Drop in a SkyQon evidence bundle (.zip) or a signed report (.pdf) and prove it is intact — file integrity, evidence content hash and issuer signature — right here in your browser. No signup. Nothing is uploaded to storage or kept.
Drop an evidence bundle or signed PDF here
or
🔒 Verification runs against the file you upload only — no database lookup, no tenant data, nothing stored.
File integrity — every file in the bundle is re-hashed and matched against the manifest, so nothing was swapped or truncated.
Evidence content hash (the important one) — the evidence payload is re-hashed with the exact canonical rule SkyQon used and matched to the recorded SHA-256. A match proves the numbers are byte-for-byte what SkyQon observed and recorded.
Issuer signature — the embedded PAdES signature is what establishes origin, and a bundle only verifies if it carries one that chains to a SkyQon issuing CA. The two hash checks above are computed against the bundle's own manifest, so on their own they show only that the archive is internally consistent, not that it came from us. A bundle that is unsigned, or signed by a self-signed or otherwise untrusted certificate, is reported as not verified with the reason given.
SkyQon evidence is a technical record, not a certification or legal advice. See the scoring methodology and the auditor verification guide for how to use it in a NIS2 / DORA file.