attest_01KSG21AQ1C53RZ3SP57VDTMFQ
Envelope hash
1f620e894108e19e21f826e6c218204a9e7290c3a45a86b728a49f2cd7b9dbca1f620e89…b9dbca · SHA-256 over the canonical envelope bytes.
Pipeline
Six checks, end to end
- 01Learn more →
Envelope hash
VerifiedThe deterministic SHA-256 of the canonicalised envelope. The leaf in the Merkle tree is derived from this exact byte sequence.
1f620e89…b9dbca
- 02Learn more →
Issuer signature
VerifiedEnvelope is signed by an AWS KMS asymmetric key. The public key is pinned in the issuers table; signature algorithm is ECDSA over SECP256R1 / SHA-256.
Issuer payment-evol…
- 03Learn more →
Dual RFC 3161 timestamp
VerifiedTwo independent timestamping authorities — Sectigo and DigiCert — sign the envelope hash. A divergence between either signature and the chain log is a tamper signal.
Sectigo ✓ · DigiCert ✓
- 04Learn more →
Merkle inclusion proof
PendingThe audit path from leaf to tree root, validated against the hourly STH. Proves the attestation is included in the log without revealing other entries.
Inclusion proof generated on bundle download
- 05Learn more →
Master STH signature
PendingThe signed tree head is signed by the chain-master KMS key (ECDSA P-256 / SHA-256). Anyone with the master public key can verify the log root for this segment.
Will be signed at the next hourly checkpoint
- 06Learn more →
On-chain anchor
Off-chainEach STH is anchored on Base. Once anchored, the tree root is verifiable from any public Ethereum RPC. Sepolia for staging, mainnet for production.
Off-chain only — anchor lands at the next hourly cycle
Labels
Salted commitments
Labels are SHA-256 commitments over a salt + value. The registry never publishes salt material; values appear here only when the issuer has explicitly opted to reveal.
This attestation carries no public label commitments.
On-chain anchor
Off-chain only
This attestation has not yet been anchored on-chain. Anchors are written hourly when the segment's tree head is checkpointed. The off-chain log root is fully verifiable today via the master STH signature.