Auditor verifier
Verify a QNSP conformance evidence pack.
Verification is local to this site: the bundle is parsed, the embedded ML-DSA-44 (FIPS 204) signature is checked against the embedded public key, and the public key's SHA-256 fingerprint is cross-checked against the QNSP signer registry below. The signature binds the bundle through the domain separator qnsp:conformance-evidence-pack:v1 so it cannot be replayed as a CBOM attestation.
Separate trust root
Published QNSP signer keys.
The bundle's proof.publicKey SHA-256 must match one of these published fingerprints. This file is committed to cuilabs/qnsp-public; its git history is the audit record of every rotation.
| keyId | algorithm | SHA-256 | status |
|---|---|---|---|
| qnsp-cbom-attestation-2026-05-11-v1 | ml-dsa-44 | 60fbd49d53e9e98d5bc183ddc6d6a028b45ce7a7d5d9c1e550026d54f557046c | active |
Step 1
Provide your evidence pack.
Upload a .json file downloaded from a QNSP customer's cloud portal, or paste the JSON contents directly.
or paste below
Step 2