verify it yourself
Don’t trust us. Recompute it.
This bundle lets anyone independently verify the Quox trust scoreboard published at quox.ai/security, with no account, no Quox repo, and no network access. It needs only Node 18+; the verifier uses Node builtins only, zero dependencies.
three layers
Three verification layers.
- 01
Signed projection recompute
Every WARD receipt’s chain_hash is recomputed from the hash recipe below, and the whole log’s Ed25519 signature is verified against the committed public key. Exit 0 only if both hold; any mismatch or hand edit since publication fails closed.
- 02
Governed engagement records
Each audit cycle traces back to a named engagement id, run as a governed QuoxSecurity engagement, not an ad-hoc script. Findings are filed and verified inside that engagement, not written by hand after the fact.
- 03
Red-proven conformance pins
Fixes are remediated test-first and verified on the running system before being marked resolved. The ones still open are published open, on purpose: an audit log that only ever shows green is indistinguishable from no audit at all.
reimplement it, don’t trust our script
The hash recipe and the public key.
Everything you need is public. Copy the data, hand-roll your own verifier if you want, and check our script agrees with yours.
- Hash recipe
sha256(prev_chain_hash|chain_id|seq|ward_entry_id|witnessed_at|source_kind|source_id|payload_hash), hex- Signature canonicalisation
- Recursively sort object keys, then sign/verify the string secaudit1|<utf8-byte-length>|<json> with Ed25519.
- Public key (base64, raw 32-byte Ed25519, non-secret)
fIQ/oPZSVq30nXqR5yU0Ny47QhHVNrD/PDqxkoIyEck=
download and run
Download and run it offline.
node quoxtrust-verify.mjs ./securityAudits.jsonTry to break it: copy securityAudits.json, change anything (a finding title, a payload_hash, a verdict), and re-run the verifier against the copy. Editing a chain field breaks the recompute; editing anything at all breaks the signature. A self-consistent forgery (tamper a payload and recompute its chain_hash) still fails the signature.
what it proves, and what it does not
The boundary, stated up front.
- Recompute (every receipt’s chain_hash) proves the chain is internally consistent.
- Signature (Ed25519 over the whole canonicalised log) proves authenticity: that the real publisher, not a hand edit, produced this file. A forger can fabricate a finding and compute a self-consistent chain_hash for it, so recompute alone is not enough. Only the holder of the private key can produce a signature the committed public key accepts, and that signature covers every byte of the log.
- It does not prove benign runtime behaviour or the truth of any external effect, only that the published evidence is authentic and unaltered.