Signed Reports and the Verify Page
Every LaunchSafe report is signed and has a verify ID. Anyone can check a report file on a public page, without an account.
What is signed
Each report version has a signed statement: who issued it, the organization and project, what LaunchSafe verified, the kind and version, when it was issued, and a hash of every file. The statement is signed with a key whose public half is published, so anyone can check it. Signing keys are kept so old reports keep verifying.
Every report has a verify ID that looks like LS-XXXX-XXXX-XXXX-XXXX. It is printed on the cover and every page of the PDF, and written into the JSON, SARIF and CSV files.
Checking a file
Open the verify page at app.launchsafe.com/verify-report and choose the file. No account is needed.
- Your file is hashed in your browser. It is not uploaded.
- The page tells you whether the file is genuine, a genuine file of a different report, changed, or not matched to any report LaunchSafe issued.
- It also tells you whether the report is current, superseded or withdrawn.
- By verify ID it shows what LaunchSafe verified, the names the organization gave itself (marked not verified), the version, the issue time and the signature, checked now. It never shows a finding or a withdrawal reason.
A genuine file means the file is exactly what LaunchSafe signed. It does not mean the organization is secure.
Checking it yourself
The verify page also shows how to check a report's signature with OpenSSL, with the report's ID and key filled in.
Time
If a trusted timestamp authority is not configured, the report's time comes from LaunchSafe's own clock, and the report says so.