hefter-certificate/1 · DEMO
- Recorded route
- Classification
- Fingerprint
Follow the document, not a promise
A processing record shows what Hefter logged: which step ran, which model was called and which destination received the content. Choose a route to compare the examples.
Synthetic examples · no document uploaded · no provider calledQC is the app’s completed-workflow marker. The local profile uses a mint double circle; the EU profile a rounded square; reviewed external processing an ochre octagon; unreviewed processing a dashed diamond; routing stacked frames with connected nodes. Shape, icon and wording distinguish the profiles without relying on colour. These are processing profiles, not different legal signature types.
Download this example ↗Technical format: canonical JSON, SHA-256 fingerprint and Ed25519 signature. The exported public key verifies the record’s integrity; compare it with the known instance key to establish provenance. No private signing key is included.
The current export records the endpoint and profile trust classification. For a router, that is not proof of the downstream provider, storage country or retention policy. EU classification comes from configuration; it is not automatic verification of EU-only processing. Job states and model-call audit records are separate; the signature does not prove OCR accuracy or that every downstream event was observed.
Hefter currently signs its processing record with the instance’s key. It does not identify a human signatory or provide an advanced (AES) or qualified (QES) electronic signature. Under eIDAS, QES has the legal effect of a handwritten signature. A future document-signing integration would be a separate feature, using an appropriate trust service.
Signature types under eIDAS · European Commission ↗