Portability
If we disappear tomorrow, you can still verify receipts locally using SHA‑256 + Ed25519 signatures and the published public key.
What to keep
- The Receipt JSON (ERF object)
- Your original file(s) locally (hash-only default)
- Signed distribution artifacts (public key, signatures, SHA256SUMS)
How to verify offline
- Compute SHA‑256 of your file.
- Compare with payload.content_hash.value.
- Verify signature on the receipt JSON using the published public key.
Reality Audit
Integrity-only packaging. Not legal advice. No admissibility guarantee.