Exact bytes · executed evidence · visible limitations
Independent review passed · exact public artifacts available · production release not authorized
IntegrityLock Community Edition — Assurance & Verification
This page records what was reviewed, what passed, what was skipped, which exact artifacts were approved, what human determinations were recorded, and what IntegrityLock’s evidence does—and does not—mean. It is an assurance record for an unsigned open-source research preview, not a certification or production-readiness claim.
- Version 0.2.0-alpha.5
- Candidate.3
- First failed gate: none
- New findings: 0
- Candidate modified: no
- Production ready: no
- Authority effect: none
Assurance at a glance
Fresh independent exact-candidate review disposition.
New open findings in the controlling candidate.3 review.
Supplemental source tests passed; one declared non-Windows ADS skip.
Property assertions passed across 1,000 requests without model or network use.
1. Controlling independent review
The controlling review used the exact candidate.3 source, Python packages, Windows packages, publication files, and sidecars. It closed the prior stale alpha.4 publication-slug defect and found no new candidate defect.
DISPOSITION:
PASS_FOR_HUMAN_EXACT_HASH_OPEN_SOURCE_RESEARCH_PREVIEW_RELEASE
FIRST FAILED GATE:
NONE
PRIOR FINDING ILCE-A5-RT-001:
CLOSED — PASS
NEW OPEN FINDINGS:
0
CANDIDATE MODIFIED:
NO
WHEEL MODIFIED:
NO
PRODUCTION READY:
NO
AUTHORITY EFFECT:
NONE
- Independent-review ZIP
a78a025a66d952cdaff4d390e6631f34bd94dc5c26426a382f287741cec12098- Machine-readable review result
7cba96725a6642394698cdba7d7592c4ae0f242390e1e3e252d072f9105186de- Public-release candidate kit
2bf4afdf5c05dd6f1cce70022b80d55f0a79259648b3cee16c01f27f917decbf
2. Executed independent evidence
Source tests
150 passed, zero failed, and one declared NTFS Alternate Data Streams skip in the supplemental Linux CPython 3.13.5 lane.
Property matrix
1,000 requests and 4,000 assertions passed. No model or network was used.
CLI and SDK
25 of 25 real-file operations passed across command-line and Python interfaces.
Strict JSONL
12 of 12 bounded JSONL bridge cases passed under exact UTF-8/LF framing.
Loopback API
10 of 10 local API cases passed, including non-loopback and authorization boundaries.
Clean installs
Fresh wheel and sdist installations, dependency checks, imports, and doctor commands passed.
Archive limits
100,000 members were accepted; 100,001 members failed closed with
typed MEMBER_COUNT_LIMIT_EXCEEDED, no extraction, and
no staging debris.
Source and Git parity
The public source and clean Git tree matched across 157 of 157 files.
Public boundary
Recursive public-boundary scanning returned zero findings.
Licenses and SBOM
MPL-2.0 metadata, license files, notices, third-party inventory, SPDX 2.3 SBOM, wheel, sdist, portable, and publication surfaces passed parity checks.
Publication replay
Exact publication bytes produced zero horizontal overflow at 1440, 375, and 320 CSS pixels.
Final nonmutation
Every commissioned candidate retained its exact pre-review SHA-256 after review.
Canonical MPL-2.0 byte parity
Every distributed license copy was checked against the authenticated Mozilla plain-text reference recorded for this release:
3f3d9e0024b1921b067d6f7f88deb4a60cbe7a78e76c64e3f1d7fc3b779b9d04
That dated identity does not claim equality with a future Mozilla-hosted copy.
Builder-executed Windows evidence versus independent evidence
The prior exact-preserved Windows builder line executed Windows Python 3.11 and 3.12 test suites, the mandatory attack matrix, portable operation, installer lifecycle, repair, and customer-file-preserving uninstall. Candidate.3 changed only publication and build-validation surfaces; the exact Windows portable and installer bytes remained unchanged.
The final independent candidate.3 reviewer did not have Windows or NTFS execution available. It therefore performed exact identity, archive, payload, installer-to-portable parity, PE32+ x86-64, licensing, and static boundary checks, but did not claim a fresh Windows runtime pass.
3. Exact approved artifact identities
These filenames and digests identify the exact approved artifacts. Five ordinary public user-download artifacts and their sidecars are linked below. The Git bundle, change manifest, and release-status identities remain part of the assurance ledger but are not ordinary download buttons on this page.
Public source ZIP
Logged-out post-upload retrieval and exact SHA-256 verification: PASS.
Python wheel
Exact pre-upload bytes and strict sidecar authenticated; upload and link creation confirmed.
Python sdist
Exact pre-upload bytes and strict sidecar authenticated; upload and link creation confirmed.
Windows x64 portable
Unsigned exact pre-upload bytes and strict sidecar authenticated; upload and link creation confirmed.
Windows installer candidate
Unsigned exact pre-upload bytes and strict sidecar authenticated; upload and link creation confirmed.
Transmission and post-upload evidence boundary
The public source ZIP and source sidecar were downloaded through a
logged-out browser after Squarespace upload. The retrieved ZIP
matched SHA-256
90c6844f4de8a0d27f584a2adfdc4ebf693ae41b629b10f03a61c04f013fb736,
passed ZIP CRC and archive-safety checks, and the retrieved sidecar
bound to the canonical filename and digest.
For the wheel, sdist, Windows portable, and Windows installer, exact pre-upload hashes and strict sidecars were authenticated and Thomas confirmed successful Squarespace upload and link creation. Under UVLM's recorded control judgment, individual post-upload byte retrieval was not repeated for every remaining artifact. No per-file post-upload hash-verification claim is made for those four files.
| Role | Exact filename | SHA-256 |
|---|---|---|
| Public source ZIP | UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Public_Source_Release_Candidate.zip |
90c6844f4de8a0d27f584a2adfdc4ebf693ae41b629b10f03a61c04f013fb736 |
| GitHub repository export | UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_GitHub_Repository_Export.zip |
90c6844f4de8a0d27f584a2adfdc4ebf693ae41b629b10f03a61c04f013fb736 |
| Python wheel | uvlm_integritylock-0.2.0a5-py3-none-any.whl |
3a7f8be73a1dcd826a48e8bf66577a1c61689d314158efafb8d3f8b1e38e0e83 |
| Python sdist | uvlm_integritylock-0.2.0a5.tar.gz |
f5aa54ccdcc1d8e3bcea35d0f7ac21a5dc50affbf9a28d7c448a42a3445d402d |
| Windows x64 portable | UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Windows_x64_Portable.zip |
30e51f83caa6f3c2a35f93c110b70d7262997899232a3a059a1c79b935fb5099 |
| Windows installer candidate | UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Windows_x64_Installer_Candidate.zip |
9c18ed917000aff89937d1378cbfb933b504974348a7c4929381294dcb75e5ee |
| Clean-history Git bundle | UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Source.bundle |
1e188886673be6ffb668ca3b55e59fbd774fb9bb60e6a4fbae6cadb59a23eebd |
| Exact change manifest | UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Exact_Change_Manifest.json |
004ea1169fca527fa8a6f34a0c6ee8300fa0a8a2b639c986488b392f2b9be218 |
| Release status | UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Release_Candidate_Status.json |
f8b6c2300d7d5d2761f93eccbf2e20832d84894ce930962f1799975207d4c5d9 |
4. Verify a downloaded file
Verify before extraction, installation, or execution. Keep the
artifact beside its exact detached .sha256 sidecar and
confirm that the sidecar names the same basename.
Windows PowerShell
$Artifact = '.\UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Windows_x64_Portable.zip'
$Sidecar = "$Artifact.sha256"
$Expected = ((Get-Content -LiteralPath $Sidecar -Raw) -split ' ', 2)[0]
$Observed = (Get-FileHash -LiteralPath $Artifact -Algorithm SHA256).Hash.ToLowerInvariant()
if ($Expected -cne $Observed) {
throw 'SHA-256 mismatch'
}
"PASS $Observed $([IO.Path]::GetFileName($Artifact))"
Linux
sha256sum -c UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Public_Source_Release_Candidate.zip.sha256
macOS
shasum -a 256 UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Public_Source_Release_Candidate.zip
5. Human authorization and external determinations
Technical review did not publish the software. Thomas Prislac separately executed the exact-hash public-release decision and signed the chain-of-title and conditional export-control management records.
- Decision-input record
81255cf915fa02c06b1c19e3ad47bd46853c628d464609bba8d3b3110fc2556b- Signed chain-of-title record
30939b3ccb7dc5e31fccdac739d153af8c3accc61dbecfea72594f16a7954112- Signed export-control record
476c66fbc385ba8459deb5f8166f9e7ea7737167b1b96627a4ea4aadfdbf88eb- Human authorization v1.1.0
5a082e90b5cd0deaebbae521849444ae827711e9151dbb9c8a622bab7b08c0a1- Signed determinations packet
1f4dae02a9193f55484f7ab7b181866a580ce5d020ccf2297b2b3672d5f114b9
Chain of title
Thomas Prislac recorded that he is the sole human contributor to the UVLM-authored portions and authorized distribution of the rights he controls under MPL-2.0. This is a UVLM management determination, not a legal opinion or warranty of noninfringement.
Encryption export-control posture
UVLM recorded a conditional management pass for staged publication under the publicly available source and corresponding object-code route. It is not a BIS classification, CCATS, export license, sanctions determination, or legal opinion.
Conservative source-notification record
A source-code notification identifying the exact source and
corresponding distribution hashes was sent to
crypt@bis.doc.gov and enc@nsa.gov at
3:50 PM Pacific Time on August 21, 2026.
Gmail blocked the source ZIP as a single archive and represented its contents unpackaged. UVLM preserves that sent-email record as process evidence and does not represent the email as agency approval, a classification, or proof that an intact ZIP attachment was retained by either recipient.
The stable public source URL and logged-out retrieval hash will be added after publication.
AUTHORIZED RELEASE CLASS:
PUBLIC OPEN-SOURCE RESEARCH PREVIEW
PUBLIC RELEASE AUTHORIZATION:
APPROVED WITH STAGED EXECUTION CONDITIONS — EXECUTED
PRODUCTION RELEASE:
NOT AUTHORIZED
PUBLIC DISTRIBUTION:
NOTICE SENT
EXACT SOURCE PUBLIC + LOGGED-OUT SHA-256 VERIFIED
WHEEL / SDIST / PORTABLE / INSTALLER UPLOADED WITH SIDECARS
PUBLIC FILE LINKS ACTIVE
AUTHORITY EFFECT:
PUBLICATION OF THE EXACT APPROVED ARTIFACTS ONLY
6. Preserved skips, limitations, and prohibited overclaims
Fresh-review skips
- Windows 11 x64 on NTFS runtime and PowerShell lifecycle: environment unavailable; no fresh reviewer runtime pass claimed.
- Linux CPython 3.11: environment unavailable.
- Linux CPython 3.12: environment unavailable.
- Private RC2 source replay: private source not distributed; only the public/private boundary and public-safe lineage were reviewed.
Known product limitations
- Windows packages are unsigned and may trigger SmartScreen, antivirus, or organizational-policy warnings.
- A bounded endpoint-security observation is not malware-absence certification.
- Cross-host, future-toolchain, universal compatibility, and full accessibility are not claimed.
- Loopback-only operation does not isolate the software from a malicious process already running as the same user.
- Package vaults are not full-disk encryption or backups.
- IntegrityLock is not a truth oracle, identity service, legal chain-of-custody certification, or credibility-scoring system.