Back to How it works

Attestation Record

tg.attestation · schema 1.0

Attestation Record

Cryptographically signed chain-of-custody artifact for one object transferred between cloud providers.

tg_id: 26e0e72027abd4501c4bf5ced83dbb85b1e6b4fc70495b662922fd839b12c391
Verification passed
6 PASS · 0 WARN · 0 FAIL
● FINAL STATE: COMPLETE — ATTESTED
Attestation scope. Transfer General attests only to operations executed within the TG-controlled pipeline — from the moment TG read this object at the source through the moment it signed this record after the destination write was confirmed. TG does not attest to the object’s prior history, who placed it in the source bucket, or events outside the TG pipeline. Those facts are the customer’s accountability layer. Two categories of customer-supplied content appear in the signed payload: customer-declared fields entered at deployment, recorded verbatim but not verified by TG.
§1Subject & Pipelinewhat was transferred · between where
Subjectin signed payload
Object namepatient001_study002_series05_img010.dcm
Size256.0 MB (268,444,629 bytes)
Content hashSHA-256: 7756cef737283c3232dfd806…
Source ETagCOGq1++cnJUDEAE=
Destination ETag"4e2ab3115963d7378ffe43d8a5cef3b0-26"
Pipelinein signed payload
Pipelinegcp1-aws1
RouteGCP (us-east5) → AWS (us-east-2)
Pipeline ID03f8d448-4563-453b-a6ed-b6b3fc7d83f0
Source bucketgcp://tg-7c4f1e-gcp1-aws1-source
Destination bucketaws://tg-7c4f1e-gcp1-aws1-dest
§2Integrity Verificationthe hash that the destination must match
Hash comparisonintegrity anchor
AlgorithmSHA-256 (NIST FIPS 180-4)
Source hash7756cef737283c3232dfd80639d6…
Destination hash7756cef737283c3232dfd80639d6…
Match✓ hash_match = true
EncryptionFIPS-validated
AlgorithmAES-256-GCM
FIPS postureAll crypto by FIPS 140-2 validated modules
Crypto librarycryptography 46.0.5 / OpenSSL 3.5.5 (FIPS provider)
PatternEnvelope (DEK wrapped by customer KMS)
§3Key Managementcustomer DEK · Server General ASK
KMS encrypt (source)evidence row
ProviderGCP
AlgorithmSYMMETRIC_DEFAULT
Key IDprojects/meridian-ai-prod/locations/us-east5/keyRings/phi-ingest/cryptoKeys/dek-prod/cryptoKeyVersions/1
Called at2026-06-23T01:39:38.452922+00:00
KMS decrypt (destination)evidence row
ProviderGCP
AlgorithmSYMMETRIC_DEFAULT
Key IDprojects/meridian-ai-prod/locations/us-east5/keyRings/phi-ingest/cryptoKeys/dek-prod
Called at2026-06-23T01:47:42.438733+00:00
Attestation signing key (ASK)in signed payload · owned by Server General
AlgorithmEC_SIGN_P384_SHA384
Key IDprojects/sg-attestation-prod/locations/us-east5/keyRings/ask-prod/cryptoKeys/ask-attestation-signer/cryptoKeyVersions/1
Public key fingerprintSHA-256: b0d7ce9c0cf19d76da0b16fbf04d16077b26824abbe2a8c8c359d572e2f7f495
Payload digestSHA-256: 95337201177964715e151a5f5f4ca5760c45cc391dc41779e4660a71abc3b4e5
CanonicalizationRFC 8785 / JCS
Signature sequence1
Context tagTG-ATTESTATION-V1
§4Transfer Timeline22 events · 21 evidence rows · 8m 42.063s under operational custody
1Encryption at SourceGCP · us-east5 · source → staging
Object detected at source — transfer started01:39:37.720
KMS encrypt — DEK wrapped01:39:51.151
Source hash computed (streaming)01:39:51.181
Encryption metadata sidecar written01:39:51.267
Object encrypted — staging write confirmed01:39:51.480
Source object deleted from source bucket01:39:51.572
Operation success01:39:51.605
2Cross-Cloud Transferstaging → landing · object encrypted throughout
Cross-cloud transfer initiated01:47:01.935
Transfer metadata read01:47:01.985
Transfer metadata written01:47:02.138
Landing write confirmed01:47:33.225
Object deleted from staging bucket01:47:33.345
Operation success01:47:33.374
3Decryption at Destination & AttestationAWS · us-east-2 · landing → destination → sign
Decryption started at destination01:47:39.203
Encryption metadata sidecar read01:47:39.322
KMS decrypt — DEK unwrapped01:48:18.785
Destination hash computed inline during decryption01:48:18.912
Hash match verified — integrity anchor01:48:19.228
Destination write confirmed01:48:19.363
Object deleted from landing bucket01:48:19.539
Operation success01:48:19.658
Attestation signed — record sealed01:48:19.782
Time-ordered events recorded by TG at the moment each occurred. Marker rows denote KMS operations, the integrity anchor, and the signing event. All 21 evidence rows appear in the signed payload, each individually Merkle-proven in the immutable ledger.
§5Immutability Anchordefense in depth · independent of TG’s signature
immudb ledger anchordefense in depth
Ledger / tx_id at signingtgaudit / 1648
Prior checkpoint tx_id1084 (signed by immudb + KMS)
Evidence rows21 (all chain-linked via Merkle hashes)
immudb state signatureSHA-256: 688d0025b30972300705… (server-signed; key cross-checked against KMS-signed checkpoint)
Beyond the ECDSA signature, the record is anchored in an append-only immudb ledger that produces its own cryptographic state — verifiable even by an auditor who distrusts the appliance. The ledger’s prior checkpoint (tx_id 1084) is itself signed by both immudb and the cloud KMS.
§6Accountabilitycustomer-declared · TG-observed
Customer-declareddeclared at deployment
Initiating organizationMeridian Health Network
Authorized byA. Whitfield
RoleVP, Information Security
Authorization basisHIPAA Data Movement Policy SEC-001
Authorization date2026-05-01
TG records these declarations verbatim and does not verify their accuracy. The customer is solely responsible for their truth.
TG-observedobserved at sign time
Pipeline namegcp1-aws1
Pipeline ID03f8d448-4563-453b-a6ed-b6b3fc7d83f0
Deployment date2026-05-23T00:12:00Z
tg_id26e0e72027abd4501c4bf5ced83dbb…
Cloud context & execution identityTG-observed · from cloud metadata APIs
Source provider / accountGCP · meridian-ai-prod · us-east5
Destination provider / accountAWS · 441903772074 · us-east-2
TG identity (source)[email protected]
TG identity (destination)arn:aws:iam::441903772074:role/tg-7c4f1e-worker-role
§7Verify Independentlyoffline · cloud-native
Level 1 — Portable (offline ECDSA)
Reconstruct the signing input from the canonical payload, schema version, and context tag; verify against the ASK public key with any standard ECDSA library. No network call. Suitable for long-term archival.
# offline, no Server General contact
node tg/verify.mjs --bundle ./attestation-bundle \
  --pubkey sg-public-key.pem \
  --checkpoint checkpoint.json
Level 2 — Authoritative (cloud-native)
Call the originating cloud’s KMS Verify API against the ASK key resource. Returns a cloud-native verification receipt — legally defensible for formal compliance proceedings.
# cloud-native receipt
gcloud kms asymmetric-signature verify \
  --key ask-attestation-signer --version 1 \
  --input-file payload.bin \
  --signature-file sig.bin
Evidence completeness: this attestation contains all TG-recorded events for this object transfer — none omitted, summarized, or redacted from the canonical payload.
Generated automatically by Transfer General at transfer completion. One signed attestation per object. The canonical JSON is the authoritative artifact; this report is a viewer.
Representative sample — infrastructure identifiers redacted.   tg.attestation 1.0 · EC_SIGN_P384_SHA384 · RFC 8785 / JCS
{
  "schema": "tg.attestation",
  "context_tag": "TG-ATTESTATION-V1",
  "attestation_version": "1.0",
  "attestedAt": "2026-06-23T01:48:19.782902Z",
  "nonce": "a0808468746d129bd5a449694b5c0202eb0d242f751dab039650e332f843a629",
  "installation": {
    "installationId": "tg-7c4f1e",
    "applianceUrl": "https://tg-appliance.meridian.internal:8443"
  },
  "pipeline": {
    "pipelineId": "03f8d448-4563-453b-a6ed-b6b3fc7d83f0",
    "label": "gcp1-aws1",
    "from": "gcp",
    "to": "aws",
    "fromRegion": "us-east5",
    "toRegion": "us-east-2",
    "sourceBucket": "tg-7c4f1e-gcp1-aws1-source",
    "stagingBucket": "tg-7c4f1e-gcp1-aws1-staging",
    "landingBucket": "tg-7c4f1e-gcp1-aws1-landing",
    "destBucket": "tg-7c4f1e-gcp1-aws1-dest"
  },
  "accountability": {
    "customer_declared": {
      "initiating_organization": "Meridian Health Network",
      "authorized_by": "A. Whitfield",
      "role": "VP, Information Security",
      "authorization_basis": "HIPAA Data Movement Policy SEC-001",
      "authorization_date": "2026-05-01"
    },
    "tg_observed": {
      "pipeline_name": "gcp1-aws1",
      "pipeline_id": "03f8d448-4563-453b-a6ed-b6b3fc7d83f0",
      "deployment_date": "2026-05-23T00:12:00Z",
      "cloud_context": {
        "source": {
          "provider": "gcp",
          "account_id": "meridian-ai-prod",
          "region": "us-east5"
        },
        "destination": {
          "provider": "aws",
          "account_id": "441903772074",
          "region": "us-east-2"
        }
      },
      "tg_execution_identity": {
        "source": "[email protected]",
        "destination": "arn:aws:iam::441903772074:role/tg-7c4f1e-worker-role"
      }
    }
  },
  "subject": {
    "tgId": "26e0e72027abd4501c4bf5ced83dbb85b1e6b4fc70495b662922fd839b12c391",
    "objectKeyAtSource": "patient001_study002_series05_img010.dcm",
    "objectKeyAtDest": "patient001_study002_series05_img010.dcm",
    "sourceEtag": "COGq1++cnJUDEAE=",
    "destEtag": "\"4e2ab3115963d7378ffe43d8a5cef3b0-26\"",
    "source_hash": "7756cef737283c3232dfd80639d60a5d184e1db727576ade8eeb249afc2e1fad",
    "destination_hash": "7756cef737283c3232dfd80639d60a5d184e1db727576ade8eeb249afc2e1fad",
    "hash_match": true,
    "contentHashAlgorithm": "SHA-256",
    "bytes": 268444629,
    "bytesHuman": "256.0 MB (268,444,629 bytes)",
    "transfer_started_at": "2026-06-23T01:39:37.720287Z",
    "transfer_completed_at": "2026-06-23T01:48:19.658005Z"
  },
  "cryptoPosture": {
    "encryptionAlgorithm": "AES-256-GCM",
    "fipsValidated": true,
    "fipsPostureDescription": "All crypto operations performed by FIPS 140-2 validated modules",
    "cryptoLibrary": "cryptography 46.0.5 / OpenSSL 3.5.5 27 Jan 2026 (FIPS provider enabled)",
    "pattern": "Envelope (DEK wrapped by customer KMS)"
  },
  "immudbAnchor": {
    "db": "tgaudit",
    "txIdBeforeSigning": 1648,
    "txHashBeforeSigningHex": "86a13b8265ad28d2b3283494513472f956ed03f5bf82033b9574db6ca610768c",
    "txIdAfterSigning": 1648,
    "txHashAfterSigningHex": "86a13b8265ad28d2b3283494513472f956ed03f5bf82033b9574db6ca610768c",
    "serverSignatureB64": "MEUCICEDeSjnmguwtx73APgTynwSULH6yqsNbgoY\u2026",
    "serverPublicKeyB64": "BMFnD485hFsOz1BRRDxCcR/k7FR/ZcrdmQG7jupG7xuvo5ZcqEUvfm1AsutchXdjWxovRTjHkeGDbDY+94rAtYQ="
  },
  "evidence": [
    {
      "timestampUs": "2026-06-23T01:39:37.720287Z",
      "event": "ENCRYPT_START",
      "severity": "AUDIT",
      "data": {
        "dst": "gcp://tg-7c4f1e-gcp1-aws1-staging/patient001_study002_series05_img010.dcm.aes256",
        "sourceEtag": "COGq1++cnJUDEAE=",
        "src": "gcp://tg-7c4f1e-gcp1-aws1-source/patient001_study002_series05_img010.dcm"
      },
      "chainHash": "5ec365a104e7d26442635b7eef02c754fa4533d36b463e4f891b86fea06add5c",
      "proofB64": "CpgFCMMJEosCAk0uAAAAAgAAAACAA/jUSEVjRTum7baz\u2026 [truncated]"
    },
    {
      "timestampUs": "2026-06-23T01:39:51.151018Z",
      "event": "KMS_ENCRYPT",
      "severity": "AUDIT",
      "data": {
        "dst": "gcp://tg-7c4f1e-gcp1-aws1-staging/patient001_study002_series05_img010.dcm.aes256",
        "kms": "{'algorithm': 'SYMMETRIC_DEFAULT', 'bulkCipher': 'AES-256-GCM', 'cryptoLibrary': 'cryptography 46.0.5 / OpenSSL 3.5.5 27 Jan 2026', 'fipsEnabled': True, 'keyId': 'projects/meridian-ai-prod/locations/us-east5/keyRings/tg-7c4f1e-keyring/cryptoKeys/tg-7c4f1e-key/cryptoKeyVersions/1', 'operation': 'encrypt', 'provider': 'gcp', 'timestamp': '2026-06-23T01:39:38.452922+00:00'}",
        "src": "gcp://tg-7c4f1e-gcp1-aws1-source/patient001_study002_series05_img010.dcm"
      },
      "chainHash": "beaa539eb2da275690f261b8fc9c442edb10bbfdbebb33f709f3b0c5fd1b5c69",
      "proofB64": "CuQHCMwJEosCAk0uAAAAAgAAAACAA/jUSEVjRTum7baz\u2026 [truncated]"
    },
    "\u2026 19 more rows (full bundle in download)"
  ],
  "checkpointAnchorPriorTxId": 1084,
  "attestedSequenceNumber": 1,
  "signature": {
    "algorithm": "EC_SIGN_P384_SHA384",
    "keyResourceName": "projects/sg-attestation-prod/locations/us-east5/keyRings/ask-prod/cryptoKeys/ask-attestation-signer/cryptoKeyVersions/1",
    "publicKeyFingerprintSha256": "b0d7ce9c0cf19d76da0b16fbf04d16077b26824abbe2a8c8c359d572e2f7f495",
    "payloadSha256": "95337201177964715e151a5f5f4ca5760c45cc391dc41779e4660a71abc3b4e5",
    "sig": "MGQCME07/ExxQzvsf/WmwKowb1uJv6UF4CthTrPxKaUNNxeo\u2026",
    "canonicalization": "RFC8785/JCS"
  }
}
Representative redacted sample. The full canonical JSON — all 21 evidence rows with Merkle proofs — is the authoritative artifact and downloads with the bundle.
Verification passed.
6 PASS · 0 WARN · 0 FAIL · the appliance ran tg/verify.mjs
StatusCheckDetail
PASSsignatureECDSA P-384 / SHA-384 against EC_SIGN_P384_SHA384
PASSchain integrity21 rows; head matches last row’s chain_hash
PASSmerkle proofs21/21 rows verified via VerifiableSQLEntry
PASSimmudb state signatureanchor + 21 rows; immudb key sha256=acb5bf7ded4ddb1e…; key cross-checked against KMS-signed checkpoint
PASSprior-checkpoint anchortx_id 1084, signed by immudb + KMS
PASSschema sanitytg.attestation
Note: this verifier runs on the appliance itself, so it confirms the artifact is internally consistent but cannot prove the appliance is not tampering with its own output. For independent verification, download the bundle and run node tg/verify.mjs <bundle-dir> on an outside machine.