How to verify any of this
Every attestation is signed, chained to the one before it, and carries a commit-pinned link to the code that computed it. Nothing below asks you to trust us — it tells you where to check.
/.well-known/letterprove.jsonthe machine-readable version ↗Run the verifier
A standalone script with no dependencies. It re-implements canonicalisation rather than importing ours, so when it agrees the agreement means something.
npm run verify -- https://app.letterprove.com/attest/<vendor>/chain
Point it at a chain, not a single document: it checks every signature and every prev_hash link, then prints the provenance tier the evidence earned.
Read the verifier source ↗How signatures are made
- Algorithm
- EdDSA (Ed25519)
- Signing mode
- countersigned
- Countersigned by Letterstory after fraud scoring, so the key never sits on this service.
What the tiers mean
Every attestation carries a `tier`. A valid signature proves only that this document is ours and unaltered — it says nothing about how good the underlying evidence is. The tier says that, and it is the claim. A signed tier-0 document asserts only that the vendor said so.
- tier 0vendor-asserted
The vendor stated this. Nothing corroborates it — either no usage was observed, or the vendor has not proven control of the domain events are pinned to.
Forgeable by: The vendor alone, trivially. Treat as a claim, not as evidence.
- tier 1script-observed
Letterprove's script reported usage attributable to this company's email domain.
Forgeable by: The vendor, with effort. The collector pins events to a verified origin, which a browser cannot forge — but a non-browser client can send whatever origin it likes.
- tier 2infrastructure-bound
Observed usage carrying a Letterprove-side receipt timestamp and an origin pinned to a domain the vendor proved control of by DNS.
Forgeable by: A determined vendor running a distributed spoofing rig. Volume and burst anomalies are scored against it; a slow, well-distributed rig is an accepted open gap.
- tier 3third-party confirmed
An invoice that actually settled for this company, read directly from the vendor's own live-mode Stripe account, alongside observed usage. A subscription on its own does not qualify: it says what the vendor meant to bill, and a free one reaches `active` for nothing.
Forgeable by: A vendor willing to pay themselves. Every condition is checked against a third party's ledger rather than the vendor's word, and money has to genuinely move through a processor in a Stripe-verified live account — but a vendor prepared to spend real money on a lie can still reach it. Read this as corroboration, not as immunity.
- tier 4customer counter-signed
The customer reviewed this exact usage summary and approved it, at a link delivered to an address on their own domain. The vendor never held that link.
Forgeable by: Nobody, without control of a mailbox at the customer's own domain. A vendor who registers a domain and invents a company on it controls both ends — fraud scoring, not this tier, is the backstop for that.