Technical evidence
The one technical door.
Every technical claim on this site resolves to bytes behind this page.
Verify it yourself
The offline verifier re-checks the signature, the signed inventory, the re-derived findings, the trust store and the reliance deadline of the frozen fixture.
The exact runnable example
# prerequisites: Node.js 20 or newer; a checkout of this public repository. # no network, no keys, no database. node scripts/observation-extract-runner-v4.mjs --case-dir public/verify/fixture/engagement-g3 # INTEGRITY / DERIVATION / TRUST / RELIANCE: PASS — exit 0
Every record page also verifies in your browser; nothing is sent.
Issuer keys
The public halves of the signing keys are published at the well-known address. /.well-known/woc-issuer-keys.json
Canonicalization
Everything signed is hashed over one canonical form — keys sorted, no whitespace, a prototype-free accumulator — then signed over the digest. The frozen recipe ships with the current artifact set; the governing law is published: /raw/laws/CANONICALIZATION-LAW-1
Published laws
Every law is published with its hash. Current versions resolve; an archived version keeps its identity — its path answers 410 with the frozen sha.
Packages
The frozen verification artifact sets — the current set and the frozen history — live at the packages hub.
Raw views
Immutable bytes, no styling:
Reading the records
The read interface is the published addresses on this page plus /records/mo-dental-013494 which renders a record’s finding brief. No keys are issued; no other interface exists.
Coverage and self-audit
The frozen sample-audit delivery and the self-audit ledgers are published with their receipts: