Integrity history

Public record of every chain verification state change on Proofroom's own rooms. Broken to valid is recorded with the same rigour as valid to broken. Silent self-healing is not allowed.

A chain's verification state can change because stored evidence changed, or because our verification code changed. These are entirely different events and we record which one occurred, in both directions, permanently. Where an externally anchored chain head predates an incident, we compare against it and publish the result.

Incidents may be resolved by correction rather than repair. See /verify for how explained discontinuities work.

Anchor reconciliation

In August 2026 a verifier defect and a now-removed hash-rewrite repair left permanent discontinuities on some internal rooms. Those breaks remain on the chain as explained discontinuities (correction_recorded + integrity incidents). We do not rewrite history to make the chain look unbroken.

Post-incident anchors are published on the daily cadence. New events after a discontinuity verify normally within their segment. Compare the latest merkle root on GitHub against /verify.

Anchoring cadence
Daily at 01:15 UTC (Vercel cron) with an Inngest backup; manifests publish to the public anchors repository.
Anchoring room
proofroom-chain-anchors · chain valid · 71 events
Latest published anchor
2026-09-30 · timestamped · 12 heads · manifest
Open integrity incidents
0

Public anchors: https://github.com/Proofroom/proofroom-anchors. Independent check: /verify.

Incident log

Chain head anchoring2026-08-03 07:12:02 UTC → 2026-08-03 07:12:02 UTC

chain valid → chain valid · seq 1

Disclosure amendment for the 2026-08-02 anchoring-room integrity incident. (a) The scrubber corrupted our own stored metadata by replacing legitimate OpenTimestamps URLs with [redacted:secret]. (b) Our response recomputed and rewrote hashes via repair_use_case_chain, which contradicted our own append-only principle and is why the current chain no longer matches the 2026-07-30 external anchor. (c) The repair capability has since been removed so this cannot recur. Wrong rows are corrected forward only.

Cause: Stored evidence changed. Evidence altered: yes (2). Verifier v1.2 → v1.2.

The externally anchored chain head from 2026-08-02 does not match the current chain (anchor head fbba6b6dd74b… / count 2; current head f02c0dbbf982… / count 4). Unless proven otherwise this indicates a data change.

Chain head anchoring2026-08-02 10:11:39 UTC → 2026-08-02 10:40:00 UTC

chain valid → chain broken · seq 1

Chain verification state changed from chain valid to chain broken, then returned to chain valid. Broken at sequence 1. Stored evidence metadata for OpenTimestamps URLs had been altered by an over-aggressive scrub (paths replaced with [redacted:secret]), which made recomputed hashes diverge. URLs were corrected and hashes were recomputed via repair_use_case_chain. Verifier 1.0 → 1.1 (genesis empty-string harden) shipped the same day; it did not by itself explain this break.

Cause: Stored evidence changed. Evidence altered: yes (2). Verifier v1.0 → v1.1.

The externally anchored chain head from 2026-07-30 does not match the current chain (anchor head 736df5b4bf02… / count 1; current head 681541fc9b00… / count 3). Unless proven otherwise this indicates a data change.