Offline verifier · 1.0.0

Check the evidence without trusting the factory.

This tool checks an audit export of the factory without access to the factory: whether entries were changed, left out or cut off at the end, which policy applied to a run, and whether everything is signed with a trusted key.

JDK only, no dependencies about 1,000 lines of Java reproducible build

Download

Version 1.0.0, for exports from schema 2.0 (factory v0.32.0 and later). Requires JDK 25 or newer.

The tool deliberately does not come from the factory being audited: you don't obtain an audit tool from the audited party. The build is reproducible — two builds from the same source yield a byte-identical JAR. To rebuild: unpack the source, run mvn package with JDK 25 on a Linux file system (on NTFS drives under WSL only the file permissions of the JAR entries differ, not the content).

What you need

  1. The export — in the factory under Audit export as JSON, per project or run.
  2. The fingerprint of the signing key — in the factory under Attestation → trust anchor. Have it confirmed via a second channel (letter, ticket, signed e-mail): whoever forges entries can also replace the key in the export.
  3. The verifier from this page.
java -jar softwarefabrik-verifier-1.0.0.jar audit-export.json --schluessel <fingerprint>
ExitMeaning
0Proven: chain, signatures and run evidence backed by the trusted keys
1Violation: changed, incomplete, signed by an untrusted key or self-contradictory
2No violation, but not everything provable — e.g. without --schluessel
3Usage error

Without --schluessel the check never ends with 0. With --bekannt <seq>:<hash> you pass a previously seen chain state, which must be contained unchanged. (The tool's output is in German.)

What is checked

  1. Keys: fingerprint of every public key against your trusted values.
  2. Entries: recompute the hash from the documented canonical form, verify the Ed25519 signature.
  3. Placeholders: entries of other runs and tenants appear only as hash plus signature — completeness is checkable without disclosing foreign content.
  4. Chaining: gap-free sequence, every entry points to its predecessor. Omission, insertion and reordering are detected.
  5. Head: the chain ends exactly at the signed head — otherwise entries are missing at the end.
  6. Policy: the version applied in the run, content and signature.
  7. Run evidence: which events belong to a run is attested by a signed manifest; each must be a verified entry of that run.

Fields in which the factory judges itself (“intact”, “chain ok”) do not count as evidence.

Limits

  • Integrity is proven from the first exported entry up to the time of export.
  • Someone with database access before the export could delete the newest entries and reset the head. --bekannt with a previously recorded state protects against this.
  • The completeness of the assignment of events to a run is attested by the factory's signature at export time.
  • Agent tool calls are not yet recorded in the chain.

Background and decisions: ADR-0023 “Offline verifier for the audit export”.