CertEvidence synthetic certificate-evidence sample ================================================== Generated 2026-09-30 from apps/cpsc/demo.py and its existing fixtures in codyras/product-compliance-ops, deployed source revision: 1ec11628cb548c576d8b2fb83a85cda728318008 Every organization, person, qualification, review and approval here is fictional. Fixture document dates are fictional business dates. Review timestamps are the local demo execution time, not customer activity. Documents are short text/CSV stand-ins: recorded page references illustrate the app's locator field, while field-source-map-v2.csv also locates each value in the downloadable fixture. The reviewer scope rationale is illustrative, not a toy-testing rule or advice. What is included ---------------- Six unchanged source fixtures; exact canonical snapshots for completed v1 and v2; their engine-produced metadata and hashes; field-source map; internal and customer data approval history; exception resolutions; readable broker handoff. The supplier retest changes report VTL-26-08812 to VTL-26-09544 and test date 2026-05-22 to 2026-06-30 in a newly reviewed v2. V1 remains available unchanged. This is the seeded new-version workflow, not a real customer's correction. What is not included -------------------- No credentials, signing key, application database, government receipt, submission, Registry import, expert engagement, current official-schema CSV or real customer data. Exported data is not a certificate issued by CPSC or a compliance decision. Customer data approval and internal review are distinct from regulatory approval. Verify offline -------------- 1. SHA-256 each file in manifest.files and compare its exact bytes to the digest. 2. SHA-256 snapshot-v1.json and snapshot-v2.json; compare each to manifest.versions[].snapshot_content_sha256 (do not reformat the JSON). 3. For each version, create sorted-key, compact UTF-8 JSON with these keys: tenant_id, record_type, record_key, version_no, prev_hash, snapshot_sha256. prev_hash is an empty string for v1; snapshot_sha256 is the content digest. SHA-256 that header; it must equal the recorded snapshot_hash. 4. V2's prev_hash must equal v1's snapshot_hash. Editing a source or snapshot causes a digest mismatch against this manifest. These are v2-unsigned local demo seals. Public digests detect changes against a trusted original; they do not independently authenticate the publisher. No secret or HMAC signature is distributed. These demo IDs do not exist in the live app's verify service; use the offline checks rather than presenting them as live records.