Manifest receipt

Locked & verifiable.

An evaluation claim anchored to a SHA-256 hash at the recorded time. Anyone can re-derive it from the canonical bytes below.

SHA-25614bc38f2bd355d86457cbedba9b37a25f2da7eb57350a7e26a591ba55d09fd92
Registered2026-09-23T11:51:18.625Z
Independent timestampRFC 3161 · 2026-09-23T11:51:18Z · timestamp.sigstore.dev · token
Transparency logRekor v2 · log2025-1.rekor.sigstore.dev · index 122163511 · inclusion proof
Kindprml-linkage/0 start record (draft spec) — run-start pre-commitment; anchored before the result existed (tier L3 evidence) · manifest 5ce3c9c3484d…
Manifest
linkage_version: prml-linkage/0
manifest_hash: 5ce3c9c3484d8db1ffbc67dc4f3958c9a88009a0ae92ce51e045ea6b70258bc3
receipt: https://registry.falsify.dev/5ce3c9c3484d8db1ffbc67dc4f3958c9a88009a0ae92ce51e045ea6b70258bc3
run:
  dataset_hash: b21f3d81db8071257d5ff1deaeba1fd4303b62712e6fcc9715c7a86202cb5871
  environment: 'illustrative: darwin/python3.9/sklearn1.6.1/cpu'
  id: acc-demo-01-C1
  model_version: sklearn-logistic-regression-l2-C1.0
  started_at: '2026-09-23T11:51:18.178825Z'
raw bytes →
README badge
PRML locked[![PRML locked](https://registry.falsify.dev/badge/14bc38f2bd355d86457cbedba9b37a25f2da7eb57350a7e26a591ba55d09fd92.svg)](https://registry.falsify.dev/14bc38f2bd355d86457cbedba9b37a25f2da7eb57350a7e26a591ba55d09fd92)
Verify in CI
- uses: studio-11-co/prml-verify-action@v2 with: mode: verdict expected-hash: 14bc38f2bd355d86457cbedba9b37a25f2da7eb57350a7e26a591ba55d09fd92github.com/studio-11-co/prml-verify-action →

share on x →

Verify this hash yourself

Paste your manifest YAML. The canonical hash must match 14bc38f2bd35…. This runs the registry's own canonicalization module (canonical.js) in your browser; for verification that does not trust this registry at all, use any of the four reference implementations offline.

Verify the independent timestamp (RFC 3161, offline)

The token countersigns this manifest hash with the timestamp authority's key, so the time claim no longer rests on this registry. Verify with OpenSSL 3 (LibreSSL, the macOS default, cannot check the ESS extension):

curl -sO https://registry.falsify.dev/14bc38f2bd355d86457cbedba9b37a25f2da7eb57350a7e26a591ba55d09fd92.tsr
curl -s https://timestamp.sigstore.dev/api/v1/timestamp/certchain -o chain.pem
awk 'split_after==1{n++;split_after=0} /END CERTIFICATE/{split_after=1} {print > ("tsa-" n ".pem")}' n=0 chain.pem
openssl ts -verify -digest 14bc38f2bd355d86457cbedba9b37a25f2da7eb57350a7e26a591ba55d09fd92 \
  -in 14bc38f2bd355d86457cbedba9b37a25f2da7eb57350a7e26a591ba55d09fd92.tsr -CAfile tsa-1.pem -untrusted tsa-0.pem

Expected output: Verification: OK.

What this receipt proves — and what it does not

PRML v0.2 is a frozen RFC (comment window closed 2026-05-22) — spec.falsify.dev/v0.2-rfc. Editor: spec.falsify.dev/editor.