Package-integrity verification boundary
PUBLIC-SURFACE LIMITED GO / CUSTOMER-PROCESSING NO-GO.
An issued Buyer Review Pack includes a canonical manifest, checksums, and an Ed25519 signed receipt binding the manifest SHA-256. Package-integrity and issuer-receipt verification are distinct from Registry entry or checkpoint-continuity verification. Receipt validation requires a separately trusted applicable issuer-key snapshot; current Registry checkpoint continuity is unavailable as an assurance claim.
Verification does not certify the underlying records, guarantee that a buyer accepts the package, or replace the reviewer's own diligence.
Synthetic or separately evidenced historical package features
This table describes bounded verifier behavior; “source-supported” is not a production-issuance claim.
| Trust feature | Status | What it means |
|---|---|---|
| Package-file SHA-256 hashes | Source-supported | The verifier design recalculates every manifest-listed file hash. |
| Ed25519 signed receipt | Source-supported | A valid receipt binds the package identifier and canonical manifest hash. |
| Issuer-key lookup | Trust input required | The receipt key ID must resolve to a separately trusted applicable issuer key; Registry checkpoint continuity is not currently proven. |
| Hosted verification | Synthetic/historical only | The hosted verifier may inspect an explicitly synthetic or separately evidenced historical ZIP. |
| Offline verification | Source-supported | Offline verification requires an independently obtained applicable issuer-key snapshot. |
| Registry transparency-log inclusion | Not active | Buyer Review Pack issuance is not currently included in a public transparency log. |
| External timestamp or witness anchoring | Not active | No independent external timestamp or witness is claimed. |
| Post-issuance package revocation | Not offered | Customers should preserve the issued ZIP and verification material; AttestLayer does not promise package withdrawal or replacement in place. |
Verification steps
Upload the issued package ZIP to the verifier.
The verifier recalculates package-file hashes against the canonical manifest, checks the receipt's manifest SHA-256 commitment and package identifier, and validates the Ed25519 receipt signature only when the receipt key ID resolves to the applicable issuer key published by the Registry.
The verifier displays one of these results:
- Package files match the manifest and the receipt is valid
- Package files or manifest do not match
- Receipt signature or package binding is invalid
- The applicable receipt key ID is not present in the Registry-published issuer key set
The reviewer evaluates the underlying records and the buyer's own acceptance criteria separately.
For an explicitly synthetic or separately evidenced historical package, use the hosted verifier only with a package authorized for that purpose. Receipt trust completes only when the receipt key ID resolves to a separately trusted applicable issuer key; a key embedded by the package cannot establish its own trust. Registry inclusion is separate and is not currently active for Buyer Review Pack issuance. Registry checkpoint continuity is not currently claimed.
