A record you can add to, and nothing else.
Write entries into a channel. Each one is hashed together with the hash of the entry before it, so the log has an order that is part of the data rather than a promise about it. Then alter an entry, or delete one, and press verify — it will tell you exactly where the chain stopped holding.
What it demonstrates
Two platform features, and the point is that neither is enough by itself.
storageAdd appends a version instead of replacing a value,
so the channel keeps every note that was ever written — that gives you a log.
attest sends the hash of each note to the platform, which
assigns the order, stamps its own clock, welds each record to the one before it and
signs the result — that is what turns a log into a record. The platform never sees the
note itself, only its hash.
Storage without the chain lets somebody hand you a shorter list and call it the whole thing. The chain without storage proves an order but not what was in it. Together they mean an entry can be added, and nothing else can happen to one.
Verification asks both questions, and you can watch each fail.
AgentConnection.attestVerify re-derives every hash and checks every
signature against the published key — without asking the platform whether the
platform is honest. Then each stored note is re-hashed and compared to the
receipt written for it, which is what catches somebody editing the text afterwards.
Break it yourself
Every entry on the page has Alter and Remove next to it. Both edit this tab's copy of the log — storage is append-only, so there is nothing there to rewrite, and that is the realistic threat anyway: somebody hands you a log and says it is the record. Verification is what tells you it is not.
A verifier nobody has watched fail is a verifier nobody should trust, which is why those two buttons are on the page rather than in a test.
Why sorted keys matter
Stamps are serialised with their keys sorted, so the same entry produces the same string —
and therefore the same hash — on any browser, next year. Re-derivation only works because
of that. Serialise with JSON.stringify straight off an object and two browsers
that happened to build it in a different order will disagree about a log neither of them
has touched.
This is the primitive, not a product
There is no camera here, no capture templates, no exportable report and no operator
manual. Those belong to an inspection product built on exactly the four functions this
page ships — sha256Text, canonical, chainNext and
verifyChain — which are on window.EvidenceChainCore so you can
paste them into a console and satisfy yourself before building anything on them.