Integrity
Seal replay
Every create, update, decision and retire appends one event. seal_n = SHA-384(UTF-8(prevSeal) || canonicalJson(event_n)), chained from a genesis value derived from the survey id. Replay recomputes the whole chain and names the first link that does not hold.
- chain intact
Demo: billing-gateway
head 1286317f0da5c96a7ea25e9202d87ef64569a33e68536086d8da5dc61d0bce715e7675f969ff03d3addf8eff9bf1d13c
genesis 8e68c02f19f14f817905a3d826c3063c2079710248cd1059dcbb3dee3599edd029aaa3ec410673647304c3d7c1e18091
Events
1
replayed
Tombstones
0
kept
Algorithm
SHA-384
digest
First break
none
no broken link
Canonical JSON
Keys are sorted recursively, arrays keep their order, numbers use the shortest round-tripping form and undefined properties are dropped. Two equal values therefore produce byte-equal output on any platform, which is what makes the chain replayable instead of merely append-only.
Tombstones, not hard deletes
Retiring a survey or a surface sets a deletion timestamp and appends an event. Nothing is removed from the chain, so a reviewer can still prove what was recorded and when. The only thing a delete revokes is public access.