Verification path
Software developer
Are the inputs, hashes, algorithms and outcomes machine-readable?
Ask in this order
- Is the file structurally valid?
- Does its exact state match the protected hash?
- Is any signature mathematically valid?
- Is the key trusted and its real-world identity actually verified?
- Is time independently trusted?
- Is the document or key still current?