CRUSETRA

Check each report: present, sealed, signed, fresh, consistent.

A reviewer asks whether the whole chain still holds.
The Dossier reads the four reports and checks that each one is present, frozen, fresh, signed with a key you can check, and consistent with the others.

git clone https://github.com/ArslaneSempai-ui/crusetra-dossier cd crusetra-dossier npm ci --ignore-scripts npm run dossier -- --reports=a-measured.json,b-measured.json
The five checks, state 01: The Dossier reads all four tool reports as one audit file. reports present: 4 of 4consistent control: 4 of 4
finding 014 of 4 present

A reviewer does not want four files. The Dossier reads all four reports and answers on them as one. In this Dossier, all four reports are present, and all four hold the top control, consistent.

4tool reports present, of the 4 the suite produces
4reports at the top control, consistent
The five checks, state 02: The Dossier recomputes each content hash and checks it matches. content hash recomputed: 4 of 4five controls per report
finding 024 hashes recomputed

The Dossier recomputes the content hash of each report and checks it against the stored value. One dataset cannot carry two hashes, and a report from an unknown tool version is named in the output.

4content hashes recomputed and matching, on the 4 reports read
5controls each report passes: present, hash, signature, validity, consistency
The five checks, state 03: Every report now carries a verifiable signature. signatures verified: 4 of 4signature refusals: 0
finding 030 signature refusals

On its first run the Dossier verified zero signatures across the suite, one refusal per report, because an unverified signature does not count as valid. The records were signed, and today the Dossier verifies all four with no refusal left.

4public-record signatures verified, of the 4 reports read
0signature refusals remaining across the 4 reports
The five checks, state 04: All four measurements fall within the declared validity period. within validity: 4 of 4oldest measurement: 18 days
finding 04oldest 18 days

The Dossier dates each measurement against a validity period the record declares, 90 days by default. In this Dossier, all four fall within it, and the oldest, routing, is 18 days old.

4measurements within the declared validity period, on the day of this Dossier
18 daysdays since the oldest measurement, routing, within the period
The five checks, state 05: Your reviewer can check the Dossier alone. 4 questions answered as onevalidity period: 90 days
finding 05verifiable on your machine

The Dossier is written next to your files and carries the same content hash the suite uses. Your reviewer confirms the result with no help from us.

4questions the Dossier answers as one, for the whole suite
90 daysdays of the declared validity period it checks freshness against

Crusetra, explained.

The five Dossier findings