The Dossier reads the other tools' signed reports: their content hashes, dates, versions, rule settings and answer counts. It never reads, stores or reprints a client value, because no name, no amount, no account, no country of yours exists in any report of the suite. It cites a report by its content hash and its answers, and names the review by its identifier only.
The document the Dossier writes is saved next to your files and in no other place. Its content hash is computed like that of each tool's results file in the suite, and the command that checks it is printed on the page that presents it.
Verify on the results file itselfThe public results file, releve-public.json, carries its own content hash and holds answers, content hashes, dates and counts. Search it for anything else.
run it yourself
python3 -c "import json; d=json.load(open('releve-public.json')); print(sorted(d), '/', sorted(d['questions']))"prints the file's top-level keys (controls, coverage, questions, settings, seal, the content hash) and its questions
Where it livessrc/dossier.ts:9 · src/empreinte.ts:58 · src/empreinte.ts:63