Skip to contentSaltar al contenidoAle nan kontni anПерейти к содержимомуדלג לתוכן
EstateDraftFL

For Florida law firms

Public verification: /verify, the offline verifier and the trust root

both lanes · Deterministic — no model call

Current availability

ShippedConfigured and enabled: public; the document-file lookup is throttled per address and globally.

Where it lives
/verify (receipt · document file · manifest) · /verifier/index.html · /trust-root · /.well-known/edfl-trust-root.json
What unlocks it
anyone — no account

Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.

Capabilities

  • ShippedDocument file: the browser fingerprints the file (SHA-256) and sends only the fingerprint; the answer names the sealed version those exact bytes belong to — its kind, number, sealing and delivery dates, and anchor tier — never a name, an amount, a matter or a firm.
  • ShippedManifest: a manifest with its files, or an unzipped hand-over folder, is verified entirely in the browser, band by band — bytes, citations re-derived from the carried statute text, the chained record, the anchor, the issuer — and what nothing checked.
  • ShippedThe offline verifier is two static files under the MIT licence, generated from the same module as the site's checks (a drift test keeps them identical); its page policy forbids every network request, and it carries a sample with one deliberately wrong quotation that it refuses.
  • ShippedThe trust root publishes every issuer key a manifest may name (current, retired and the sample), and the daily anchor tier.

Limits

  • A match proves only that the bytes are the sealed version's bytes; a print, a scan or a re-save is a different file.
  • Nothing here says a document is legally valid, complete or suitable, or who signed it and how it was executed.
  • A lookup that cannot run says so (unavailable) — it is never reported as no match.

What EstateDraftFL refuses

Reason codeHTTPWhat it means
not-a-fingerprint400Only a 64-character SHA-256 fingerprint is accepted; no file content is ever sent.
rate-limited429Too many checks from one address (or overall) in the window.
verification_unavailable503The record could not be read; the check did not run (never a failed match).

Evidence

  • src/app/api/verify-document/route.ts
  • src/components/verify/VerifyModes.tsx
  • public/verifier/index.html
  • src/lib/verifier/offline-verifier-drift.test.ts
  • src/lib/verifier/trust-root.ts

Last reviewed 2026-09-25

← All surfaces