CertEvidence synthetic certificate-evidence sample
==================================================
Generated 2026-09-30 from apps/cpsc/demo.py and its existing fixtures in
codyras/product-compliance-ops, deployed source revision:
1ec11628cb548c576d8b2fb83a85cda728318008

Every organization, person, qualification, review and approval here is fictional.
Fixture document dates are fictional business dates. Review timestamps are the
local demo execution time, not customer activity. Documents are short text/CSV
stand-ins: recorded page references illustrate the app's locator field, while
field-source-map-v2.csv also locates each value in the downloadable fixture.
The reviewer scope rationale is illustrative, not a toy-testing rule or advice.

What is included
----------------
Six unchanged source fixtures; exact canonical snapshots for completed v1 and
v2; their engine-produced metadata and hashes; field-source map; internal and
customer data approval history; exception resolutions; readable broker handoff.
The supplier retest changes report VTL-26-08812 to VTL-26-09544 and test date
2026-05-22 to 2026-06-30 in a newly reviewed v2. V1 remains available unchanged.
This is the seeded new-version workflow, not a real customer's correction.

What is not included
--------------------
No credentials, signing key, application database, government receipt, submission,
Registry import, expert engagement, current official-schema CSV or real customer
data. Exported data is not a certificate issued by CPSC or a compliance decision.
Customer data approval and internal review are distinct from regulatory approval.

Verify offline
--------------
1. SHA-256 each file in manifest.files and compare its exact bytes to the digest.
2. SHA-256 snapshot-v1.json and snapshot-v2.json; compare each to
   manifest.versions[].snapshot_content_sha256 (do not reformat the JSON).
3. For each version, create sorted-key, compact UTF-8 JSON with these keys:
   tenant_id, record_type, record_key, version_no, prev_hash, snapshot_sha256.
   prev_hash is an empty string for v1; snapshot_sha256 is the content digest.
   SHA-256 that header; it must equal the recorded snapshot_hash.
4. V2's prev_hash must equal v1's snapshot_hash. Editing a source or snapshot
   causes a digest mismatch against this manifest.

These are v2-unsigned local demo seals. Public digests detect changes against a
trusted original; they do not independently authenticate the publisher. No secret
or HMAC signature is distributed. These demo IDs do not exist in the live app's
verify service; use the offline checks rather than presenting them as live records.
