Verify evidence package

This page shows the status, manifest hash, and export timestamp PflichtPilot has on file for the supplied verify code. If you also have the evidence-package ZIP, you can upload the manifest.json from inside it — the page then computes SHA-256 locally in the browser and verifies whether the hash matches the server value exactly. No package contents are shown.

What exactly is confirmed

Newer evidence packages: the content of the proof files is sealed in. Older evidence packages: only the metadata structure (chain, status, counts) is sealed.

In detail: the verify code confirms that PflichtPilot issued a manifest with exactly this hash at the time shown. For exports from manifest schema 2 onwards, the manifest additionally embeds SHA-256 hashes computed server-side from the stored proof files — the manifest hash then also binds the proof-file contents. For older exports (schema 1), the hash covers the manifest metadata only, not the proof-file bytes. In both cases, the proof files themselves are checked against the per-file hashes in the ZIP's overview.json.

Verification in progress…

Note: verification is active only while the issuing PflichtPilot subscription is active. If the subscription ends, the verify link becomes inactive — the original PDF evidence package itself stays with its owner and is unaffected.