Exact bytes · executed evidence · visible limitations

Independent review passed · exact public artifacts available · production release not authorized

IntegrityLock Community Edition — Assurance & Verification

This page records what was reviewed, what passed, what was skipped, which exact artifacts were approved, what human determinations were recorded, and what IntegrityLock’s evidence does—and does not—mean. It is an assurance record for an unsigned open-source research preview, not a certification or production-readiness claim.

  • Version 0.2.0-alpha.5
  • Candidate.3
  • First failed gate: none
  • New findings: 0
  • Candidate modified: no
  • Production ready: no
  • Authority effect: none

Assurance at a glance

PASS

Fresh independent exact-candidate review disposition.

0

New open findings in the controlling candidate.3 review.

150

Supplemental source tests passed; one declared non-Windows ADS skip.

4,000

Property assertions passed across 1,000 requests without model or network use.

1. Controlling independent review

The controlling review used the exact candidate.3 source, Python packages, Windows packages, publication files, and sidecars. It closed the prior stale alpha.4 publication-slug defect and found no new candidate defect.

DISPOSITION:
PASS_FOR_HUMAN_EXACT_HASH_OPEN_SOURCE_RESEARCH_PREVIEW_RELEASE

FIRST FAILED GATE:
NONE

PRIOR FINDING ILCE-A5-RT-001:
CLOSED — PASS

NEW OPEN FINDINGS:
0

CANDIDATE MODIFIED:
NO

WHEEL MODIFIED:
NO

PRODUCTION READY:
NO

AUTHORITY EFFECT:
NONE
Independent-review ZIP
a78a025a66d952cdaff4d390e6631f34bd94dc5c26426a382f287741cec12098
Machine-readable review result
7cba96725a6642394698cdba7d7592c4ae0f242390e1e3e252d072f9105186de
Public-release candidate kit
2bf4afdf5c05dd6f1cce70022b80d55f0a79259648b3cee16c01f27f917decbf
Review-lineage warning. An earlier alpha.5 review returned HOLD and remains preserved as historical negative evidence. It is not the controlling candidate.3 review. The controlling PASS review is identified only by the independent-review SHA-256 shown above.

2. Executed independent evidence

Source tests

150 passed, zero failed, and one declared NTFS Alternate Data Streams skip in the supplemental Linux CPython 3.13.5 lane.

Property matrix

1,000 requests and 4,000 assertions passed. No model or network was used.

CLI and SDK

25 of 25 real-file operations passed across command-line and Python interfaces.

Strict JSONL

12 of 12 bounded JSONL bridge cases passed under exact UTF-8/LF framing.

Loopback API

10 of 10 local API cases passed, including non-loopback and authorization boundaries.

Clean installs

Fresh wheel and sdist installations, dependency checks, imports, and doctor commands passed.

Archive limits

100,000 members were accepted; 100,001 members failed closed with typed MEMBER_COUNT_LIMIT_EXCEEDED, no extraction, and no staging debris.

Source and Git parity

The public source and clean Git tree matched across 157 of 157 files.

Public boundary

Recursive public-boundary scanning returned zero findings.

Licenses and SBOM

MPL-2.0 metadata, license files, notices, third-party inventory, SPDX 2.3 SBOM, wheel, sdist, portable, and publication surfaces passed parity checks.

Publication replay

Exact publication bytes produced zero horizontal overflow at 1440, 375, and 320 CSS pixels.

Final nonmutation

Every commissioned candidate retained its exact pre-review SHA-256 after review.

Canonical MPL-2.0 byte parity

Every distributed license copy was checked against the authenticated Mozilla plain-text reference recorded for this release:

3f3d9e0024b1921b067d6f7f88deb4a60cbe7a78e76c64e3f1d7fc3b779b9d04

That dated identity does not claim equality with a future Mozilla-hosted copy.

Builder-executed Windows evidence versus independent evidence

The prior exact-preserved Windows builder line executed Windows Python 3.11 and 3.12 test suites, the mandatory attack matrix, portable operation, installer lifecycle, repair, and customer-file-preserving uninstall. Candidate.3 changed only publication and build-validation surfaces; the exact Windows portable and installer bytes remained unchanged.

The final independent candidate.3 reviewer did not have Windows or NTFS execution available. It therefore performed exact identity, archive, payload, installer-to-portable parity, PE32+ x86-64, licensing, and static boundary checks, but did not claim a fresh Windows runtime pass.

3. Exact approved artifact identities

These filenames and digests identify the exact approved artifacts. Five ordinary public user-download artifacts and their sidecars are linked below. The Git bundle, change manifest, and release-status identities remain part of the assurance ledger but are not ordinary download buttons on this page.

Transmission and post-upload evidence boundary

The public source ZIP and source sidecar were downloaded through a logged-out browser after Squarespace upload. The retrieved ZIP matched SHA-256 90c6844f4de8a0d27f584a2adfdc4ebf693ae41b629b10f03a61c04f013fb736, passed ZIP CRC and archive-safety checks, and the retrieved sidecar bound to the canonical filename and digest.

For the wheel, sdist, Windows portable, and Windows installer, exact pre-upload hashes and strict sidecars were authenticated and Thomas confirmed successful Squarespace upload and link creation. Under UVLM's recorded control judgment, individual post-upload byte retrieval was not repeated for every remaining artifact. No per-file post-upload hash-verification claim is made for those four files.

Role Exact filename SHA-256
Public source ZIP UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Public_Source_Release_Candidate.zip 90c6844f4de8a0d27f584a2adfdc4ebf693ae41b629b10f03a61c04f013fb736
GitHub repository export UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_GitHub_Repository_Export.zip 90c6844f4de8a0d27f584a2adfdc4ebf693ae41b629b10f03a61c04f013fb736
Python wheel uvlm_integritylock-0.2.0a5-py3-none-any.whl 3a7f8be73a1dcd826a48e8bf66577a1c61689d314158efafb8d3f8b1e38e0e83
Python sdist uvlm_integritylock-0.2.0a5.tar.gz f5aa54ccdcc1d8e3bcea35d0f7ac21a5dc50affbf9a28d7c448a42a3445d402d
Windows x64 portable UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Windows_x64_Portable.zip 30e51f83caa6f3c2a35f93c110b70d7262997899232a3a059a1c79b935fb5099
Windows installer candidate UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Windows_x64_Installer_Candidate.zip 9c18ed917000aff89937d1378cbfb933b504974348a7c4929381294dcb75e5ee
Clean-history Git bundle UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Source.bundle 1e188886673be6ffb668ca3b55e59fbd774fb9bb60e6a4fbae6cadb59a23eebd
Exact change manifest UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Exact_Change_Manifest.json 004ea1169fca527fa8a6f34a0c6ee8300fa0a8a2b639c986488b392f2b9be218
Release status UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Release_Candidate_Status.json f8b6c2300d7d5d2761f93eccbf2e20832d84894ce930962f1799975207d4c5d9
No renaming or recompression. Publication authorization applies to these exact filenames and bytes. Rebuilding, editing, re-zipping, or otherwise mutating an approved artifact creates a different candidate and invalidates this assurance record for that changed file.

4. Verify a downloaded file

Verify before extraction, installation, or execution. Keep the artifact beside its exact detached .sha256 sidecar and confirm that the sidecar names the same basename.

Windows PowerShell

$Artifact = '.\UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Windows_x64_Portable.zip'
$Sidecar = "$Artifact.sha256"

$Expected = ((Get-Content -LiteralPath $Sidecar -Raw) -split '  ', 2)[0]
$Observed = (Get-FileHash -LiteralPath $Artifact -Algorithm SHA256).Hash.ToLowerInvariant()

if ($Expected -cne $Observed) {
  throw 'SHA-256 mismatch'
}

"PASS $Observed  $([IO.Path]::GetFileName($Artifact))"

Linux

sha256sum -c UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Public_Source_Release_Candidate.zip.sha256

macOS

shasum -a 256 UVLM_IntegrityLock_Community_Edition_v0.2.0-alpha.5_Public_Source_Release_Candidate.zip
Hashes are not truth. A matching SHA-256 proves only that observed bytes match the declared digest under the stated procedure. It does not prove truth, safety, authorship, consent, legality, malware absence, certification, or release authority. A signature ties bytes to a key; it does not prove key-holder identity or authority.

5. Human authorization and external determinations

Technical review did not publish the software. Thomas Prislac separately executed the exact-hash public-release decision and signed the chain-of-title and conditional export-control management records.

Decision-input record
81255cf915fa02c06b1c19e3ad47bd46853c628d464609bba8d3b3110fc2556b
Signed chain-of-title record
30939b3ccb7dc5e31fccdac739d153af8c3accc61dbecfea72594f16a7954112
Signed export-control record
476c66fbc385ba8459deb5f8166f9e7ea7737167b1b96627a4ea4aadfdbf88eb
Human authorization v1.1.0
5a082e90b5cd0deaebbae521849444ae827711e9151dbb9c8a622bab7b08c0a1
Signed determinations packet
1f4dae02a9193f55484f7ab7b181866a580ce5d020ccf2297b2b3672d5f114b9

Chain of title

Thomas Prislac recorded that he is the sole human contributor to the UVLM-authored portions and authorized distribution of the rights he controls under MPL-2.0. This is a UVLM management determination, not a legal opinion or warranty of noninfringement.

Encryption export-control posture

UVLM recorded a conditional management pass for staged publication under the publicly available source and corresponding object-code route. It is not a BIS classification, CCATS, export license, sanctions determination, or legal opinion.

Conservative source-notification record

A source-code notification identifying the exact source and corresponding distribution hashes was sent to crypt@bis.doc.gov and enc@nsa.gov at 3:50 PM Pacific Time on August 21, 2026.

Gmail blocked the source ZIP as a single archive and represented its contents unpackaged. UVLM preserves that sent-email record as process evidence and does not represent the email as agency approval, a classification, or proof that an intact ZIP attachment was retained by either recipient.

The stable public source URL and logged-out retrieval hash will be added after publication.

AUTHORIZED RELEASE CLASS:
PUBLIC OPEN-SOURCE RESEARCH PREVIEW

PUBLIC RELEASE AUTHORIZATION:
APPROVED WITH STAGED EXECUTION CONDITIONS — EXECUTED

PRODUCTION RELEASE:
NOT AUTHORIZED

PUBLIC DISTRIBUTION:
NOTICE SENT
EXACT SOURCE PUBLIC + LOGGED-OUT SHA-256 VERIFIED
WHEEL / SDIST / PORTABLE / INSTALLER UPLOADED WITH SIDECARS
PUBLIC FILE LINKS ACTIVE

AUTHORITY EFFECT:
PUBLICATION OF THE EXACT APPROVED ARTIFACTS ONLY

6. Preserved skips, limitations, and prohibited overclaims

Fresh-review skips

  • Windows 11 x64 on NTFS runtime and PowerShell lifecycle: environment unavailable; no fresh reviewer runtime pass claimed.
  • Linux CPython 3.11: environment unavailable.
  • Linux CPython 3.12: environment unavailable.
  • Private RC2 source replay: private source not distributed; only the public/private boundary and public-safe lineage were reviewed.

Known product limitations

  • Windows packages are unsigned and may trigger SmartScreen, antivirus, or organizational-policy warnings.
  • A bounded endpoint-security observation is not malware-absence certification.
  • Cross-host, future-toolchain, universal compatibility, and full accessibility are not claimed.
  • Loopback-only operation does not isolate the software from a malicious process already running as the same user.
  • Package vaults are not full-disk encryption or backups.
  • IntegrityLock is not a truth oracle, identity service, legal chain-of-custody certification, or credibility-scoring system.
Never claim: certified, FIPS validated, production ready, malware free, unhackable, universally reproducible, externally penetration tested, legally cleared for every use, or proof of truth, authorship, consent, safety, identity, or authority.