- IF.TTT is a receipt‑first governance layer. It binds a source artifact to an output with a
- trace page, stable no‑login links, and optional offline bundles anyone can verify.
-
- We don’t claim “compliance”. We support audits by producing verifiable receipts that third parties can check without your
- credentials.
+ If it’s not verifiable, label it as a gap. Don’t endorse it.
+ This is how you keep governance legible to outsiders.
- HTML views exist for sandboxes that load text/html but reject downloads:
- /static/pack/<shareId>, /static/review/<shareId>, /static/marketing/<shareId>.
-
-
-
-
- Note: some constrained “web fetchers” reject downloadable binaries (e.g., .tar.gz) while still loading HTML. That’s why
- HTML views exist for packs and indexes.
-
- VERIFIED means the hashes match what the receipt declares. QUANTUM READY may be shown when a
- post‑quantum signature receipt exists (PQ verification is additive; hash verification still stands).
-
-
-
-
-
-
-
-
-
Vertical Fit (what each buyer is actually looking for)
-
Same mechanism, different third‑party pressure.
-
-
-
-
-
-
-
B2B SaaS (SOC 2 / ISO)
-
Third party
-
Auditors + enterprise procurement
-
They want
-
Evidence that controls existed at the right time, in the right scope, with receipts.
-
IF.TTT helps by
-
Publishing no‑login receipts and offline bundles for disputes and audits.
- “VERIFIED” means the hashes on the trace page match the output/source that can be downloaded and hashed independently. It is an
- integrity receipt: the bytes match what the trace declares.
-
-
-
-
- What is “QUANTUM READY”?
-
- “QUANTUM READY” is shown when a post‑quantum signature receipt exists for the trace. It means PQ receipts are present now (for future
- audit requirements). PQ verification is additive; the hash receipt remains valid either way.
-
-
-
-
- Do you guarantee compliance?
-
- No. IF.TTT produces verifiable artifacts that can support audits and disputes. Compliance is a broader program: scope, policy, human
- review, and governance decisions are still required.
-
-
-
-
- What’s the difference between shareId and trace_id?
-
- shareId is the public handle used in URLs. trace_id is the chain‑of‑custody UUID recorded in receipts and
- bundles.
-