Skip to content

Verify the evidence

Every record Noset keeps is part of a hash chain and signed. You can check it on your own computer, without internet and without trusting Noset.

  • One chain per gate, on your server. Every record carries a sequence number and the hash of the record before it, and is signed with the gate’s own key. The key is made at noset login and never leaves that server, so Noset cannot forge or delete a gate’s records, and a missing number shows.
  • One chain per organization, on the Noset server: approvals, permits and admin events, plus a reference to every gate record. It is signed with your organization’s key.
  • Checkpoints: once an hour the server writes the latest hashes of every chain and has independent RFC 3161 time-stamp authorities stamp them. Copies go to the gates and, if you set up the evidence archive, to your own S3 storage with Object Lock. A rewritten chain no longer matches these copies.

Records are canonical JSON (RFC 8785) with SHA-256 hashes and Ed25519 signatures.

  1. In the Audit log, click Export and choose JSON.

  2. Run noset verify on the file. The Check it yourself card under the audit log shows the command with your organization’s key:

    Terminal window
    noset verify --strict --key <your organization's public key> evidence.jsonl

noset verify checks every record’s canonical form, hash and signature, the links between records of the same chain, sequence gaps, and the references between the organization’s chain and the gates’ chains.

Flag
--key KEY Trust this public key (base64url). Repeat it for several keys.
--strict Trust only the keys you give (and the ones a logged-in gate pinned), and require every gate chain the organization’s chain refers to.

Without --strict, noset verify can take keys from the file itself and says so: compare their fingerprints with the ones the web app shows.

  • OK: 1286 records in 3 chain(s), unbroken and signed. Each chain follows with its record count, its last hash and the key fingerprints it was signed with.
  • FAILED: evidence.jsonl: … names the first problem: a hash that does not match, a signature that does not verify, a missing record, a broken link. It also says how many records were read before it.

A failure means the file is not what Noset signed: it was changed, cut off, or records are missing. Keep the file and tell your Noset admin and Noset.

On a gate’s server, the gate keeps its chain in /var/lib/noset/gate. Run noset verify there on the gate’s evidence file; a logged-in gate trusts its own key and the organization keys it pinned.