Skip to content
PQC TriageGitHub
Menu

Integrity

Seal replay

Every create, update, decision and retire appends one event. seal_n = SHA-384(UTF-8(prevSeal) || canonicalJson(event_n)), chained from a genesis value derived from the survey id. Replay recomputes the whole chain and names the first link that does not hold.

1 survey(s) · SHA-384 chain from genesis

Canonical JSON

Keys are sorted recursively, arrays keep their order, numbers use the shortest round-tripping form and undefined properties are dropped. Two equal values therefore produce byte-equal output on any platform, which is what makes the chain replayable instead of merely append-only.

Tombstones, not hard deletes

Retiring a survey or a surface sets a deletion timestamp and appends an event. Nothing is removed from the chain, so a reviewer can still prove what was recorded and when. The only thing a delete revokes is public access.