A sample inspection pack you can verify yourself
Two zip files below: a clean sample inspection pack, and a copy of it with one byte changed. Download either one, or both, and check them yourself with the offline verifier — no ActaSeal install, no account, nothing sent anywhere.
Everything in this pack is synthetic. The audited entity ("Kestrel Point Cooperative"), the audit firm ("Marrow & Finch LLP"), and every preparer/reviewer/EQR name in it are invented for this sample. No real company, audit firm, engagement, or person is represented.
The RFC 3161 timestamp embedded in archive_attestation.json
is a replayed fixture: a real, previously captured
freetsa.org response, reused here instead of a live network call so this
sample is generated deterministically and offline. It is cryptographically
real, but it does not commit to this specific pack's workpaper-set hash
— checking it against a CA bundle correctly reports a named mismatch,
not VERIFIED. The pack's chain-of-custody and workpaper-set
integrity checks (the ledger hash chain and the SCITT/transparency chain)
are genuine and independently re-derivable from the files themselves; only
the TSA leg is a stand-in, and the command below deliberately doesn't ask
the verifier to check it. This pack also carries an UNLICENSED
watermark in its manifest, the same as any self-hosted deployment run
without a licence would produce.
Download
- sample-inspection-pack.zip — clean
- sample-inspection-pack-tampered.zip — one byte changed
What's in the pack
manifest.json (engagement id, workpaper count, framework
profile, licence watermark), workpaper_index.json (each
workpaper's content hash plus its preparer/reviewer/EQR identity),
archive_attestation.json (the RFC 3161 timestamp and the
SCITT transparency-log inclusion proof, together covering the Merkle root
of the archived workpaper set), ledger_slice.ndjson (the
engagement's own hash-chained ledger events, from registration through the
post-archive addition below), verify.py (the offline
verifier itself, embedded in the zip), and README.txt (the
same verify instructions as this page, phrased for running from inside
the extracted folder rather than against the zip directly, plus what
VERIFIED does and does not prove).
The sample engagement has 6 workpapers on record, but only 5 hashes in
the attested set. The 6th, wp-06 ("Subsequent events review
update"), was added through the product's permitted
post-archive-addition path after the documentation
completion deadline had already passed and the attestation had already been
issued — it shows up in the ledger and in workpaper_index.json
with a reason and who added it, but correctly has no content hash and is
not part of what the attestation commits to. That's the asymmetry AS 1215's
"nothing deleted, addition permitted" rule describes: visible, dated,
reasoned — and never retroactively folded into an already-issued
attestation.
Verify it
Requires Python 3 and pip install cryptography. No unzip
step — verify.py accepts the zip directly, extracting
it itself, and reads manifest.json to detect on its own
that this is an archive-export pack, not a dispute-action packet:
python verify.py sample-inspection-pack.zip
Expected output, exactly as the real verifier prints it, exit code
0:
VERIFIED (archive export): ledger chain intact, workpaper set matches attestation RFC 3161 timestamp NOT verified -- no --tsa-ca-cert given (get the TSA's CA cert out of band) SCITT transparency receipt NOT verified -- no --sth-public-key given (get the deployment's public key out of band, e.g. its /.well-known/actaseal-keys.json while it is live -- never trust a copy embedded in this pack itself)
Those last two lines are not a failure. VERIFIED already means what it says: the ledger chain is intact and the workpaper set matches what the attestation commits to. RFC 3161 and SCITT are two SEPARATE, optional checks that need a trust root this pack cannot supply itself — a key or CA cert embedded in the pack would prove nothing, since whoever fabricated a pack from scratch could just embed a key matching their own fabricated receipt. The verifier never drops a check silently: if you didn't pass the flag, it tells you by name that the check didn't run, instead of letting you assume everything possible was checked.
Run the SCITT check for real, against this sample's own public key (given here because this is a synthetic sample with no live deployment behind it — for a real pack, get the key out of band from whoever issued it):
python verify.py sample-inspection-pack.zip --sth-public-key 8a9db82ae18fcbf2bdd04ba3d20e84a42294628617c56f9c59a87bd5d13ad3e6
VERIFIED (archive export): ledger chain intact, workpaper set matches attestation RFC 3161 timestamp NOT verified -- no --tsa-ca-cert given (get the TSA's CA cert out of band) SCITT transparency receipt verified against the supplied public key
Now the tampered copy — expected output and exit code
1, so you know what to expect before you run it:
python verify.py sample-inspection-pack-tampered.zip
VERIFICATION FAILED ARCHIVE_EXPORT_WORKPAPER_SET_TAMPERED
The change between the two zips is exactly one byte: a single hex
digit inside the first workpaper's content_hash in
workpaper_index.json, from 2 to 0
at byte offset 91 of that file's decompressed content. Nothing else in
either zip differs except what that one changed byte causes the verifier
to report.
File hashes
| File | SHA-256 |
|---|---|
sample-inspection-pack.zip | b2cb472b0c6b9138a4e29c3d68c51865ecf0b5c83aea3ed0e3364d964979b161 |
sample-inspection-pack-tampered.zip | 256bcd1456d57faf5238d05605ad4e85489738c4261a323fb13fea597f28b53d |