External Audit

Core51 is built to support independent verification. This section describes what can be audited today and what is planned.

What you can verify offline

Evidence exports

wire-export.zip

Exports contain a signed/message-integrity oriented wire format. They can be validated with an offline verifier, without trusting the server.

Verifier (source)

Download from Downloads and run offline. (Signature/hash-chain verification is being expanded.)

Planned

Third-party audit workflows

Key continuity reports

Audit-friendly reporting for key changes, pinning, and rotation events.

Process & controls

Operational controls documentation: incident response, record retention, and access control posture.