Verify a Walk‑Check record yourself
Every sealed walkaround carries its own proof. You do not need an account, our servers, or our word for it. This page gives you the tool and the key.
How it works
Each record is a hash chain: every entry links to the previous one and is signed with an ECDSA P-256 key held in AWS KMS, and the seal that closes the walkaround carries a timestamp from an RFC 3161 authority. The verifier below re-derives the whole chain from genesis and checks all three. It does not import our application code and it does not call our servers: it reads the public key once from a file and computes the rest locally. That is the point. If you do not trust us, you do not have to.
Steps
-
Get the protocol
Open the share link you were given and download the PDF, or use the PDF you received by e-mail.
-
Extract the proof
The machine-readable evidence is attached inside the PDF.
pdfdetachis part of Poppler (the packagepoppler-utilsorpoppler). Take out onlywalkcheck-proof.json, never all attachments: a file planted in the PDF next to the tool could take its place.shellpdfdetach -savefile walkcheck-proof.json report.pdf -
Get the tool
Download the five
.pyfiles, the keywalkcheck-audit-public-key.derand the anchortsa-trust-freetsa.pemfrom the list below into one folder:verify_chain.pyneeds the other four next to it. You need Python 3.12 or newer and three libraries. Install them into an environment of their own, because many systems refusepip installoutside one.shellpython3 -m venv venv . venv/bin/activate python3 -m pip install \ "cryptography>=43" "pydantic>=2.9" "structlog>=24.4" -
Run the verifier
Run it with the key and the anchor from this page, never with a key that came together with the PDF.
shellpython3 verify_chain.py \ --export walkcheck-proof.json \ --public-key walkcheck-audit-public-key.der \ --tsa-trust tsa-trust-freetsa.pem -
Read the verdict
- VERIFIED
- chain intact, signatures and timestamp valid
- TAMPERED
- the record does not match what was sealed (with the key and the anchor from this page, that means a change after sealing); the line names the entry and the reason
- PENDING
- sealed, but the storage attestation does not cover it yet
- UNSEALED
- the walkaround was never sealed, so it is not evidence yet
- UNVERIFIED_DEV
- you ran it with
--allow-unsigned, so signatures were not required. Not proof.
The exit code follows the verdict:
1for TAMPERED, and also for an export that can be read but is malformed;0for the others;2when the command is wrong or a file cannot be read, and nothing was checked. A run over a real record prints exactly this on standard output (log lines go to standard error):STORAGE: pilot mode, the record is NOT under an irreversible lock; it is kept for at least four years, then in a deep archive, and only Walk-Check can delete it, as an exception (this does not weaken the chain) VERIFIED (sealed=True, records=10), NOT CHECKED: global anchor (--require-anchor), WORM attestation (--require-attestation) SEALED HEAD (record_hash): b321eb4bf2b55b0a57eefaf01f059463f728cb6c1746dd48b8e0b677f0f07e34, WALKAROUND ID: 4b3bcb62-2ea9-4c05-ab88-164e80e3de32 LOCATION (reported by device): none in chain (record predates device location)STORAGE:appears only for a record stored in pilot mode, described at the bottom of this page. It does not weaken the chain.- Behind the verdict the tool names what it did not check in that run. That tail is the scope, not a failure: the global anchor and the storage attestation need data that the PDF does not carry.
- The sealed head and the walkaround ID must match the PDF (fields SEALED HEAD and WALKAROUND ID). If they do not, do not rely on the document. The tool checks the attachment, not the printed pages: where the PDF and the attachment differ, the attachment is what was sealed.
LOCATIONis the position the phone reported, if any. It is not a measurement of where anyone stood.
Depending on the version of the
cryptographylibrary you may also see one warning about PKCS#7 certificates parsed as BER. It does not affect the verdict: the timestamp token of the pilot authority is BER encoded, which CMS allows, and this tool checks its signature over the exact bytes with its own decoder.
Files
Tool
Keys
The same thing written out, with every switch, the data it needs and what this does not prove: README.md, or README.sk.md in Slovak.
Two things we say out loud. The timestamp authority in the pilot is freetsa.org, which is a real RFC 3161 authority but not an eIDAS qualified one. And storage currently runs in pilot mode, without an irreversible lock: before the seal the user can delete a record, after the seal it is only hidden and archived, and only Walk‑Check can delete it permanently, as an exception. The sealed content never changes, and the verifier prints the storage mode itself rather than hiding it. Neither weakens the chain: if a record exists, you can prove it was not changed.