WilWell Technologies CivicAttest™

Confirm that a CivicAttest report has not been altered.

Every audit report we issue carries a SHA-256 hash, which is a short string of characters calculated from the exact bytes of the finished document. This page publishes those hashes so that anyone holding a copy can check the copy against the version we actually issued.

An audit that nobody can check is only an assertion. A city that publishes one of our reports should be able to point the public at something better than our word, and so should any resident who wants to confirm the copy in their hands. That is the entire purpose of this page.

What the hash proves, and what it cannot do

A hash is a one way calculation. Changing a single character anywhere in a report produces an entirely different hash, so any alteration to the document becomes visible the moment the two strings are compared. Adding a page, deleting a finding, or editing a single date will all fail the comparison.

The calculation cannot be run backward. Nobody can take a hash from this page and reconstruct the report it came from, because the hash carries none of the original content with it. These strings are fingerprints rather than copies.

Nothing on this page identifies any client. There are no city names, no department names, no findings, no counts, and no line of log data on this page or inside the hashes themselves. Each registry entry records only that a document exists and what its fingerprint is.

Published report registry

Both rows shown here are placeholders, and their hash values will be replaced with issued values as reports are published.
Audit registry number Date issued Engine version SHA-256 hash
CA-2026-0001 2026-08-14 r4.0 9f2b7c41e8d05a63bb147e9c0a8d3f26514c7b9083e6a1df425c08b7e3916a4d
CA-2026-0002 2026-09-02 r4.0 4c81de6039a7b2f5188c0e34ad9761b8e520f7c3a64d91e07b385caf2d106e94

How to verify your own copy

Before you trust anything printed here, confirm that your address bar reads civicattest.com exactly. A page that copies this layout on some other domain proves nothing at all, and checking the domain first costs you only a moment.

Then compute the hash of the file you were given, using whichever line below matches your computer.

On Windows, open Command Prompt and run this line:

certutil -hashfile "C:\path\to\report.pdf" SHA256

On macOS, open Terminal and run this line:

shasum -a 256 /path/to/report.pdf

On Linux, open a terminal and run this line:

sha256sum /path/to/report.pdf

Compare the result against the row carrying your audit registry number. If the two strings match in every position, your copy is byte for byte the document we issued. If they differ anywhere at all, treat the copy as unverified and ask us for a fresh one before you rely on it.

A failed comparison does not by itself mean that anyone acted improperly. A file can change through an ordinary re-save, a printing step, or an email system that rewrites attachments. The comparison tells you only that the copy in front of you is no longer the document we issued, which is exactly the question worth asking.

CivicAttest™ · an independent audit by WilWell Technologies civicattest.com