Skip to the content.

Evidence bundle

You hit a TEE-hosted app. This page is the audit-ready report for what’s running there. It is built for two readers at the same time:

The mechanical part — proving the code running on this CVM is the same code in the public GitHub repo — is resolved on this page, automatically, on load. The judgmental part — whether the code does what it claims — is the source-reading work below. You don’t have to do it; you can pass the URL to someone whose job it is.

Reading: timelock at hermes-staging

Provenance

What’s in the bundle

What an auditor would actually look at in the source