← Policies

Policy of record

Independent verification

Every page names the exact release it was compiled from, and no one has to trust this site to check it.

revision sha256:7aaf4a64a993… · published in release sha256:2fff3dda7ab7…

The release graph is signed, content-addressed, and independently mirrorable. Any consumer can prove what the catalog said, when, from local bytes.

How to verify a release

  1. Choose the focused public dataset for the records you need: companies.json, startup-credits.json, or agent-readiness.json. Each carries the same release ID and artifact digest, with stable identifiers and revision digests for its records.
  2. Recompute any revision digest from the record's canonical bytes and compare. Each revision is content-addressed, so a single changed fact changes its digest.
  3. Follow a record's evidence bindings to their observation and capture digests. The bindings name the exact bytes, and the byte ranges, that support each field.
  4. Run the public repository's read-only reference verification command. It accepts only local bytes and pinned roots, and checks the signed manifest, the signer registry chain, and the object index without calling this site.

TLS, a hosting provider, or an API response is never the sole proof.