Technical evidence

The one technical door.

Every technical claim on this site resolves to bytes behind this page.

Verify it yourself

The offline verifier re-checks the signature, the signed inventory, the re-derived findings, the trust store and the reliance deadline of the frozen fixture.

The exact runnable example
# prerequisites: Node.js 20 or newer; a checkout of this public repository.
# no network, no keys, no database.
node scripts/observation-extract-runner-v4.mjs --case-dir public/verify/fixture/engagement-g3
# INTEGRITY / DERIVATION / TRUST / RELIANCE: PASS — exit 0

Every record page also verifies in your browser; nothing is sent.

Issuer keys

The public halves of the signing keys are published at the well-known address. /.well-known/woc-issuer-keys.json

Canonicalization

Everything signed is hashed over one canonical form — keys sorted, no whitespace, a prototype-free accumulator — then signed over the digest. The frozen recipe ships with the current artifact set; the governing law is published: /raw/laws/CANONICALIZATION-LAW-1

Published laws

Every law is published with its hash. Current versions resolve; an archived version keeps its identity — its path answers 410 with the frozen sha.

current ATTRIBUTION-LAW-1 v3current CANONICALIZATION-LAW-1 v3current CANONICALIZATION-V2-ERRATUM-1 v1current DOMAIN-GLOSSARY-1 v3current LAW-LOCATION-ERRATUM-1 v3current NAME-COMPARISON-1 v3current PROCEDURE-FAULT-1 v3current RETENTION-1 v2
archived ATTRIBUTION-LAW-1 v1 · sha256 e8ddf56a8f4dbe66fb4ac4ed9929f01fb528aa3a5f4eac15ac90390f9024107b · 410archived CANONICALIZATION-LAW-1 v1 · sha256 f8cf2bfbaf25423a243b12ed86c3cc7fe6fcc3ffa9caf77dbc5da63fe65f5970 · 410archived CANONICALIZATION-LAW-1 v2 · sha256 018f1cd64e1e77f6703cc13a9e564bea6b93342ae2f9ce0d07b602fca3c02901 · 410archived DOMAIN-GLOSSARY-1 v1 · sha256 b92a6a0f012d302eb658fde7a6fc9a3c2a24734990ecfc65162fb2115bcf3f4a · 410archived DOMAIN-GLOSSARY-1 v2 · sha256 bccad8e9fb5aa50cf66fb8e0520a0f1a69cb79a21060d4feeeb26bbadfa3cecf · 410archived LAW-LOCATION-ERRATUM-1 v1 · sha256 0a383520e4ca060a3ed0f1d6943efe5d92aabece281fe62cbba4f9ab6a967e33 · 410archived NAME-COMPARISON-1 v1 · sha256 7f491461856b22b2877c4540aad702bc90a4bb841c72915519fbfb41de631f36 · 410archived NAME-COMPARISON-1 v2 · sha256 98b99c19ebbd47ff3ec8ee84f295f03c718fae58ff987248ed0a843b986cc988 · 410archived PROCEDURE-FAULT-1 v1 · sha256 3e2efe4fd585d73b7dd0a6540e737a29abdceea48d52a72b5ae5789e6ad0118a · 410archived PROCEDURE-FAULT-1 v2 · sha256 27a2e93c285652d77e1764a8c1d01e1c2575fe49554a0699786fa4ced6b637d4 · 410archived RETENTION-1 v1 · sha256 9bb27d2fca4e31704f64ee8f9356ae3fc56a9febeefd5fa496375aad66ffefff · 410archived RETENTION-1 v1.1 · sha256 169695674edf0fedddc19e269a84dd91e1f307dd5820eaca4c61b159223685b7 · 410

Packages

The frozen verification artifact sets — the current set and the frozen history — live at the packages hub.

Raw views

Immutable bytes, no styling:

/records/mo-dental-013494/raw/issuer/raw/records/:id/json/raw/epochs/:id

Reading the records

The read interface is the published addresses on this page plus /records/mo-dental-013494 which renders a record’s finding brief. No keys are issued; no other interface exists.

Coverage and self-audit

The frozen sample-audit delivery and the self-audit ledgers are published with their receipts:

/verify/sample-audit/verify/self-audit/2026-09-07T043637637Z/ledger