Skip to content

Documentation

Verifying a proof

How somebody who does not trust us checks one.

What is in it

A manifest naming the finding, the change, the test that failed before and passed after, and the re-scan that confirmed it — with the framework version pinned, the time, and a signature over all of it.

Each proof also carries the hash of the previous one, so a record cannot be removed from the middle of the chain without the ones after it failing.

Checking it without us

Signing keys are published at a stable URL, including retired ones, because verifying a proof signed in 2026 needs the 2026 key whenever somebody asks.

The verification is a signature check over a canonical serialisation. It needs no account, no API key and no request to us, and it keeps working if this company does not.