New System Ensures Secure, Tamper-Proof Verification for PDF Reports with Comprehensive Provenance and Coherence Checks

August 31, 2026
New System Ensures Secure, Tamper-Proof Verification for PDF Reports with Comprehensive Provenance and Coherence Checks
  • A tamper-evident verification system signs a PDF report to bind results to the exact code, hardware, and time used, with verifiable integrity open to anyone.

  • Embedded protocol lines capture metrics, phases, and inputs/outputs to enable comprehensive provenance and cross-run coherence checks.

  • Benchmark artifacts attest public or salted private scores, preserving provenance of evaluation results without exposing sensitive model weights or data.

  • The system supports cross-platform verification, sealing, provenance, and disclosure management, with Linux-specific hardware attribution and file activity tracing.

  • Compute-cost attestation compares declared FLOPs to hardware capabilities to flag fabrication or misreporting, using defined thresholds for bound violations.

  • Selective-disclosure proofs enable revealing specific files or prompts/outputs without exposing the entire run through prove-and-verify workflows.

  • Checkout bundles allow reconstructing a signed snapshot’s files while keeping source contents content-addressed and deduplicated inside a sealed bundle.

  • Users can install via prebuilt binaries or build from source, with quick-start commands like init, run, seal, and verify to generate and validate signed reports.

  • The cryptographic protocol uses canonical JSON, SHA-256, RSA-PSS, and embeds seal data within the PDF to ensure verification remains valid against future field changes.

  • Users can choose redacted or full disclosure levels, with signed timelines and content-addressed snapshots organized in a Merkle-based structure.

  • Agent sessions generate hash-chained, per-entry attributed logs that can be verified for tampering at the entry level.

  • HMCA (execution coherence) records per-process telemetry at about 10 Hz to determine whether CPU, memory, I/O, and GPU metrics co-fluctuate as expected, yielding PASS, WARN, FAIL, or N/A.

Summary based on 1 source


Get a daily email with more Startups stories

More Stories