Signed Reports and the Verify Page

Every LaunchSafe report is signed and has a verify ID. Anyone can check a report file on a public page, without an account.

Edit on GitHub

What is signed

Each report version has a signed statement: who issued it, the organization and project, what LaunchSafe verified, the kind and version, when it was issued, and a hash of every file. The statement is signed with a key whose public half is published, so anyone can check it. Signing keys are kept so old reports keep verifying.

Every report has a verify ID that looks like LS-XXXX-XXXX-XXXX-XXXX. It is printed on the cover and every page of the PDF, and written into the JSON, SARIF and CSV files.

Checking a file

Open the verify page at app.launchsafe.com/verify-report and choose the file. No account is needed.

  • Your file is hashed in your browser. It is not uploaded.
  • The page tells you whether the file is genuine, a genuine file of a different report, changed, or not matched to any report LaunchSafe issued.
  • It also tells you whether the report is current, superseded or withdrawn.
  • By verify ID it shows what LaunchSafe verified, the names the organization gave itself (marked not verified), the version, the issue time and the signature, checked now. It never shows a finding or a withdrawal reason.

A genuine file means the file is exactly what LaunchSafe signed. It does not mean the organization is secure.

Checking it yourself

The verify page also shows how to check a report's signature with OpenSSL, with the report's ID and key filled in.

Time

If a trusted timestamp authority is not configured, the report's time comes from LaunchSafe's own clock, and the report says so.

On this page