Sample

A sample evidence report

This is what the report looks like at the end of a matter. It was made from a synthetic ledger. The timestamps are real, from a free public authority, but they cover made-up data. Back to the WORM ledger page.

SAMPLE, SYNTHETIC DATA. This report was generated from a made-up ledger to show the format. Nothing in it describes a real business, person or transaction.

Evidence report: sample ledger

Ledger file: sample-ledger.log · Generated 2026-10-02 23:58:46 UTC

INTACT

Every check that was run found no problem. The tables below say exactly what was and was not checked, and the section "What this does NOT prove" says what no check here can show.

What was checked

CheckResultDetail
Hash chain (bin/worm_verify, read-only)OKRESULT: CHAIN INTACT: ledger is tamper-evident; blocks parsed: 12, malformed lines: 0, broken links: 0, content hash mismatches: 0, sequence gaps: 0
Record countOK12 records read
First and last record timeOK2026-10-02 23:58:30.935 to 2026-10-02 23:58:31.499 (as written by the ledger's own clock; the time zone is not recorded)
Signed tipOKthe tip signature verifies under the supplied public key over the ledger's current tip. Public key SHA-256 fingerprint of the PEM file: c27a0f4502a886fdc67e639ec2cfc3ca9f6fdbf3a0ca01ef48f4e5bd0a29151d.
Independent timestamps (RFC 3161), re-verified offlineOK2 of 2 verified; latest authority time 2026-10-02T23:58:46Z; 0 refused-stamp alerts in the journal
Ledger still contains every timestamped tipOKeach timestamped record count and tip hash matches the ledger at that position

Record types

Event typeRecords
RECEIPT12

Independent timestamp timeline

Each row is a timestamp from an authority outside the ledger's owner, covering the ledger as it stood: at least that many records, ending in that exact tip, no later than that time.

#Authority time (UTC)AuthoritySerialCovers recordsTip hash (prefix)Verified offline
12026-10-02T23:58:31Zfreetsa0x08CF3B2F1 to 84f7307b59ecbc96fOK
22026-10-02T23:58:46Zfreetsa0x08CF3BC51 to 125a9bf02b80495b63OK

Records

Metadata only: record content is not included in this report. The first and last 50 records are listed.

#Time as writtenEvent typeStatusHash (prefix)
12026-10-02 23:58:30.935RECEIPTSEALED025e7de58ab93154
22026-10-02 23:58:30.951RECEIPTSEALED76516c6e3cd4d1b5
32026-10-02 23:58:30.968RECEIPTSEALED2a6a388b4c8a8648
42026-10-02 23:58:30.984RECEIPTSEALED93d16f16577b9161
52026-10-02 23:58:31.000RECEIPTSEALED7513161e291d9bb0
62026-10-02 23:58:31.016RECEIPTSEALED288a4476ebba26cd
72026-10-02 23:58:31.032RECEIPTSEALED6f7250295789fa72
82026-10-02 23:58:31.048RECEIPTSEALED4f7307b59ecbc96f
92026-10-02 23:58:31.447RECEIPTSEALEDbe368e6e28f009fb
102026-10-02 23:58:31.465RECEIPTSEALEDd29b3a20eba7532a
112026-10-02 23:58:31.483RECEIPTSEALEDbd37059e671403e9
122026-10-02 23:58:31.499RECEIPTSEALED5a9bf02b80495b63

How this works

A WORM ledger is a text file in which every record carries the hash of the record before it, so changing or removing a record in the middle breaks every link after it. This report ran the open verifier worm_verify over the file, which recomputes each record's hash and its link to the previous record. If a signed tip was supplied, the verifier also checked a digital signature over the record count and last hash, which is what exposes records cut from the end. Separately, a timestamp authority independent of the ledger's owner signed a small file stating the ledger's record count and last hash, and each signed token (RFC 3161) is re-checked here offline against the authority's certificate. Each token shows that the ledger had at least that many records, ending in that exact hash, no later than the time the authority signed. The report then confirms the ledger still contains every timestamped tip at the position that was stamped. Anyone can repeat these checks with the commands at the end, which do not depend on this report.

What this does NOT prove

Process description a custodian may reference

On 2026-10-02 23:58:46 UTC, evidence_report.py version 1.0.0 was run on a file named sample-ledger.log (SHA-256 ea1431f34fbcc4c628750834ccee69f9293762acc57021b5eaaeb692a3d8d409, 4548 bytes). The program (1) ran bin/worm_verify, a read-only program that recomputes each record's hash and its link to the previous record; (2) checked the signature over the ledger tip, using the public key whose SHA-256 fingerprint (of the PEM file) is c27a0f4502a886fdc67e639ec2cfc3ca9f6fdbf3a0ca01ef48f4e5bd0a29151d; (3) read the timestamp journal sample-ledger.log.stamps and re-verified each RFC 3161 token offline with OpenSSL against the authority certificate; (4) read the ledger once to count records and note first and last record times; and (5) compared each timestamped tip with the ledger. It did not modify the ledger. The results are listed above.

The program did not determine who wrote the records, whether their contents are true, or how any key was stored.

This description is provided for convenience. It is not a certification, declaration or affidavit, and it is not legal advice. Any certification or declaration about these records would need to be prepared with a lawyer and made by a person who has knowledge of how the records were created and kept.

Re-check this independently

shasum -a 256 sample-ledger.log                        # compare with the SHA-256 in the footer
bin/worm_verify sample-ledger.log --require-signed-tip signer.pub --tip-sig sample-ledger.log.tipsig
python3 tools/phantom_stamp/stamp_ledger.py journal-verify sample-ledger.log
python3 tools/phantom_stamp/phantom_stamp.py verify sample-ledger.log.stamps/subject-000002.json
openssl ts -verify -in sample-ledger.log.stamps/subject-000002.json.tsr -data sample-ledger.log.stamps/subject-000002.json -CAfile tools/phantom_stamp/tsa/freetsa/cacert.pem -untrusted tools/phantom_stamp/tsa/freetsa/tsa.crt -attime 1790985526      # OpenSSL 3, no network

These are the commands the report's own tools use, run with the ledger and the journal folder alongside. They do not depend on this report. We can supply the tools with your package if you want to repeat the checks yourself.

Generated 2026-10-02 23:58:46 UTC by evidence_report.py v1.0.0. Ledger file sample-ledger.log: SHA-256 ea1431f34fbcc4c628750834ccee69f9293762acc57021b5eaaeb692a3d8d409 (4548 bytes). SAMPLE: SYNTHETIC DATA.