Verify an audit pack

Check that an audit pack from DoThat is signed by DoThat and that no file in it has changed. The check runs in your browser. The pack is not uploaded anywhere.

Your pack

Drop the pack’s zip here, or choose it.

The check reads manifest.json, hashes every file it lists with SHA-256, and verifies the ES256 signature in manifest.sig with DoThat’s public keys at /.well-known/audit-pack-keys.json. A pack says it is evidence prepared for an audit. It makes no compliance claim.