Evidence verification
Verify an R2PQ Evidence Receipt
An R2PQ Evidence Receipt records what an assessment committed to, and when an independent timestamp authority saw that commitment. This page checks it cryptographically and tells you exactly what the result means.
Verification runs entirely in your browser. Your receipt is never uploaded, and this page makes no network request while checking it.
Provide a receipt
Receipts are JSON files, typically around 10 KB. Nothing you paste leaves this page.
Result
Ready
Upload, paste, or load the demo receipt to begin.
What was checked
These are distinct questions. A receipt can be cryptographically sound and still tell you nothing about who produced it.
-
Integrity
Do the receipt's own hashes agree with each other?
Not yet checked
-
Timestamp
Does an RFC 3161 token commit to this evidence?
Not yet checked
-
Signature
Is the timestamp token's signature intact?
Not yet checked
-
Certificate trust
Does the signing certificate chain to a trusted root?
Not evaluated in the browser
-
Provenance
Who performed this assessment?
Not established
What this establishes
What it does not establish
Technical detail
See what tampering looks like
The demo receipt above verifies. Change a single character of its committed evidence and the check fails — that is the whole point of a cryptographic commitment.