Auditor kit
Check a customer's evidence yourself, offline, without trusting CAIN. You need Python 3.9 or newer and the cryptography package. The three scripts below import nothing from CAIN.
1. Get the pack from the customer
The customer exports their own evidence with their API key:
curl -X POST https://cainstudio.online/fabric/scitt/auditor-pack \
-H "X-API-Key: $CAIN_API_KEY" -H "Content-Type: application/json" \
-d '{"since_tree_size": 0}' -o pack.json
For a follow-up audit, set since_tree_size to the tree_size of the checkpoint you kept last time.
2. Pin the keys yourself
Get the notary keys from GET /fabric/scitt/keys and the contract root key from GET /fabric/contracts/trust, ideally out of band. Keep them. If you don't pin them, the result says SELF_ASSERTED: that shows the pack is internally consistent, not who signed it.
3. Verify
python3 auditor_pack_verify.py pack.json --scitt-keys keys.json --root-key BASE64 \ [--previous-checkpoint last_checkpoint.json]
Downloads (keep all three in one folder):
- auditor_pack_verify.py: checks the whole pack
- scitt_verify_offline.py: RFC 9162 inclusion and consistency proofs, Ed25519 checkpoints
- contract_verify_offline.py: governance contracts, signatures, receipt chains, replayed decisions
Checksums are in MANIFEST.json. The publisher countersignature is in _publisher/auditor-kit.json.
What it checks
- Every evidence receipt verifies against one signed checkpoint.
- The receipts cover consecutive log positions, so nothing in the range can be left out without detection.
- The log was only appended to since your last audit (consistency proof back to the checkpoint you kept).
- Every governance contract export passes the clean-room verifier.
What it does not prove
That the recorded events are true. It proves the evidence was not altered or rewritten after it was logged. It is not a certification. The same operator runs the log; there are no external witnesses yet.