Isolated hosted build
A pinned reusable workflow runs the build and signing steps in separate, fresh GitHub-hosted jobs. Application code has no signing permission.
Inspect the Numina 4 application inventory, discover its detached build statements, and review the separate rc26 runtime evidence.
Numina 4.0.0 brings the website, operations workspace and installable mobile web app together. Your service workflows and private Treasury records remain available in the same design.
Loading deployed release…
Loading…This build identity is calculated from the packaged application files. Detached build provenance is checked separately using the exact inventory fingerprint below. The rc26 control-plane dependency retains its own identity and signed records.
A detached signed statement can identify the builder and the exact release file. The statement stays separate so the original file remains unchanged.
Signature verification has not been performed.
Loading…No manifest response is currently loaded.
The lookup opens GitHub’s public records for this fingerprint. A listed statement is evidence to verify; its presence alone does not establish a valid signature, SLSA level or deployment match. An empty or unavailable lookup does not verify the release.
Save the exact manifest above as application-release-v4.json. Use GitHub CLI to check its digest, the designated repository and the pinned builder identity.
Load the current manifest to prepare verification.
Review the verified source revision and workflow run against the intended release. A signature check does not by itself prove that these bytes were deployed or that all SLSA Build L3 controls are established.
Loading verified build record…
The source archive, Linux image archive and inventory have their own dated build evidence.
The recorded build produced a Linux image. Production hosting and financial execution are not established by that build. Current application capabilities are reported separately below.
UnavailableUnavailableUnavailableGitHub CLI verified these artifact signatures against the pinned builder and source revisions. This page checks the retained review and inventory fingerprints; it does not repeat Sigstore signature verification in the browser. The contract was a precompiled input. This record does not establish a security audit, reserves, custody, settlement or a new SLSA level.
Rechecked 14 September 2026: all three historical artifacts passed separate GitHub CLI verification commands with exit code 0. Inspect the dated results and signed statements ↗ · Original completion record ↗. The command records are unsigned observations; the original artifact signatures retain their build-only scope.
Current application status unknown
UnknownThese fields come from the current public application status response. Enabled capabilities describe application configuration; transaction receipts and reserve evidence are separate. The canonical Numina treasury and private provider observations remain in their authenticated views.
Consulting services use the existing USD Stripe checkout after an authenticated request is saved. Review service scope and pricing ↗
The Numina 4 application uses control-plane runtime v1.9.0-rc26. Its signed declaration and control-state receipts can be checked against the public key pinned in this website.
A runtime signature authenticates the service’s declaration. It does not independently establish a build-platform security level or verify the bytes of the referenced SBOM and provenance artifacts.
The historical Numina 2.0.0 deployment archive and application inventory from GitHub Actions run 34717406980 · GitHub access required ↗ meet SLSA v1.2 Build Level 3 under our documented self-assessment, with verified builder-signed provenance.
4a7210c10fcfa79436018e8ba337244402661036https://slsa.dev/provenance/v1A pinned reusable workflow runs the build and signing steps in separate, fresh GitHub-hosted jobs. Application code has no signing permission.
The release check verified the signature, expected builder and source revisions, workflow run, and both artifact fingerprints.
The assessed inventory fingerprint is 30434a312366a8869b93e9f27b428ee0e5f385c1bd0e8fc877912a98fe97f792. These downloads preserve that completed build; the current release inventory above may identify a later build. Each later artifact requires its own signature and identity verification.
This is a build-artifact assessment, not third-party certification. It trusts GitHub’s hosted platform, Sigstore and the pinned builder. It does not assess subsequent hosting transformations, the separate rc26 runtime build, financial execution, reserve backing or native-store publication. The official slsa.dev predicate is also used for production.
SLSA requirements · Assessment guidance · GitHub build and attestation guidance.
The earlier rc20 records remain available as historical artifacts. They do not establish the rc26 build’s provenance.