Verify Evidence

Verify a published evidence record

One recorded decision from a preproduction rehearsal is published below as sealed record facts.

Decision Evidence Canonical digest Receipt Verification Audit / review

Sealed record — published facts

Record identifier
The identifier of the recorded decision. fxcov-2026-07-26-16ee35adadecc216
Record class
FX covenant decision (EUR/MDL) — real data, preproduction T0b rehearsal.
Original receipt SHA-256
SHA-256 digest of the original receipt content. e2cb99a2ed6ca8cb09bbae3042e6a1c89613e3c9310b15261a0023afc5b5d66f
Original receipt signature class
CONTENT_BOUND_PREPRODUCTION_HSM_SIGNED
Receipt WORM generation
1785102160671103
Later production attestation signature class
Added after the original receipt; it covers the exact receipt digest and WORM generation above. SOFTWARE KMS protection level. CONTENT_BOUND_PRODUCTION_SOFTWARE_KMS_SIGNED
Attestation WORM generation
1785136044712767
Retention
Locked WORM bucket retention (create-only, no overwrite, no delete).

The later production attestation was signed at the SOFTWARE KMS protection level. SOFTWARE KMS protection is not HSM protection.

Record check

Run a live record check

Enter the record identifier to ask the verification backend for the current per-dimension result for that record. Each dimension of the check is reported on its own row, and failure codes are shown verbatim; the page never reduces the dimensions to a single overall result.

Format: fxcov-YYYY-MM-DD- followed by 16 lowercase hex characters.

How the live record check works

The live record check re-derives content digests, Merkle inclusion and signatures against pinned public keys. The checks run server-side on read-only evidence copies fetched at pinned object generations. The check never writes, never signs, and never lists storage.

Reading the result

Four states, kept distinct

A record check is read one dimension at a time. UNKNOWN is not VERIFIED. FAILED is not a warning. NOT CHECKED is not FAILED.

  • VERIFIED

    The dimension was checked and the check passed. Verification is reported per dimension; dimensions are never reduced to a single overall result.

  • FAILED

    The dimension was checked and did not pass. Failure codes are reported verbatim, never softened into a warning.

  • UNKNOWN

    The dimension could not be determined. An unknown is reported as unknown — it is never presented as verified.

  • NOT CHECKED

    The dimension was not run. An absent check is stated as absent, never counted as a pass.

Limitations

This page publishes one recorded decision only. Population completeness is not proven. Governance completeness is not proven. Organizational independence is not claimed. SOFTWARE KMS protection is not HSM protection.

A content digest by itself is a checksum, not a signature. Where this page names a signature class, an authoritative signature over the stated digest exists in the published record facts; nothing here treats a bare checksum as one.