Every consequential thing our agents do leaves a signed receipt, chained to the one before it. These are our real ones, published with our public key. Change a word, hide the change, delete one, reorder them. Your own browser does the checking.
Recomputing every SHA-256 and checking every Ed25519 signature with your browser's own cryptography. Nothing is fetched; nothing is taken on trust.
Pick a receipt and change anything on it. Then try to cover your tracks.
Each receipt's hash covers every field, so any edit shows. Re-computing the hash to hide it doesn't help: the hash is signed with a private key that never leaves our hardware, and the next receipt still points at the old hash. Deleting or reordering breaks the chain at that spot.
That makes the record tamper-evident: a change can't be hidden. It is not "tamper-proof", and we don't call it that.
Sovereignware clients keep their receipts on their own ArkNode. Check yours here: the files stay in this browser and are never uploaded.
An auditor needs three files and no account: the receipts, the public key, and a short script with no Sovereignware code in it.
Download them: receipts.jsonl · public_key.pem · verify_agent_receipts.py
pip install cryptography python3 verify_agent_receipts.py receipts.jsonl public_key.pem
It proves what was recorded, by which key, in what order, and that nothing changed since. It doesn't prove an agent's judgement was right.