← Back to blog
Music Industry

Sending a Pre-Release Track: How to Prove Who Received a File and When

By James A Snell·15 July 2026

A pre-release track must reach curators, press, and label contacts before the public — and if a leak occurs, an artist without a verified distribution record has no independent evidence of who held the file or when.

Every professional release requires the track to circulate before the public date. Playlist curators need time to deliberate. Press need time to write. Sync agents, collaborators, and label contacts all need access before publication. Each of those distributions is professionally necessary. Each one also creates a potential leak vector. The question is not whether to share the track before release. It is whether the sharing is done in a way that produces evidence if something goes wrong.

The Commercial Concentration in the Release Window

The pre-release window is the period between a track being finished and its coordinated public release. It is the highest-risk phase of any release cycle because the recording has its maximum commercial value and its minimum built-in protection. Everything — the playlist pitching, the press campaign, the label relationship, the streaming momentum — depends on controlled timing.

The financial weight of that timing is significant. Spotify alone paid out a record $10 billion to the music industry in 2024, the highest annual contribution from any single music retailer in history. That revenue flows through releases that achieve streaming velocity in the first days of publication. A pre-release leak collapses that window before the coordinated release can take place, and the lost momentum cannot be recovered.

The mechanism is measurable. According to Chartlex campaign data across more than 2,400 artist campaigns, tracks with 200 or more pre-saves see roughly 40 to 60 per cent higher first-week algorithmic playlist inclusion compared to tracks released cold, because Spotify's recommendation engine uses early engagement signals to determine how widely to surface a recording. The coordinated promotional push — playlist pitching, press coverage, social amplification — is designed to generate exactly those early signals. Disrupt the launch and the signals never arrive.

The commercial concentration is stark. Under Spotify's royalty threshold policy introduced in late 2023, tracks must reach 1,000 streams annually before generating any royalties; according to analysis by Disc Makers, 87 per cent of all tracks on the platform fall below that threshold, leaving royalty generation concentrated in the minority of releases that achieve genuine traction. For an artist whose track crosses into that minority, the pre-release window is the single most financially consequential period of the release cycle.

A leak that disrupts a coordinated release at this point is a permanent commercial loss. Streaming algorithms weight first-week velocity heavily in how they surface a track to new listeners, and a version that circulates without the coordinated promotional push arrives without the playlist pitching, press coverage, and social amplification designed to feed those early signals. The commercial value of a first release is spent once.

Why Standard Distribution Tools Leave No Evidentiary Record

Messaging apps, cloud storage links, and direct email attachments were built to move files from sender to recipient. They were not built to produce evidence. When a file is sent through any of these channels, every recipient receives a copy identical to every other recipient's copy. There is no per-recipient differentiation, no independent access log, and no timestamp that cannot be altered on the system the sender controls. If the file appears on a leak forum two weeks later, there is no mechanism in the file or the sending tool to identify the source.

Even when a sender retains metadata from their own system — sent timestamps, read receipts, download notifications — that record sits on infrastructure the sender controls. It can be questioned on exactly those grounds. Courts and opposing legal teams do not take a claimant's own logs at face value for the same reason they do not take a defendant's self-serving records at face value: the party with an interest in the outcome controls the record. An independent distribution record removes that weakness. It is made at the time of distribution, held beyond either party's reach, and cannot be altered after the fact.

Why Agreements Create Obligation Without Evidence

A confidentiality agreement or non-disclosure agreement establishes that a recipient agreed to keep a track confidential. It does not establish what file they received, when they received a specific version, or what that version contained. In most professional situations, the NDA is signed well before the specific file is shared, covering a general category of material rather than a particular file in its exact form at a particular moment.

The distinction is established in UK breach of confidence law. In Coco v AN Clark (Engineers) Ltd [1968], Megarry J set out the three elements a claimant must establish: that the information had the necessary quality of confidence; that it was imparted in circumstances importing an obligation of confidence; and that there was unauthorised use. The first two elements define the duty. The third defines the breach. What the law does not provide is any mechanism for proving, in evidential terms, what specific information was imparted at what moment — that burden remains with the claimant, dischargeable only by records, never by the agreement alone.

When a breach occurs, the agreement gives the artist the right to take action. It does not give them the evidence to identify which recipient breached, to prove what file that recipient held at what moment, or to demonstrate that the leaked version corresponds to the version distributed to the identified party. These are evidentiary questions that no agreement can answer. A signed agreement that cannot be tied to a verifiable distribution record is a legal framework resting on a factual foundation it cannot itself supply.

Why Watermarking Alone Is Not Enough

Audio watermarking — embedding a unique signature into each recipient's copy — is an established practice. Major record labels have used it for years to identify the origin of leaked promotional copies. It solves one problem: if the watermark survives the format conversion and re-encoding that typically accompanies a leak, it identifies which copy leaked.

What a watermark alone cannot do is prove when that copy was distributed, to whom it was sent, what version the recipient held, or what terms applied at the moment of receipt. Without an independently anchored record of the distribution event itself, a watermark that identifies a copy is evidence of origin but not evidence of distribution. The recipient can acknowledge receiving a file while contesting the timing, the version, or the terms. Without an independent record that neither party can alter, there is no objective answer to any of those questions.

The missing component is an access log that is cryptographically anchored to an independent timestamp at the moment each distribution and access event occurs — not held by the artist, not held by the recipient, but recorded by a third party in a form that neither can alter after the fact. That converts watermark-based identification into a legally defensible evidentiary chain.

What a Complete Evidential Chain Requires

A distribution record that can withstand challenge in a legal or commercial dispute requires three elements working together. Without all three, the record has a structural gap that an opposing party can exploit.

First, prior proof of the original work. The original master file must be independently hashed and timestamped before any distribution takes place, establishing what the work contained and when it existed in that form. Without this, there is no verifiable baseline against which a disputed copy can be compared.

Second, per-recipient differentiation. Each recipient must receive a copy that is cryptographically and audibly distinct from every other recipient's copy. A unique audio watermark embedded into the file achieves this, provided it is designed to survive format conversion. This answers the identification question: which recipient's copy was the one that leaked.

Third, an independently anchored access log. Every access event — receipt, download, playback — must be recorded against the specific recipient and the specific copy in a log that is timestamped by an accredited third party and anchored to a public blockchain. Neither the artist nor the recipient can alter this record after the fact. This answers the distribution question: when did that recipient receive it, what did they access, and what version did they hold at the time.

Cryptographic prior proof at the qualified standard works in four layers:

  • SHA-256 hash generated — a unique cryptographic fingerprint of the file in its exact form. Change a single byte and the fingerprint changes entirely; an altered file fails verification. The file itself never leaves the creator's control.
  • RFC 3161 timestamp applied — the fingerprint is timestamped by an accredited Trust Service Provider, creating a cryptographically signed record of the exact moment.
  • eIDAS Article 41 qualification — the timestamp is qualified by an accredited Qualified Trust Service Provider (QTSP). The resulting certificate carries a legal presumption of accuracy in EU member states, is treated as strong electronic evidence under UK law, and supports authentication under Federal Rule of Evidence 901 in the United States.
  • Bitcoin blockchain anchoring — the fingerprint is anchored via OpenTimestamps, creating a permanent, decentralised record that remains verifiable independently of any single provider's continued operation.

Applied to a distribution workflow, the same approach secures the original master at deposit, then anchors a daily log of access events on a per-recipient basis. The result is a chain from creation through distribution that is independently timestamped, blockchain-anchored, and can withstand scrutiny in UK, EU, and US proceedings.

What Changes When Distribution Is Verified

Most of the value of an independently verified distribution record arrives before a leak ever occurs. Recipients who receive a uniquely watermarked copy, logged against their identity and anchored to an independent timestamp, are operating in a different environment from recipients who received an identical file with no audit trail. The record changes behaviour without requiring any conversation about distrust.

When a leak does occur, the position changes in kind. The conversation with the identified recipient — whether commercial, legal, or relational — proceeds from a position of documented fact rather than suspicion. Every other recipient can be confirmed as not having been the source, preserving working relationships that would otherwise be damaged by a blanket loss of trust across everyone who received a copy. The label, the distributor, and any insurers have an evidentiary record rather than an incident report.

The asymmetry is significant. The downside of a disrupted release — lost algorithmic placement, damaged relationships, unattributable leak, permanent commercial loss — is large and irreversible. The cost of establishing an independent distribution record is small and the process is routine once it is in place. Any professional releasing music who shares pre-release copies without an independently verifiable record is accepting a large, irreversible downside risk for which there is no justification.

There is a further consequence that is not often considered: the absence of a verified distribution record affects every recipient, not just the one who leaked. When a leak occurs and the source cannot be identified, every person who received the file becomes a suspect by default. Professional relationships that might otherwise survive are damaged simply by the uncertainty. A record that can clear the innocent recipients is worth as much as one that identifies the guilty party.

Related Reading

Global Music Report 2025 — IFPI

Spotify's Loud & Clear: Track Royalty Eligibility

Proving Song Authorship Before You Walk Into a Co-Write

This post provides general information about the role of cryptographic evidence. It is not legal advice. For advice on a specific matter, consult a qualified lawyer in your jurisdiction.

James Snell is the founder of Provlyn, a platform providing cryptographic prior proof of IP ownership. provlyn.com

Prove Who Received a Pre-Release File and When | Provlyn