Browser-local capsule verification

Move evidence.
Not trust.

Select one .runbook capsule. Its bytes cross only into an isolated browser Worker, then return as a deterministic verification receipt.

Verification boundaryLocal browser memory
  • No server upload path
  • No online evidence checks
  • No payload rendering or storage

The served verifier origin and browser remain trusted computing components.

Evidence relay / one-way inspection

Capsule in. Receipt out.

Checking browser
01Local capsuleOpaque bytes
NO UPLOAD
02Isolated verifierBounded Worker
JCS BYTES
03Exact receiptNo added newline
Drop one capsule hereor choose a local file · 1 byte–64 MiB
Expected: valid

Golden fixture

Run minimal-synthetic-root.runbook from the frozen embedded corpus.

Expected: invalid

Tampered twin

Choose the one-byte payload mutation. Its author signature remains valid while package integrity fails.

Normative output

Verification receipt

No capsule evaluatedSelect a local file or run one of the synthetic guided checks.