Verify an evidence package
Auditors and customers can check that a TrustEvidence evidence package is exactly what was collected: every file unchanged since export, each record's content and metadata unchanged since collection, each record part of a sealed batch, the batches unbroken, and the signatures valid.
The checks run in this browser. The package is not uploaded; the only thing this page fetches is our published signing keys, to compare them with the ones in the package.
Other ways to verify
- Every package contains
verify.html, the same checks as this page, which works offline. - On a terminal: download verify.py and run
python3 verify.py <package.zip>(signatures needpip install cryptography).
What this proves, and what it does not
It proves that every record in the package is exactly as TrustEvidence collected and sealed it, that no file was changed after export, and that the signatures come from the keys we publish. It does not prove that the package contains every record that exists: a package holds the records selected for its period. It also does not prove more about a system than what each record shows, and the time a batch was sealed is stated by TrustEvidence rather than by an independent time-stamping authority.
TrustEvidence