Skip to main content
Two products, one construction

VerifyBundle: durable records anyone can check.

VerifyBundle is the consumer product built on the same SEP construction and the same verification rules, checked by its own pinned verifier. Seal a file or a note in your browser and get an offline-verifiable record. Its durable path is post-quantum today, so the record stays tamper-evident for decades. Same construction, same checks, a different audience.

Open VerifyBundle

One construction, two defaults

The same SEP construction and the same offline checks, tuned to two threat models.

AGA

Runtime governance

Seals each decision into an evidence bundle that verifies offline against the published format. Defaults to Ed25519, the zero-dependency operational default. The ML-DSA-65 + Ed25519 composite is specified and reference-verified against the NIST FIPS 204 vectors; it ships in the aga-mcp-server npm package, not in the aga-verify CLI, and it is not what the live gateway signs.

How AGA works
VerifyBundle

Durable consumer evidence

Seals a file or a note client-side into a portable record. Post-quantum in the durable path, today, for multi-decade tamper-evidence. Browser-signed, stores nothing.

verifybundle.com

What a record proves

Offline verification

Anyone checks a record on their own machine, with no network access and no callback. Built for air-gapped use.

Tamper-evidence

Any change to the sealed content or the receipt makes verification fail. The record proves it has not changed since sealing.

Self-contained record

Everything needed to check the record travels inside it: the sealed content hash, the signed seal, and its checkpoint. A VerifyBundle record carries a single seal by design; hash-linked chaining across many receipts is the AGA gateway profile.

Sealing timestamp

Each record carries the time it was sealed (the producer's signing-time clock, not a certified time authority).

What it does not prove

A passing check proves your data is unaltered since you sealed it, and the time it was sealed. The seal itself resists a quantum adversary's forgery. It does not prove who sealed it, or that the contents are true (the seal is signed with an ephemeral, anonymous key). Anyone can re-derive the check offline.

The offline verifier is pinned and dated. See the dated, offline re-derivable trust root on verifybundle.com.