Offline verifier
Checks an AugmentEV receipt on this device. This page contacts nothing: it runs from the file you opened, and its security policy blocks every network request. You can disconnect before you start.
A receipt's own embedded key is never trusted. Always check against a key you obtained yourself.
Level 2: Intel TDX (live service key). Optional.
Checks, offline, that Intel's root attests the live service key was created and held inside a genuine Intel TDX trust domain whose measurements equal the expected-TD file you pin. If the box above holds a live record, the record is checked end to end: its key is taken from the key receipt (each service boot has a new key), so you pin the trust domain, not a key. Otherwise the receipt is checked against the key pinned above. Intel's dated collateral is evaluated at this device's clock; nothing is fetched.
Timestamp (RFC 3161). Optional.
Checks, offline, that a file existed no later than a stated time, on the word of a timestamp authority whose root is built into this page (Sigstore or DigiCert). Choose the file itself: its exact bytes are hashed, so a pasted copy would not match.
Public logs (Sigsum and Rekor). Optional.
Checks, offline, that a live-key receipt's exact bytes were recorded in public append-only logs: Sigsum (one or both of its logs), cosigned by a quorum of the independent witnesses built into this page, and Rekor when listed. Each entry must be signed by a log key the receipt's own quote binds. Check the receipt at Level 2 too: this does not check the quote itself.
What a valid result proves
It proves that the document was signed by the key you selected, and that not one signed character has changed since. For a lab receipt it also proves that the recorded environment check, job linkage, policy hashes and usage meter are internally consistent. For a chain, it proves that no receipt was removed, inserted or reordered.
It does not prove that the computation's answer was correct. It does not prove that the key belongs to anyone except the publisher you got it from (a published key is trust in its publisher, not a hardware root of trust). It does not re-check the chips' own evidence against the manufacturers' roots; this release reads the recorded verdicts. And it cannot tell whether other copies of a chain exist.
Is this file genuine? Before you disconnect, compare this file's SHA-256 with the checksum published separately by AugmentEV (for example with shasum -a 256 augmentev-verify.html). The build line below comes from inside this file, so it cannot vouch for itself. The same applies to the built-in keys: they are only as trustworthy as the file.