szl-provctl-live

provenance-DAG verify hologram · in-toto Statement v1 + SLSA provenance v1 · every SHA3-256 digest re-hashed in YOUR browser
verifying…

The sample below is a real provenance DAG produced by the canonical SZLHOLDINGS/szl-provctl kernel (chain source shown in footer). Nothing here is fabricated: this page independently re-computes the SHA3-256 hash-chain of every receipt with a vendored, pinned js-sha3 0.8.0 (MIT) and re-checks every DAG edge. Labels: MEASURED-in-your-browser = re-hashed here now · REPORTED = as emitted by the kernel.

Provenance DAG

in-toto Statement v1 https://in-toto.io/Statement/v1

Subject digest = the finetune chain head, so a signature over this Statement binds to the exact provenance. REPORTED (kernel-emitted); subject digest head match: …


  

SLSA provenance v1 https://slsa.dev/provenance/v1

A governed run as a first-class build-provenance event (spec-exact field names). REPORTED
show SLSA statement
⟨ 4TH WALL ⟩ You are reading rendered bytes. Don’t trust them — hash them:
canonical source: SZLHOLDINGS/szl-provctl-live · verify from outside: curl -sL https://huggingface.co/spaces/SZLHOLDINGS/szl-provctl-live/resolve/main/index.html | sha256sum
Integrity & origin of this page only — never the accuracy of anything on it. Known platform delta: Hugging Face may inject one window.huggingface variables <script> into <head> of the served page, so the in-browser hash can differ from the source hash by exactly that banner — diff the two documents to see it. Distrust only differences beyond that. Doctrine v11.