KAELOX.

Kx Verifier

Do not take our word for it.

An inspection pack is only worth anything if it can be checked by someone who does not trust the system that produced it. The Kx Verifier is 164 lines with zero dependencies — short enough to read in full before you run it.

Kx Verifier result: nine verified, none failed, two not verified as witnesses, result verified and scoped
Node.js only. Nothing installed, nothing transmitted, nothing written.Kx Verifier

During alpha it is sent on request rather than published. Not because it is fragile — the adversarial suite is below and passes — but because a control this important should be handed over with a conversation attached. Ask, and it arrives the same day.

Three states, never collapsed into twoREF OP-001 · requirement OP-13
StateMeaning
VERIFIEDThe hash recomputed from the block’s own content matches, and the linkage to its predecessor holds
FAILEDThe recomputed hash does not match, the linkage is broken, or a block is missing with no witness supplied
NOT_VERIFIEDThe block does not carry what is needed to check it. This is not a pass. A distinct exit code, so an unchecked block can never be reported as a verified one
What it cannot do — disclosedT6 · the basis for SL 2
Eleven adversarial tests run against a known-good pack — altered reading, flipped verdict, removed block, transplanted signature, resealed block, backdated timestamp, removed not-fired conditions, a block disguised as a witness, an unrecognised hash algorithm. All detected.
One is not. An attacker with write access to the entire store, who rewrites the chain from a point forward, is not detected by hashing alone. Defence requires an anchor outside the store — periodic external notarisation, or a hardware root of trust. Kaelox has neither today. This is the stated basis for claiming IEC 62443 SL 2 rather than SL 3.

A witness carries sequence number, own hash and predecessor hash only, with no content — enough to prove nothing was removed, disclosing nothing about anyone else’s material.