Manifest receipt

Locked & verifiable.

An evaluation claim anchored to a SHA-256 hash at the recorded time. Anyone can re-derive it from the canonical bytes below.

SHA-256464df2bee6b479b742306cca356ce8e4904be22cad09beb5cfee29025c1b1d31
Registered2026-09-23T11:50:27.917Z
Independent timestampRFC 3161 · 2026-09-23T11:50:28Z · timestamp.sigstore.dev · token
Transparency logRekor v2 · log2025-1.rekor.sigstore.dev · index 122162688 · inclusion proof
KindPRML manifest — conformed to the published v0.1 schema at commit time
Manifest
version: prml/0.1
claim_id: 01a0ce19-5532-7c91-bed6-1ac1d4c0d689
created_at: '2026-09-23T11:49:15Z'
metric: accuracy
metric_args:
  split: stratified 70/30 train/test at the manifest seed
  features: all 20 attributes; categorical one-hot encoded; numeric standardised
  model_config: scikit-learn LogisticRegression, L2 penalty, C=1.0, max_iter=2000
  definition: share of correct predictions (good/bad credit) on the held-out test split
comparator: '>='
threshold: 0.7
dataset:
  id: uci-statlog-german-credit
  hash: b21f3d81db8071257d5ff1deaeba1fd4303b62712e6fcc9715c7a86202cb5871
  uri: https://archive.ics.uci.edu/dataset/144/statlog+german+credit+data
seed: 42
producer:
  id: acceptance-record-example.falsify
model:
  id: sklearn-logistic-regression-l2-C1.0
notes: 'Illustrative acceptance record (criterion C2 of plan AP-2026-001). Falsify OU plays both supplier and client roles; not a client engagement.'
raw bytes →
Amendment chain1 manifest — not amended · full chain →
README badge
PRML locked[![PRML locked](https://registry.falsify.dev/badge/464df2bee6b479b742306cca356ce8e4904be22cad09beb5cfee29025c1b1d31.svg)](https://registry.falsify.dev/464df2bee6b479b742306cca356ce8e4904be22cad09beb5cfee29025c1b1d31)
Verify in CI
- uses: studio-11-co/prml-verify-action@v2 with: mode: verdict expected-hash: 464df2bee6b479b742306cca356ce8e4904be22cad09beb5cfee29025c1b1d31github.com/studio-11-co/prml-verify-action →

share on x →

Verify this hash yourself

Paste your manifest YAML. The canonical hash must match 464df2bee6b4…. This runs the registry's own canonicalization module (canonical.js) in your browser; for verification that does not trust this registry at all, use any of the four reference implementations offline.

Verify the independent timestamp (RFC 3161, offline)

The token countersigns this manifest hash with the timestamp authority's key, so the time claim no longer rests on this registry. Verify with OpenSSL 3 (LibreSSL, the macOS default, cannot check the ESS extension):

curl -sO https://registry.falsify.dev/464df2bee6b479b742306cca356ce8e4904be22cad09beb5cfee29025c1b1d31.tsr
curl -s https://timestamp.sigstore.dev/api/v1/timestamp/certchain -o chain.pem
awk 'split_after==1{n++;split_after=0} /END CERTIFICATE/{split_after=1} {print > ("tsa-" n ".pem")}' n=0 chain.pem
openssl ts -verify -digest 464df2bee6b479b742306cca356ce8e4904be22cad09beb5cfee29025c1b1d31 \
  -in 464df2bee6b479b742306cca356ce8e4904be22cad09beb5cfee29025c1b1d31.tsr -CAfile tsa-1.pem -untrusted tsa-0.pem

Expected output: Verification: OK.

What this receipt proves — and what it does not

PRML v0.2 is a frozen RFC (comment window closed 2026-05-22) — spec.falsify.dev/v0.2-rfc. Editor: spec.falsify.dev/editor.