Audit explorer
Anonymous visitors see a snapshot taken from the reset. The auditor persona can open a live view. The snapshot lists synthetic subjects only.
Verified on the laptop, not yet on a public host.
Integrity
- Ferrum. Ferrum residency audit = hash-chained with a verify endpoint (verify is unauthenticated and reveals chain metadata only).
- Solum. Solum audit = hash-chained single-writer file, detects after-the-fact edits but is not an external signature.
- HELIOS. HELIOS = signed report over the Solum export.
- ga4gh-infra broker. ga4gh-infra broker = JSON log lines only, not queryable over HTTP, not tamper-evident, visa JWTs are embedded without signature verification unless verify_embedded_visas is enabled (off).
- BRA. BRA = SQL rows with input hash only.
HELIOS signing public key
Signed HELIOS reports on this demo are verified against an Ed25519 public key. SHA-256 of the public key file: fe3a4604ec534b28672148b3aba58ca85863626fa4114a5af954924fc620dda1. First used (UTC date): 2026-10-11. Auditors can download /helios-report.json and check the signature against that key (trust store or helios validate).
fe3a4604ec534b28672148b3aba58ca85863626fa4114a5af954924fc620dda1
If the key is rotated, this page will show the new fingerprint and date, and the previous public key will be archived as retired (see docs/RUNBOOK.md). A demo reset does not rotate the key.
The auditor passport is not ferrum:admin. Ferrum returns only rows whose requester matches that token's sub.
Ferrum's residency audit records data access events but not denied or anonymous attempts.
Caddy writes a JSON access log for the auditor persona: time, method, path, and status. Client addresses are truncated to an IPv4 /24 or an IPv6 /32. Retention is 168 hours, at most 10 MiB per file and 7 files. Badge: plain log file, not tamper-evident.
The live view caps the time window at 7 days and does not page. The proxy is limited to 64 MiB and keeps the sidecar token on the server.