Skip to content

Custody Chain Attestation

JSON Schema for custody-chain attestations in CycloneDX declarations format. Shape-only: chain continuity (prevEventHash linkage), seq gaplessness, Merkle inclusion under the seal token, and Fulcio identity comparison are verifier (adbom-cli) checks, not schema checks. Normative requirements: https://sec.hypermedia.au/standards/custody-chain/v1 Cross-document convention (ratified 2026-07-18): map.requirement cites the requirement's published URL (pattern-pinned, offline-checkable); claim.target is a BOM-Link to the L1 Case Provenance BOM. These deliberately reference documents outside this BOM; resolution is via sec.hypermedia.au and BOM-Links.

Attests conformance to the custody-chain standard.Download raw JSON.

What this attestation claims

It asserts exactly one claim: custody-chain-intact.

About: CUST-007: BOM-Link to the L1 Case Provenance BOM — matching ^urn:cdx:.+.

Reasoning: a written justification is optional.

Evidence: one or more references to evidence items, by bom-ref.

How it's scored

Each mapped requirement carries two independent 0.0–1.0 scores, each with a rationale: conformance (how fully the requirement is met) and confidence (how sure the assessor is of that judgement).

Signing & trust

Signed with ES256 / ES384 / ES512.

Keyless signing via a Fulcio certificate — the signer's identity is bound in the certificate path, so there's no long-lived key to manage.

Who may attest

Each attestation names an assessor described by:

bom-ref (required)
a BOM reference identifying the assessor entry
thirdParty
whether the assessor is an independent third party
organization (required)
the attesting organization (name + URL)