Integrity Statement
Decision Archive exists to preserve and verify the existence and integrity references associated with consequential Decision Records while keeping private customer content access-controlled.
1. Private record boundary
Decision Records, Archive Drafts, evidence, report PDFs and customer-sensitive materials are private by default. They are not automatically published to the public Decision Archive.
Public visibility is a deliberate publication action and should expose only approved public-safe verification metadata.
2. Public verification metadata
A public archive entry may include an archive identifier, selected metadata, a timestamp and a SHA-256 verification reference generated when the archive entry is created.
The public verification reference is a cryptographic reference point for the published archive metadata. It is not a representation that the operational database itself is immutable.
3. Canonical report integrity
Solarascope's canonical fulfilment path calculates a SHA-256 checksum over the generated PDF bytes. The stored report record preserves that checksum for later comparison.
The normal storage path does not silently overwrite an existing report object at the same path. If an object already exists, the application compares checksum and byte length and treats a mismatch as an integrity conflict.
4. Access control
Private report retrieval is scoped through the application. Missing or deliberately incorrect customer credentials are denied; the correct scoped credential is permitted.
Private storage buckets and core Decision Record tables are configured fail-closed for ordinary anonymous/authenticated direct client access.
5. Publication governance
- No customer Decision Record is automatically made public.
- No public archive page should expose confidential diligence, evidence or customer materials.
- Public verification metadata should remain separate from the private Decision Record.
- Changes to the archive model or public claims should be re-verified before publication.
6. What Decision Archive does not claim
- It does not claim that the operational database is append-only or technically immutable.
- It does not provide legal, investment, accounting or compliance approval.
- It does not certify the quality or outcome of the underlying decision.
- It does not represent Solarascope as SOC 2, ISO 27001 or otherwise certified unless independently obtained and explicitly stated.