Evidence Report

Scope: public demo · Tenant log: evd://tenant/t_demo · Period: 2026-07-18T01:08:23Z → 2026-07-18T01:08:23Z · Generated: 2026-09-02T13:49:49Z

VERDICT: VERIFIED

Independently confirmed public commitment (E2): every subject receipt summarized here is covered by a checkpoint whose anchor was re-read from the public chain during this report run and whose RFC 3161 token terminates at a TSA root supplied by the relying party. The earliest covering commitment was at 2026-07-18T01:08:26Z. This establishes public commitment no later than that block time; it does not prove the action's self-reported event time or export completeness. This HTML records the result of that run; it is not a signed live-query transcript. Re-run the live command below against a trusted RPC of your choice to reproduce the public-chain determination. Credential-bearing RPC URLs are not embedded; only exact allowlisted public endpoints may be shown.

Relying-party TSA root fingerprint(s), SHA-256 over DER: 2aca8fea5d3ce48b01cc77076293c280e6c23ffe44034757ee7833ca9f45d633. These identify the external trust input used by this level; the report does not make that trust decision for its reader.

Full bundle digest (SHA-256/JCS): bcd2193d4891fe184e91402a07d54c790c7db1118a6330470b5cea4e33bfcbf9 — cite this evidence bundle by that digest.

This report was generated from the verified evidence bundle plus the live chain checks listed below; the generator used no other data source.

Evidence levels, briefly

Each evidence level adds a requirement; this is not a score. This report's displayed subject rows: E2.

E0 · Signed receipt
The receipt's DSSE signature verifies. That authenticates the signed bytes, not the underlying action.

E1 · Presented history
E0 plus Merkle inclusion, key-log replay and signed-checkpoint consistency for the history presented—not latest history, capture/export completeness or independent time.

E2 · Public commitment
E1 plus one exact covering Base/Base Sepolia checkpoint confirmed live, with an RFC 3161 token for that same checkpoint digest ending at a TSA root supplied by the relying party.

E3 · Dual attestation
E2 plus an issuer signature and a co-signature from an active non-issuer registered recorder on the same receipt, verified under a recorder key supplied by the relying party.

What happened

time (UTC)agentactioncontextlevel
session no session
2026-07-18T01:08:23Z_systemSigning key created evd.key.createdkey 6sihoKmS2ClmVd-sE2 ✓
session s_a70a88a9d68f5d7e inferred
no mandate recorded
2026-07-18T01:08:23Zrefund_agentAI model call llm.chatgpt-x, status 200E2 ✓
2026-07-18T01:08:23Zrefund_agentAI model call llm.chatgpt-x, status 200E2 ✓
session no session
2026-07-18T01:08:23Z_systemSigning key rotated evd.key.rotatedkey z8BJ5P1udWHH4DnAE2 ✓
session s_a70a88a9d68f5d7e inferred
2026-07-18T01:08:23Zrefund_agentAI model call llm.chatgpt-x, status 200E2 ✓

What this level means: Every E2 ✓ line has the E1 receipt and presented-history checks plus live checkpoint coverage and a timestamp rooted outside the bundle.

Verification appendix

How to verify this yourself

pip install swarrm==1.2.0        # or: use verify/ from the repo
swarrm verify bundle.json           # → VERIFIED
swarrm verify bundle.json --trust sample_sigstore_tsa_trust.json --live --rpc https://base-sepolia.drpc.org   # external-level check

The bundled sample_sigstore_tsa_trust.json makes this run reproducible, but it is not independent merely because it is a separate file. Before relying on it, retrieve /api/v1/timestamp/certchain from Sigstore yourself and confirm the root's SHA-256/DER fingerprint is 2aca8fea5d3ce48b01cc77076293c280e6c23ffe44034757ee7833ca9f45d633.

No install? Drop the bundle into swarrm.ai/verify — it verifies in your browser, no account, nothing uploaded.

Annex

Download the embedded evidence bundle — the exact bytes this report verified, embedded in this file so report and proof travel together (P2: nothing else must accompany this document). Its SHA-256 is the digest cited above; any verifier run on the download must reproduce this report's verdict.

When Swarrm's hosted export flow creates a report, it appends the report's SHA-256 afterward as an evd.report.created receipt. That later receipt is not inside the input bundle and must be supplied and verified separately; standalone report generation does not create it.