Append-only · SHA-384
Integrity
Every create, update, analysis, export and delete is appended to a per-spec chain where seal = SHA-384(prevSeal ‖ canonicalJson(event)). Replaying recomputes each seal and reports the first link that does not match.
recomputing seals…
How the seal is computed
canonicalJson(value): - object keys sorted recursively - arrays preserved in order - undefined dropped, non-finite numbers -> null seal_n = SHA-384( UTF-8(prevSeal) || canonicalJson(event_n) ) prevSeal_0 = "000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000" // genesis
Because the serialization is canonical, the same event always produces the same bytes, so a seal computed in a browser test is identical to one computed on the server. Deleting a spec writes a tombstone rather than removing the row, which is what keeps the chain replayable.