The auditor's walk

A regulator receives an evidence bundle and has no reason to trust AINumbers. The walk checks it from the top of the wall to the bottom, using only the bundle and verifier code running in this page. The evidence is real: the Agent Staircase session of 26 September 2026 with its three timestamps, the signed Work Mandate from that session, and the Groth16 receipt of node art-07.

Goal of this animation

Show what a regulator learns at each layer of the wall, and what each layer cannot tell them, by checking one real evidence bundle with open verifier code.

🔒 No personal dataThe Work Mandate is synthetic and the art-07 run uses fixture inputs. Apart from loading its fonts and its own files, the page makes no network requests, and the counter on the wall shows what started while the checks ran. The browser's request log cannot see WebSocket traffic, so the stronger guarantee is the page's security policy, which blocks fetch, XHR and WebSocket connections outright (connect-src 'none').
☁ Our server is Cloudflare“AINumbers server” means Cloudflare today: the site's files are delivered through Cloudflare's network. The walk never asks it anything. You do trust this page for the verifier code and the pinned roots, and limit 4 below says how to check without it.
What the red, amber and green results mean
● green · the check passed● amber · the check could not run here● red · a mismatch was caught
✓ CHECK PASSEDThat layer verified. The stop card says what the auditor now knows.
✗ CHECK FAILEDA corrupted bundle fails at the layer built to notice that change, and often at more than one. Editing a signed mandate breaks its signature and its hash together.
? COULD NOT RUNThe check had something it could not finish here, such as a certificate chain that is not pinned in this page. It never counts as a pass, and the memo records it.
WHAT A PASS CANNOT TELLEach stop also lists what a pass does not prove, such as who authored a result or whether the computation itself was correct.
The auditor receives a bundle
– requests while checkingpage load: counting…
✗check failed✓check passed?could not run
drag to rotate · the auditor moves down the wall

Corrupt the bundle, then walk it

To see every kind of tampering and which layer catches each one, try Break the wall.


Not shown because they are long: the 256-byte Groth16 seal, the 6,528-byte kernel source and the three RFC 3161 tokens. All of them are checked.

Limits of this page

1. The bundle joins two pieces of real evidence. The session, its timestamps and the Work Mandate come from the Agent Staircase run of 26 September 2026. The Groth16 receipt and kernel belong to node art-07, whose run is not one of the ten session leaves. They sit together so that every layer has something real to check.

2. The Work Mandate is synthetic. Its signature is real and was made with the key the mandate names as its principal, so stop 5 shows that this key signed these bytes. It says nothing about who holds the key.

3. Two of the three timestamps chain to roots pinned in this page, DigiCert and FreeTSA. The Sigstore token's imprint and signature check, but its root is not pinned here, so its chain shows as not checked. The timestamp verifier in this page checks one certificate hop and does not look up revocation, so a full audit would also use the Anchor Suite verifier.

4. This page supplies both the verifier code and the pinned roots. An auditor who trusts nothing here can rerun the same checks with the open verifiers in the public repository, or check each timestamp with openssl ts -verify, because the tokens are stored byte for byte.

Evidence and verifier code from github.com/PostOakLabs/ainumbers · runs in your browser · Zero PII · CC BY 4.0 · Post Oak Labs