Independent integrity checks

Check the record. Keep the proof.

Every ArcticScore engagement produces a signed bundle whose integrity can be checked offline, without calling our servers.

Can you verify an ArcticScore evidence bundle without trusting ArcticScore?
Yes. Every signed evidence bundle includes verify_bundle.py and VERIFY_BUNDLE.md — a standalone, stdlib-only verifier with plain-English instructions. Anyone holding the bundle can run six verifier integrity checks offline, without contacting ArcticScore. Alteration of the delivered files, record, signature, or timestamp is detectable by the verifier.

The linked record, explained

Evidence events are linked so a later change is detectable. The exported state is signed and timestamped by an external RFC 3161 authority, and the included verifier checks that the delivered files and record still agree.

RFC 3161 timestamp anchoring

An external RFC 3161 authority timestamps the delivered record state. The included token can be checked against the authority’s public certificate, independently of ArcticScore’s system clock.

The standalone verifier — verify without ArcticScore

Every bundle ships with a readable verifier and plain-English instructions. It runs offline without calling ArcticScore, so a buyer or technical reviewer can inspect it and independently check the declared files, linked record, signature, and external timestamp. The result reports pass, fail, or unverified rather than silently accepting an incomplete record.

Authentication-oriented records

Structured for independent review

When the qualified-individual workflow is completed, a bundle can include optional certification artifacts designed to support authentication under FRE 902. The bundle states whether those artifacts are present. Admissibility is determined by the court.

Inside the record, every claim carries its verification status on its face: machine-verified against a fresh evidence pull, attested in writing, contradicted by live evidence, or not yet checked. Nothing is silently upgraded — a fix claim earns its certificate from the evidence or stays marked unverified. And the coverage map states which sources could check which claims, so a reviewer knows what the record covers before relying on it.

The short version

We’re a small company. That’s a fair concern. The bundle reduces ongoing vendor dependence by shipping the verification materials with the record:

1.

The verifier doesn’t call us

2.

The timestamps are third-party

3.

The math is checkable

4.

The verifier ships in the bundle

5.

The bundle is yours forever

The verification boundary

If a bundle fails verification for reasons within our control, we will correct it under the terms of the applicable agreement. The standalone verifier makes alteration to the delivered bundle detectable by checking its declared files, linked record, signature, and external timestamp. Those checks establish integrity and provenance; they do not decide whether every source assertion is true, whether the assessment scope was complete, or whether a court, carrier, or regulator will accept the result.

Evidence you can verify without us.

The shipped verifier checks the delivered record against its hashes, signatures, chain links, and timestamp token without calling ArcticScore.

See pricing