Verify a FreshContext Evidence Pack.
FreshContext Evidence Packs use Ed25519 signatures. The signature proves integrity relative to the signing key. The public fingerprint on this page is the independent trust anchor that lets you check that the key in a pack is the FreshContext key we published.
Published: 29 September 2026.
Current Evidence Pack signing fingerprint
Algorithm
Ed25519
Fingerprint
bcf5 ec32 3a79 1129 b0bf c262 9cb3 979a
How to verify a pack
Put every file from the Evidence Pack in one folder and run the verifier included in the pack with Node.js 18 or later:
node verify-evidence.mjs . --expect "bcf5 ec32 3a79 1129 b0bf c262 9cb3 979a"
The verifier needs no network connection. A valid result should show that the signed manifest matches the key and that every file covered by the manifest is unchanged.
What VERIFIED means
Signature integrity
The Evidence Pack manifest verifies with the Ed25519 key whose fingerprint appears above, and the signed files match the hashes and sizes recorded in that manifest.
Evidence trace
When the observation log is included, the verifier also checks the exact source URL, recorded fetch time and page fingerprint used by the report, and checks quoted evidence against the normalized visible page text FreshContext recorded.
Identity
The key inside a pack does not authenticate itself. Comparing its fingerprint with this independently published page is what binds that key to FreshContext.
Verification outcomes
| Result | Meaning |
|---|---|
| VERIFIED | Signed-file integrity passed and the included evidence trace passed. |
| VERIFIED-INTEGRITY ONLY | The signed files are intact, but the pack did not include enough observation evidence for full quote tracing. |
| FAILED | The signature, expected key, file integrity or evidence trace failed. Do not rely on the pack without investigation. |
What an Evidence Pack does not prove
- It is not an independent timestamp authority.
- It is not an independent archive of the public web.
- It does not prove what a source said before or after FreshContext's recorded read.
- It does not establish the truth of unsupported reasoning, opinions, or claim types outside the audit's scope.
- A pack received together with a substituted key and substituted verifier is not self-authenticating; the published fingerprint above is the independent check.
Report a security issue
Email security@freshcontext.dev. Please do not include passwords, API keys, private customer data or exploit payloads in the first message. We can arrange an appropriate secure channel if needed.