Download
Version 1.0.0, for exports from schema 2.0 (factory v0.32.0 and later). Requires JDK 25 or newer.
- softwarefabrik-verifier-1.0.0.jar — the program
SHA-2568b2b3b2f00ca1cac60d9aac237508a93a71c7aeb2137a91068f7df528fa7a873 - softwarefabrik-verifier-1.0.0-sources.jar — the complete source code to read
SHA-2569fc128f494214111364e9f026b8248c34bc3e72f63705c46e9e109e29e5c5737 - softwarefabrik-verifier-1.0.0.sha256 — checksums (
sha256sum -c)
The tool deliberately does not come from the factory being audited: you don't obtain an audit tool from the audited party. The build is reproducible — two builds from the same source yield a byte-identical JAR. To rebuild: unpack the source, run mvn package with JDK 25 on a Linux file system (on NTFS drives under WSL only the file permissions of the JAR entries differ, not the content).
What you need
- The export — in the factory under Audit export as JSON, per project or run.
- The fingerprint of the signing key — in the factory under Attestation → trust anchor. Have it confirmed via a second channel (letter, ticket, signed e-mail): whoever forges entries can also replace the key in the export.
- The verifier from this page.
java -jar softwarefabrik-verifier-1.0.0.jar audit-export.json --schluessel <fingerprint>
| Exit | Meaning |
|---|---|
| 0 | Proven: chain, signatures and run evidence backed by the trusted keys |
| 1 | Violation: changed, incomplete, signed by an untrusted key or self-contradictory |
| 2 | No violation, but not everything provable — e.g. without --schluessel |
| 3 | Usage error |
Without --schluessel the check never ends with 0. With --bekannt <seq>:<hash> you pass a previously seen chain state, which must be contained unchanged. (The tool's output is in German.)
What is checked
- Keys: fingerprint of every public key against your trusted values.
- Entries: recompute the hash from the documented canonical form, verify the Ed25519 signature.
- Placeholders: entries of other runs and tenants appear only as hash plus signature — completeness is checkable without disclosing foreign content.
- Chaining: gap-free sequence, every entry points to its predecessor. Omission, insertion and reordering are detected.
- Head: the chain ends exactly at the signed head — otherwise entries are missing at the end.
- Policy: the version applied in the run, content and signature.
- Run evidence: which events belong to a run is attested by a signed manifest; each must be a verified entry of that run.
Fields in which the factory judges itself (“intact”, “chain ok”) do not count as evidence.
Limits
- Integrity is proven from the first exported entry up to the time of export.
- Someone with database access before the export could delete the newest entries and reset the head.
--bekanntwith a previously recorded state protects against this. - The completeness of the assignment of events to a run is attested by the factory's signature at export time.
- Agent tool calls are not yet recorded in the chain.
Background and decisions: ADR-0023 “Offline verifier for the audit export”.