LIVE RELEASE EVIDENCE

Build manifest.
Evidence you can inspect.

Release identity, runtime readiness, and signed evidence from the live Numina verifier. Every status below comes from a fresh response.

Open the control plane

One release.
Across your workspace.

Numina 2.0.0 brings the website, operations workspace and installable mobile web app together. Your service workflows and private Treasury records remain available in the same design.

Loading deployed release…

Application build identity
Loading…
Application release schema
numina.application-release.v2

This build identity is calculated from the packaged application files. Detached build provenance is checked separately using the exact inventory fingerprint below. The rc22 control-plane dependency retains its own identity and signed records.

One file.
Trace its build.

A detached signed statement can identify the builder and the exact release file. The statement stays separate so the original file remains unchanged.

Signature verification has not been performed.

Manifest response SHA-256
Loading…
Inventory generation-time metadata
Loading…

No manifest response is currently loaded.

Look up signed statements ↗

The lookup opens GitHub’s public records for this fingerprint. A listed statement is evidence to verify; its presence alone does not establish a valid signature, SLSA level or deployment match. An empty or unavailable lookup does not verify the release.

Verify the downloaded file independently

Save the exact manifest above as application-release-v2.json. Use GitHub CLI to check its digest, the designated repository and the pinned builder identity.

Load the current manifest to prepare verification.

Review the verified source revision and workflow run against the intended release. A signature check does not by itself prove that these bytes were deployed or that all SLSA Build L3 controls are established.

Checking…

Loading current release evidence.

Not checked yet
RUNTIME DEPENDENCYChecking…

rc22 control-plane runtime

FROZEN COREChecking…

Checking… files reported checked

RUNTIME READINESSChecking…

Current runtime response

RUNTIME SIGNATUREChecking…

Verified in this browser

The supplied payload.
Identified precisely.

Reported rc22 release SHA-256
Checking…
Production files root
Checking…
Frozen core manifest root
Checking…
Signing key ID
Checking…
Reported SPDX SBOM hash
Checking…
Reported provenance hash
Checking…

The release, production and frozen-core manifest hashes are matched to the values recorded for this integration. SBOM and provenance hashes remain upstream-reported. The runtime declaration signs the release name and reported checks; it does not sign these manifest hashes or prove the full hosted build process.

Take the evidence
with you.

Download the responses fetched during this check. The manifest and attestation remain available through their original machine-readable APIs.

Inspect the full manifest response
Waiting for a response.

Confidence needs
clear boundaries.

Frozen core

The running service reports its supplied core validation result. Checking… passing conformance cases are reported by the runtime; the referenced rc22 test artifact has not been independently inspected here.

Signed runtime declaration

Your browser verifies the runtime declaration and control-state receipts against the runtime key pinned in this website. Manifest identity is compared separately. These signatures authenticate the runtime’s statements; they do not independently rerun release checks.

Supply-chain evidence

Artifact report: Checking…. The service publishes SBOM and provenance hashes. The referenced rc22 artifact bytes have not been independently inspected in this deployment. No SLSA build level is claimed.

Execution scope

The public verifier evaluates and signs policy decisions. The control plane works with internal records. These checks do not establish live-funds connectivity, financial balances, custody, or settlement.

The earlier web-adapter evidence remains available in the preserved control documentation. Historical rc20 evidence remains available through the rc20 manifest, SBOM and provenance. Its original hashes remain unchanged.

START WITH ONE WORKFLOW

Make the next step
concrete.

Bring a process, a constraint, or an integration challenge. We’ll discuss a scope that can be evaluated.