AUTH AUDIT / MERKLE
Runtime, ledger configuration, and cryptographic integrity are reported separately. A missing ledger is unavailable—not a pass or failure. Only confirmed successful events are eligible for append.
Runtime probe
Checking
Ledger configuration
Checking
Integrity verification
Not completed
Merkle root
Unavailable
Audit leaves
Unavailable
Tree depth
Unavailable
Evidence timing
Sync window: 30 seconds. No completed verification yet.
Credentials sign in
Submitted to NextAuth with its server-issued CSRF token. Passwords never enter the audit ledger.
Register
Production registration fails closed if the authoritative identity service is unavailable.
Session
Checking session…
Protected audit events
Requires an authenticated auditor or superadmin capability.
| Sequence | Type | Leaf | Time |
|---|---|---|---|
| Loading… | |||
Inclusion proof
Select an event, retrieve its authoritative SHA-256 proof, then verify it server-side.
No leaf selected.
No proof requested.