Proof, stage three
When they ask, hand them a file.
The answer is a sealed, time-anchored record your own auditor re-checks on their own laptop, offline, with us switched off. It survives even if we disappear. Change one byte and the check fails.
A real sealed self-scan record and the real verifier, exactly as an auditor would receive them. Externally observed, point-in-time, not a legal opinion. The record's format field reads assessqu-evidence-pack/1. It was sealed by this engine on 17 June 2026 and nothing inside it has been touched since, which is the point: the seal and the verifier do not change when the things around them do.
Verify it yourself
Download the record and the verifier
Two files: the sealed record and a standalone verify.py. No account.
Run it offline
python verify.py pack.json, network off. It recomputes the SHA-256 chain and checks the RFC 3161 timestamp against the pinned FreeTSA root. What it does not do is bind the timestamp to a named legal identity.
Change one byte
Edit a single value and run it again. The check fails. The file defends itself, with us switched off.
The system of record, the spine
Where the record comes from, and lives.
The record is a screen you log into, not a document we email you. Discovery, the crypto inventory, the swap lab, the framework mapping and the board view all read the same estate, and every finding in them lands in the sealed record below.
Product screens are not published here. The sealed record on this page is the real artifact, and it verifies on your own laptop with none of our systems in the room.