GOLDLEVEL

Read-only capture · archive verification · visible proof gaps

Defensive Archive Starter

Capture selected public material without executing it. Verify what was preserved. Keep omissions, identity boundaries and unresolved assurance visible.

Review candidate · human release required

Purpose

Preserve what was delivered without granting it authority.

The starter creates content-addressed archives from a selected local folder or one explicitly named public HTTPS origin. Captured material remains untrusted data. The tools do not execute captured scripts, submit forms, use credentials or install packages.

01

Capture

Choose local data or explicitly opt into one public HTTPS origin.

02

Preserve

Store objects under content hashes with receipts and review signals.

03

Verify

Check paths, collisions, links, compression, manifests and hashes.

04

Qualify

Keep missing external scans, key pinning and live delivery explicit.

Verification

Check the archive and release envelope separately.

SHA-256 and SHA-512 identify exact bytes. A detached Ed25519 signature proves consistency against the supplied public key. Publisher identity still requires independent key pinning.

Archive checks

  • absolute and traversal paths rejected;
  • duplicate, case-fold and Unicode collisions rejected;
  • symbolic links and encrypted members rejected;
  • compression and manifest limits enforced;
  • optional extraction only to a new directory.

Content signals

  • executable and archive signatures;
  • active documents and web content;
  • UTF-8, UTF-16 and entity-normalised views;
  • double extensions and metadata mismatches;
  • instruction-like text and opaque binaries.

Proof boundary

A pass proves less than a promise.

A passing verification supports readability and recorded byte identity. It does not prove that the source is benign, complete, compliant, recoverable or free from undiscovered threats.

Recorded passes

  • release self-audit: PASS;
  • release-envelope verification: PASS;
  • Python compilation: PASS;
  • security regression: PASS;
  • 64-cell security matrix: PASS;
  • secret and private-method scans: 0 hits.

Still requires proof

  • external antivirus: REQUIRES LOCAL PROOF;
  • YARA: REQUIRES LOCAL PROOF;
  • behavioural sandbox: REQUIRES LOCAL PROOF;
  • publisher identity: REQUIRES INDEPENDENT PINNING;
  • live delivered bytes: NOT VERIFIED;
  • malware-free status: NOT CLAIMED.

Download and verify

Versioned files under one stable product route.

The direct ZIP is the source-readable review candidate. The source-upload packet bundles public verification material and receipts for controlled transfer.

SHA-256d74d407429fc69c73dc13391c09190f1b27fcf215ebb86918c8cfd6c8e27648f
SHA-51257137cc560ea05ce814782884633b509ad462196d61b6e3d079f84f60441a69cf08204eb6b8c2bd90ee6598ff83ddc599c5d9443d2deb045c11f311c5fc61ca0
Key fingerprint9c2d0c40fe8b2c6c70f19cda0e00a78c0c1c47b500f4c21431b7c3947069f8b9
Packet SHA-256c191618bdf353e300f94287096f3ca09a100cdf5f16d662b6bc4813c71c4cc8d
Receiptsrelease · metadata · tests