaccurate. For anyone whose product is trust, an overstated integrity claim is the one mistake you can't survive. The first competent skeptic who recomputes your chain and shows it can be rebuilt hasn't just found a bug; they've disproved your entire premise in a sentence. You cannot be the party that vouches for records and also the party caught overclaiming about your own.
So we say tamper-evident, and we mean it precisely: alter a sealed decision and the chain breaks visibly; anchor the chain's head outside our control and that break can't be papered over. That's a claim we can hand to a hostile auditor and watch survive. "Tamper-proof" is a claim we'd have to hope no one tested.
The trustworthy move and the accurate move turn out to be the same move: claim exactly what the mechanism delivers, and no more. In a market that has been sold a lot of "immutable," the calm, precise version is not a weakness. It's the whole point.