Trust

This page exists for one job: if someone hands you a compliance evidence packet produced by SMDurgan, LLC, you can confirm here that it came from us and has not been altered, without contacting us and without trusting whoever handed it to you.

Who signs

Packets are signed by SMDurgan, LLC, the company under contract with the firm. They are not signed by an individual. A packet is often read years after the work, and the party a reader needs to identify is the one that holds the obligation, not whoever happened to run the export. The person who ran it is recorded separately inside the packet, under generated_by.

The signing keys

The current key always lives at the same address, so a link to it never rots:
https://smd.services/keys/evidence-packet-signing-key.pem

Fingerprint (SHA-256 of the DER public key)StatusIn use
64a294493be8bfed2f09c8ce83316744af0af95d19f2fc47ef48337181f98c8aEd25519active2026-08-01 to present

A retired key stays on this page permanently. Packets signed under it are still authentic, and removing the key would make them unverifiable for no reason. If a key was retired because its private half may have been exposed, the reason says so, and you should weigh packets signed after that date accordingly.

Verifying a packet

Open manifest.json inside the packet and read the fingerprint under signer.key_id. Find that fingerprint in the table above and download that key. Then check the detached signature over the exact bytes of the manifest:

openssl pkeyutl -verify -pubin \
  -inkey evidence-packet-signing-key.pem \
  -rawin -in manifest.json -sigfile manifest.sig

A success result means the manifest is ours and unmodified. The manifest carries a SHA-256 for every other file in the packet, so once it verifies you can hash any individual file and compare.

What the signature does not tell you

It proves origin and integrity after export. It says nothing about whether the underlying audit record is correct. That is a separate mechanism: the record is hash chained, so a deleted, reordered, or inserted entry breaks the chain at a point anyone can identify. The packet reports both, separately, and never blurs them.

Questions

If a packet fails to verify, tell the firm that gave it to you before you tell us, then write to team@smd.services.