Verify a report

Drop in the .dvnr bundle you were sent. Your browser checks the signature and every file hash against the published key — nothing is uploaded, nothing leaves this page.

Choose or drop the .dvnr file

The signed bundle that shipped with your report — the file ending in .dvnr.

or drag it here

What this checks

The Ed25519 signature over the bundle's manifest, that the manifest's key matches the published issuer key, and that every file's SHA-256 hash matches what was signed. Any of these failing means the bundle is not authentic, has been altered, or was not signed by AquaVein.

Runs entirely in your browser. The file is read locally with JavaScript; it is never transmitted anywhere, including to AquaVein. You can disconnect from the internet after this page loads (aside from the one-time script load below) and verification will still work.

The issuer key, published

Key IDStatusValue
TESTREFERENCEEvery specimen and sample on this site is signed with a published TEST key. Its public key is embedded in this page. Production reports carry a separate ceremony-issued key, published here the day it goes live.

Prefer the command line?

The reference verifier is open: dvnr_tool.py verify --pub aquavein_issuer.pem BUNDLE.dvnr. Every bundle also ships its own raw source data, so a report can be checked, re-derived, or handed to a third party years from now without AquaVein's involvement.

Order a report What's in a report