Incident in progress What to do in the first hour → Preserve first. Several ordinary responses destroy the evidence permanently.
Wirewalk Forensics and Security

Versions and integrity

Every page here carries a digest of its own source and a link to its history. Here is what those values mean, how to check them without taking my word for it, and the index of every page on the site.

Document
WW-F-015
Version
1.0
Issued
2026-09-11
Last revised
2026-09-11
Scope
Document integrity and version index
Authority
Principal

What the footer means

Four values at the foot of every page; an unstamped page shows no digest row. Prices are stamped the same way: Principal examination $425/hr, full schedule.

Footer fields
FieldWhat it isWhat this does not establish
PAGE The document's canonical path. Not that an intermediary left the delivered page unaltered.
REVISED Last substantive revision. Not that no edit followed it; the history can contradict me.
SHA-256 (SOURCE) Digest over the source below the front matter, from a tool in the public repository. Not who wrote the text, when, or whether it is true.
prior versions Commit history of that one file. Not that the history is complete; I hold the repository.

Checking it yourself

  1. git clone https://github.com/wirewalktech/forensics-wirewalk
  2. Every page: python3 tools/stamp.py --check names any file whose digest does not match.
  3. One page, none of my code:
    awk 'f{print} /^---$/{n++; if(n==2) f=1}' versions.html | shasum -a 256

Must equal the footer digest and front-matter content_sha256.

A match proves one thing: this text is byte for byte the source that was stamped. A mismatch usually means I published without stamping — my failure, what this check catches. It does establish this is not the stamped text.

What it is not

Not a timestamping authority, not notarisation, and no evidence about any examination or opinion of mine — test those against the method and the limits. Nor does it protect you against me: I compute the digest and hold the repository. Clone any term that may matter later.

Index

An identifier is never reused. A withdrawn page leaves this table, not the history.

Published documents — index at 2026-09-11
DocumentPageVersionHistory
WW-F-001Home1.0index.html
WW-F-002Emergency1.0emergency.html
WW-F-003Scope1.0scope.html
WW-F-004Rates1.0rates.html
WW-F-005Method1.0method.html
WW-F-006Limits1.0limits.html
WW-F-007Engagement1.0engagement.html
WW-F-008Roles1.1roles.html
WW-F-010Evidence handling1.0evidence-handling.html
WW-F-011Standby1.0standby.html
WW-F-012eDiscovery1.0ediscovery.html
WW-F-013Specimen report1.0specimen-report.html
WW-F-014Contact1.0contact.html
WW-F-015Versions1.0versions.html
WW-F-016Matters1.0matters.html
WW-F-017Security2.0security.html
WW-F-018Order1.0order.html

If something does not match

A digest that fails, a version that did not move when a price did, a page with no row above: tell me. Ring 917-217-7975 or use the form on contact. Reporting a defect creates no engagement. Same number for the work.