DSSE viewer — one page a reviewer can read.
Machine format stays standard (DSSE). This page simply renders a human summary: Security Review Packet + Transparency proof pointers — so procurement/security can validate without spelunking JSON.
Auditors: Open Trust Center (identity receipts · verification · evidence pointers).
Expected outputs (GO / HOLD)
GO: DSSE loads and the referenced receipts + sha256 pointers verify deterministically.
HOLD: Publication/signatures pending, or any required pointer is missing (fail-closed). For procurement pointers, detached PGP signatures in *.sig/ are authoritative; empty embedded signatures are intentional HOLD until the ceremony completes.
FAIL: Any mismatch in digests or proofs — escalate to security before proceeding.
Copy for ticket
One block to paste into a procurement/security ticket (Jira or ServiceNow).
meridianverity.com (or parses a local file). If a procurement pointer is unsigned, the page will show the exact HOLD label and link you to the signing ceremony runbook.