What this repository is
This repository contains the reviewed public template and offline verification tools for deterministic evidence bundles. It does not contain a deployment's evidence records.
Evidence model
- Each deployment maintains its own controller identity and local signed, hash-chained ledger.
- A portable bundle carries the declared trust state, signed chain, deterministic summaries, and an offline verifier.
- Git may preserve an additional reviewed copy, but it is not the authoritative evidence store.
Arrows show what each identity signs or authorises. No key is derived from another.
Use a local-only tool
These pages use no analytics, remote fonts, CDN code or network API. Private material remains in the current browser session unless you explicitly download it.
Repository controls
Changes require pull requests and Code Owner review. Evidence ingestion may add only one new bundle directory containing evidence.bundle and bundle.sha256. Automated checks verify the complete chain and reject mixed or unexpected ingestion paths.
Interpretation boundary
A valid signature proves that the identified key signed the exact statement. It does not prove physical deletion, absence of copies outside controlled systems, or legal compliance.