What a valid record says
Verification Record Valid: Manifest [hash] evaluated on [date] under Protocol v9.3 at Evidence Assurance Level EAL-2. Signature Verified. Zero customer data stored.
Three other answers are possible:
- Review required. The record is on automated status hold under the assurance recall protocol — we found a flaw in our own method or scoring, the customer has been notified, and a re-evaluation is in progress.
- No record. The hash is not on file. Either it was transcribed wrongly, the run was self-administered at EAL-1 (customer-reported evidence is never notarised), or the bundle was not produced by EvalQA.
- Not a SHA-256. The input is not 64 hexadecimal characters.
How to find the hash
- Open the bundle’s
manifest.json(it sits besidereport.htmlin the S3 prefix or Snowflake stage the customer chose). - Copy the value of
manifest_sha256. It is also printed in the footer of the Tier-1 board scorecard. - Optionally recompute it:
sha256sum manifest.jsonmust match, or the bundle has been altered since signing.
What this notary will never do
- Return a finding, a query, a table name, a score or a customer name. It does not have them.
- Issue a badge, a seal or a “certified” status. See why there is no badge.
- Answer for an EAL-1 self-run. Unverified evidence is labelled unverified, not laundered through a notary.