Trust, transparency and compliance
How to verify that Seal's sealed packages actually do what Seal says they do.
Last updated
How to verify that Seal's sealed packages actually do what Seal says they do.
Every artifact Seal ships is accompanied by mechanisms that let you, your auditors, and your customers verify what was changed, who built it, and whether it has been tampered with. This section is the canonical home for those mechanisms — what the artifacts are, how to read them, and what compliance frameworks they support.
Why this matters: the trust model — what you can verify and why.
Code diff: the source-level diff between a sealed version and its origin.
Attestations: per-package PDF attestations and machine-readable VEX records.
Patch validation prompt: an LLM-driven scope check for sealed patches.
Cryptographic signing and hash verification: ECDSA signing and SHA-512 hashes.
SLAs and compliance frameworks: the 72-hour SLA, Seal's own certifications, and the frameworks Seal helps you meet.
Last updated