Every audit report we issue carries a SHA-256 hash, which is a short string of characters calculated from the exact bytes of the finished document. This page publishes those hashes so that anyone holding a copy can check the copy against the version we actually issued.
An audit that nobody can check is only an assertion. A city that publishes one of our reports should be able to point the public at something better than our word, and so should any resident who wants to confirm the copy in their hands. That is the entire purpose of this page.
A hash is a one way calculation. Changing a single character anywhere in a report produces an entirely different hash, so any alteration to the document becomes visible the moment the two strings are compared. Adding a page, deleting a finding, or editing a single date will all fail the comparison.
The calculation cannot be run backward. Nobody can take a hash from this page and reconstruct the report it came from, because the hash carries none of the original content with it. These strings are fingerprints rather than copies.
Nothing on this page identifies any client. There are no city names, no department names, no findings, no counts, and no line of log data on this page or inside the hashes themselves. Each registry entry records only that a document exists and what its fingerprint is.
| Audit registry number | Date issued | Engine version | SHA-256 hash |
|---|---|---|---|
| CA-2026-0001 | 2026-08-14 | r4.0 | 9f2b7c41e8d05a63bb147e9c0a8d3f26514c7b9083e6a1df425c08b7e3916a4d |
| CA-2026-0002 | 2026-09-02 | r4.0 | 4c81de6039a7b2f5188c0e34ad9761b8e520f7c3a64d91e07b385caf2d106e94 |
Before you trust anything printed here, confirm that your address bar reads civicattest.com exactly. A page that copies this layout on some other domain proves nothing at all, and checking the domain first costs you only a moment.
Then compute the hash of the file you were given, using whichever line below matches your computer.
On Windows, open Command Prompt and run this line:
On macOS, open Terminal and run this line:
On Linux, open a terminal and run this line:
Compare the result against the row carrying your audit registry number. If the two strings match in every position, your copy is byte for byte the document we issued. If they differ anywhere at all, treat the copy as unverified and ask us for a fresh one before you rely on it.
A failed comparison does not by itself mean that anyone acted improperly. A file can change through an ordinary re-save, a printing step, or an email system that rewrites attachments. The comparison tells you only that the copy in front of you is no longer the document we issued, which is exactly the question worth asking.