The offline verifier
One self-contained HTML file. It cannot make network requests: its own security policy forbids them, and nothing is fetched at any point. Open it here, or save it and open it with your network switched off.
The live inputs are public: the current key receipt at https://api.augmentev.ai/v1/attestation/live-key and its log evidence at /v1/attestation/live-keys/<key id>/log-evidence.
Downloads and pins
The verifier compares what it is given against values you pin. A pin is only as trustworthy as where you got it: README.txt explains how to check each one without relying on us.
A command-line verifier for macOS is coming once its Apple notarization is complete.
What a valid result proves, and what it does not
A valid key receipt proves that a genuine Intel TDX trust domain, with the measurements you pinned, generated and held our live signing key. Valid log evidence proves that receipt was public before the key signed anything.
It does not prove what the software computed, says nothing about GPUs or any machine other than the attested one, and cannot see revocations Intel published after the collateral's date. It also does not prove that we cannot access that machine: today we keep administrative access to it for operations, and the measured deployment manifest shows this. The hardware boundary protects the workload from the cloud host and its operators, not yet from us.
Quick online check (convenience, not independent)
This is the checker this page used to offer. It sends the record you paste to our API (POST /v1/evidence/verify), and our server answers, so you are trusting our server's answer. It is useful for a quick look or to try a tampered record. For an independent check, use the offline verifier above.
Straight talk: this checker trusts only the service's current signing key, and each restart of the service makes a new one. The sample is a real record signed by an earlier key, so it now returns valid:false with untrusted_signing_key. A record signed by a previous key is checked with the offline verifier, against the key receipt for that key.