FLUXPROOF SAMPLE PROOF PACKET (a real capture of a public example page)

CAPTURE: cap_4rfxOGIty94CcCXeuHQv6nnuW7cthJD9
  Page requested:   https://example.com/
  Page served from: https://example.com/
  Fetched at:       2026-10-10T08:14:10.036Z (FluxProof's clock)
  HTTP status:      200, text/html; charset=utf-8, 577 bytes
  SHA-256 of bytes: 25ddf2c883e0d1958ea971d279a7e4f0fd446724ee3db7db19dadabd4a62e484
  Lowest price the page declares: none found
  Independent timestamp: 2026-10-10T08:14:10.000Z from DigiCert (RFC 3161), over SHA-256 598a0cd8814a51567dcfd242ae774bc2fbc7eb8af27e6b94370d5f4fac203e82 of manifest.json
  Timestamp authority trust: DigiCert roots ship in Windows, macOS and most Linux certificate stores.
  Exact bytes served: page.html
  Previous capture in this monitor's chain: none (first capture)

WHAT THIS PACKET SHOWS
- The FluxProof server requested the page above and received exactly the bytes in the page file, with
  the status and headers recorded in the manifest, at the time shown.
- The manifest, which names that page's SHA-256, existed no later than the independent timestamp
  (when one is present). That time comes from the timestamp authority, not from FluxProof.
- FluxProof issued the manifest (Ed25519 signature) and it has not changed since.
- Captures of the same page are chained: each manifest names the previous capture's manifest hash.

WHAT IT DOES NOT SHOW
- What other visitors saw. Sites can show different content by location, device, cookies, login,
  or test group. FluxProof fetches without cookies or login, from Cloudflare's network.
- Anything drawn only by JavaScript. FluxProof does not run scripts; prices are read only from what
  the page itself declares (structured data, meta tags, or Shopify product JSON).
- A picture of the page. Opening page.html in a browser loads today's images and styles from the
  live site; the evidence is the HTML itself.
- Who changed the page or why.

This packet is a technical record, not legal advice. Whether and how it can be used in a dispute or
in court is for you and your lawyer to decide. A lawyer can use the manifests, the hashes and the
verification steps above to support a certification by a qualified person (for example under US
Federal Rules of Evidence 902(13) or 902(14)); FluxProof does not make that certification for you.

HOW TO CHECK THIS PACKET YOURSELF (OpenSSL 3 and sha256sum, on any computer)

1. Nothing in the packet was altered since it was built:
     sha256sum -c files.sha256

2. page.html is exactly what the manifest describes: compare
     sha256sum page.html
   with "raw" -> "sha256" in manifest.json.

3. FluxProof signed manifest.json (Ed25519):
     openssl pkeyutl -verify -pubin -inkey signing-key.pem -rawin -in manifest.json -sigfile manifest.sig
   The same public key is published at /.well-known/fluxproof-signing-key.pem on the FluxProof site.

4. An outside timestamp authority (DigiCert) saw manifest.json no later than 2026-10-10T08:14:10.000Z:
     openssl ts -reply -in timestamp.tsr -text
     openssl ts -verify -data manifest.json -in timestamp.tsr -CAfile <root certificate>
   DigiCert roots ship in Windows, macOS and most Linux certificate stores.
