Prove your signed documents are valid, at scale
AlgoVoi Evidence Auditor verifies every signature across an archive of signed documents (classical RSA/ECDSA and post-quantum), flags the weak, expired, broken-chain and quantum-exposed ones, and produces a signed, tamper-evident audit report your auditor checks with the free verifier. Read-only, self-hosted, air-gap capable.
What it is
Evidence Auditor is the middle rung between checking one document by hand and running the whole records lifecycle. Point it at a folder or archive and it verifies every signature it finds, classifies the state of each document, and signs the resulting report with a post-quantum reseal envelope. You hand that report to an auditor, who verifies it themselves with the free tool, and re-run it each cycle to prove nothing has changed since the last one.
The ladder
Free: av-reseal-verify
Inspect and verify a single document, offline. Apache-2.0, no licence.
Reseal
Re-anchor the documents you already hold into post-quantum attestations.
Evidence Auditor (this)
Batch-verify a whole archive and produce the signed, tamper-evident report.
Compliance Suite
Store write-once, retain, place legal holds, run a console, custody keys, seal at scale.
What it flags per document
Signature state
Verified or invalid, and unsigned files called out explicitly.
Weakness and expiry
Weak digest (SHA-1), expired certificate, and broken trust chain.
Shadow PDF
Partial-coverage (shadow) PDF signatures that do not cover the whole document.
Post-quantum exposure
Documents whose classical signatures a quantum adversary could forge, your cue to re-anchor them.
Optional offline trust-path (--trust-roots) and CRL (--crl) checks; air-gap capable, no upload.
The report verifies itself
Each run produces audit-report.json (findings), audit-report.json.reseal.json (the signed attestation), plus HTML and CSV. Because the report is signed with a post-quantum reseal envelope, anyone can confirm it is authentic and unaltered using the free verifier, with no licence:
| Output | What it is |
|---|---|
audit-report.json | Per-document findings across the whole archive |
audit-report.json.reseal.json | Post-quantum signed attestation over the report, verifiable offline by the free tool |
audit-report.html / .csv | Human-readable and spreadsheet views of the same findings |
Baseline diff
Re-run against a prior report and Evidence Auditor shows what changed, what is new, and what was removed since the baseline. That turns a one-off check into a repeatable control: each cycle produces signed evidence that the archive is still intact, which is what an auditor or regulator wants to see over time rather than a single snapshot.
Scope, stated honestly
Read-only: Evidence Auditor verifies and reports; it never stores, mutates, or governs your documents. Auditing an archive is the licensed action, gated at the engine and fail-closed. Verifying an existing report is free with av-reseal-verify, as is single-document verification. It produces cryptographic evidence artifacts; it is not a guarantee of legal admissibility or regulatory compliance.
Pricing
A licensed product from $599 perpetual or $299 per year, bought self-serve from the suite store. The free av-reseal-verify tool checks the reports it produces at no cost, so the parties you share evidence with never need a licence to trust it.
Frequently asked questions
What is AlgoVoi Evidence Auditor?
Evidence Auditor verifies every signature across an archive of signed documents (classical RSA/ECDSA and post-quantum) and produces a signed, tamper-evident audit report you can hand to an auditor, then re-run each cycle to prove nothing changed. It is read-only, self-hosted, and air-gap capable, and it never stores, mutates, or governs your documents.
How is it different from the free verifier and the Compliance Suite?
It is the middle rung of the ladder. The free av-reseal-verify checks one document. Evidence Auditor batch-verifies a whole archive and produces the signed report. The Compliance Suite goes further: write-once storage, retention, legal holds, a console, SIEM forwarding, key custody, and sealing at scale.
Can the audit report be trusted and verified independently?
Yes. The report is signed with a post-quantum reseal envelope, so anyone can confirm it is authentic and unaltered using the free av-reseal-verify tool with no licence needed. The party you hand the report to verifies it themselves, offline, rather than taking your word for it.
What does it flag per document?
Per document it reports verified or invalid, unsigned, weak digest (SHA-1), expired certificate, broken trust chain, partial-coverage (shadow) PDF, and post-quantum exposure, with optional offline trust-path and CRL checks. A baseline diff re-runs against a prior report to show changed, new, and removed items.
Is it read-only and air-gap capable?
Yes. Evidence Auditor verifies and reports; it never stores, mutates, or governs your documents, and it uploads nothing. Auditing an archive is the licensed action, gated at the engine and fail-closed; verifying an existing report is free with av-reseal-verify, as is single-document verification.
How much does Evidence Auditor cost?
A licensed product from $599 perpetual or $299 per year, bought self-serve from the suite store. Verifying the report it produces is always free with the open av-reseal-verify tool.
Last updated: 11 August 2026.