Letterprove

How to verify any of this

Every attestation is signed, chained to the one before it, and carries a commit-pinned link to the code that computed it. Nothing below asks you to trust us — it tells you where to check.

/.well-known/letterprove.jsonthe machine-readable version ↗

Run the verifier

A standalone script with no dependencies. It re-implements canonicalisation rather than importing ours, so when it agrees the agreement means something.

npm run verify -- https://app.letterprove.com/attest/<vendor>/chain

Point it at a chain, not a single document: it checks every signature and every prev_hash link, then prints the provenance tier the evidence earned.

Read the verifier source ↗

How signatures are made

Algorithm
EdDSA (Ed25519)
Signing mode
countersigned
Countersigned by Letterstory after fraud scoring, so the key never sits on this service.

What the tiers mean

Every attestation carries a `tier`. A valid signature proves only that this document is ours and unaltered — it says nothing about how good the underlying evidence is. The tier says that, and it is the claim. A signed tier-0 document asserts only that the vendor said so.

  • tier 0vendor-asserted

    The vendor stated this. Nothing corroborates it — either no usage was observed, or the vendor has not proven control of the domain events are pinned to.

    Forgeable by: The vendor alone, trivially. Treat as a claim, not as evidence.

  • tier 1script-observed

    Letterprove's script reported usage attributable to this company's email domain.

    Forgeable by: The vendor, with effort. The collector pins events to a verified origin, which a browser cannot forge — but a non-browser client can send whatever origin it likes.

  • tier 2infrastructure-bound

    Observed usage carrying a Letterprove-side receipt timestamp and an origin pinned to a domain the vendor proved control of by DNS.

    Forgeable by: A determined vendor running a distributed spoofing rig. Volume and burst anomalies are scored against it; a slow, well-distributed rig is an accepted open gap.

  • tier 3third-party confirmed

    An invoice that actually settled for this company, read directly from the vendor's own live-mode Stripe account, alongside observed usage. A subscription on its own does not qualify: it says what the vendor meant to bill, and a free one reaches `active` for nothing.

    Forgeable by: A vendor willing to pay themselves. Every condition is checked against a third party's ledger rather than the vendor's word, and money has to genuinely move through a processor in a Stripe-verified live account — but a vendor prepared to spend real money on a lie can still reach it. Read this as corroboration, not as immunity.

  • tier 4customer counter-signed

    The customer reviewed this exact usage summary and approved it, at a link delivered to an address on their own domain. The vendor never held that link.

    Forgeable by: Nobody, without control of a mailbox at the customer's own domain. A vendor who registers a domain and invents a company on it controls both ends — fraud scoring, not this tier, is the backstop for that.

Published proofs (2)