Skip to content
PUBLIC-SURFACE LIMITED GO / CUSTOMER-PROCESSING NO-GO. Public information and synthetic examples may remain available; live files, checkout, production package generation, Registry-dependent issuance, and customer activation are paused.

Package-integrity verification boundary

PUBLIC-SURFACE LIMITED GO / CUSTOMER-PROCESSING NO-GO.

New production issuance is paused. The descriptions below apply to an explicitly synthetic sample or a separately evidenced historical package; they do not establish current Registry checkpoint continuity or authorize new customer processing.

An issued Buyer Review Pack includes a canonical manifest, checksums, and an Ed25519 signed receipt binding the manifest SHA-256. Package-integrity and issuer-receipt verification are distinct from Registry entry or checkpoint-continuity verification. Receipt validation requires a separately trusted applicable issuer-key snapshot; current Registry checkpoint continuity is unavailable as an assurance claim.

Verification does not certify the underlying records, guarantee that a buyer accepts the package, or replace the reviewer's own diligence.

Synthetic or separately evidenced historical package features

This table describes bounded verifier behavior; “source-supported” is not a production-issuance claim.

Trust featureStatusWhat it means
Package-file SHA-256 hashesSource-supportedThe verifier design recalculates every manifest-listed file hash.
Ed25519 signed receiptSource-supportedA valid receipt binds the package identifier and canonical manifest hash.
Issuer-key lookupTrust input requiredThe receipt key ID must resolve to a separately trusted applicable issuer key; Registry checkpoint continuity is not currently proven.
Hosted verificationSynthetic/historical onlyThe hosted verifier may inspect an explicitly synthetic or separately evidenced historical ZIP.
Offline verificationSource-supportedOffline verification requires an independently obtained applicable issuer-key snapshot.
Registry transparency-log inclusionNot activeBuyer Review Pack issuance is not currently included in a public transparency log.
External timestamp or witness anchoringNot activeNo independent external timestamp or witness is claimed.
Post-issuance package revocationNot offeredCustomers should preserve the issued ZIP and verification material; AttestLayer does not promise package withdrawal or replacement in place.

Verification steps

  1. Upload the issued package ZIP to the verifier.

  2. The verifier recalculates package-file hashes against the canonical manifest, checks the receipt's manifest SHA-256 commitment and package identifier, and validates the Ed25519 receipt signature only when the receipt key ID resolves to the applicable issuer key published by the Registry.

  3. The verifier displays one of these results:

    • Package files match the manifest and the receipt is valid
    • Package files or manifest do not match
    • Receipt signature or package binding is invalid
    • The applicable receipt key ID is not present in the Registry-published issuer key set
  4. The reviewer evaluates the underlying records and the buyer's own acceptance criteria separately.

For an explicitly synthetic or separately evidenced historical package, use the hosted verifier only with a package authorized for that purpose. Receipt trust completes only when the receipt key ID resolves to a separately trusted applicable issuer key; a key embedded by the package cannot establish its own trust. Registry inclusion is separate and is not currently active for Buyer Review Pack issuance. Registry checkpoint continuity is not currently claimed.