Verify counter-signed declaration

Did a vendor send you a counter-signed declaration? Paste the token or the .intoto.json file below to check who issued it and that it has not been altered since. Verification happens in your browser, with the codafort public key that ships with this page: nothing is sent, and it works offline.

What this proves (and what it does not). That the license holder declared this result, at this version of the code and with these rules, and that codafort counter-signed it. It does not prove the absence of vulnerabilities and does not replace the independent pentest required by Brazilian CMN Res. 5.274, Art. 22-A.

Older browser? Verification needs Chrome 137+, Safari 17+ or Firefox 129+. The command line is free too: codafort attest verify <token>.