Trust
This page exists for one job: if someone hands you a compliance evidence packet produced by SMDurgan, LLC, you can confirm here that it came from us and has not been altered, without contacting us and without trusting whoever handed it to you.
Who signs
Packets are signed by SMDurgan, LLC, the company under contract with the firm. They are not signed by an individual. A packet is often read years after the work, and the party a reader needs to identify is the one that holds the obligation, not whoever happened to run the export. The person who ran it is recorded separately inside the packet, under generated_by.
The signing keys
The current key always lives at the same address, so a link to it never rots:
https://smd.services/keys/evidence-packet-signing-key.pem
| Fingerprint (SHA-256 of the DER public key) | Status | In use |
|---|---|---|
| 64a294493be8bfed2f09c8ce83316744af0af95d19f2fc47ef48337181f98c8aEd25519 | active | 2026-08-01 to present |
A retired key stays on this page permanently. Packets signed under it are still authentic, and removing the key would make them unverifiable for no reason. If a key was retired because its private half may have been exposed, the reason says so, and you should weigh packets signed after that date accordingly.
Verifying a packet
Open manifest.json inside the packet and read the fingerprint under signer.key_id. Find that fingerprint in the table above and download that key. Then check the detached signature over the exact bytes of the manifest:
openssl pkeyutl -verify -pubin \
-inkey evidence-packet-signing-key.pem \
-rawin -in manifest.json -sigfile manifest.sigA success result means the manifest is ours and unmodified. The manifest carries a SHA-256 for every other file in the packet, so once it verifies you can hash any individual file and compare.
What the signature does not tell you
It proves origin and integrity after export. It says nothing about whether the underlying audit record is correct. That is a separate mechanism: the record is hash chained, so a deleted, reordered, or inserted entry breaks the chain at a point anyone can identify. The packet reports both, separately, and never blurs them.
Questions
If a packet fails to verify, tell the firm that gave it to you before you tell us, then write to team@smd.services.