Security and verification

Verify a FreshContext Evidence Pack.

FreshContext Evidence Packs use Ed25519 signatures. The signature proves integrity relative to the signing key. The public fingerprint on this page is the independent trust anchor that lets you check that the key in a pack is the FreshContext key we published.

Published: 29 September 2026.

Current Evidence Pack signing fingerprint

Algorithm

Ed25519

Fingerprint

bcf5 ec32 3a79 1129 b0bf c262 9cb3 979a

How to verify a pack

Put every file from the Evidence Pack in one folder and run the verifier included in the pack with Node.js 18 or later:

Strict fingerprint check
node verify-evidence.mjs . --expect "bcf5 ec32 3a79 1129 b0bf c262 9cb3 979a"

The verifier needs no network connection. A valid result should show that the signed manifest matches the key and that every file covered by the manifest is unchanged.

What VERIFIED means

Signature integrity

The Evidence Pack manifest verifies with the Ed25519 key whose fingerprint appears above, and the signed files match the hashes and sizes recorded in that manifest.

Evidence trace

When the observation log is included, the verifier also checks the exact source URL, recorded fetch time and page fingerprint used by the report, and checks quoted evidence against the normalized visible page text FreshContext recorded.

Identity

The key inside a pack does not authenticate itself. Comparing its fingerprint with this independently published page is what binds that key to FreshContext.

Verification outcomes

ResultMeaning
VERIFIEDSigned-file integrity passed and the included evidence trace passed.
VERIFIED-INTEGRITY ONLYThe signed files are intact, but the pack did not include enough observation evidence for full quote tracing.
FAILEDThe signature, expected key, file integrity or evidence trace failed. Do not rely on the pack without investigation.

What an Evidence Pack does not prove

  • It is not an independent timestamp authority.
  • It is not an independent archive of the public web.
  • It does not prove what a source said before or after FreshContext's recorded read.
  • It does not establish the truth of unsupported reasoning, opinions, or claim types outside the audit's scope.
  • A pack received together with a substituted key and substituted verifier is not self-authenticating; the published fingerprint above is the independent check.

Report a security issue

Email security@freshcontext.dev. Please do not include passwords, API keys, private customer data or exploit payloads in the first message. We can arrange an appropriate secure channel if needed.