How does SHA-256 pinning make an AI audit record tamper-evident?

SHA-256 (FIPS 180-4) produces a fixed 256-bit digest where any change to the input — one bit in the model, probe set, or result — yields a completely different hash, and the function is collision-resistant. Pinning each artifact by its digest and binding them…

register 09 · Compliance pins· SHA-256 / FIPS 180-4
01 ·

Answer.

Supply-chain / provenance standard · SHA-256 / FIPS 180-4.

SHA-256 (FIPS 180-4) produces a fixed 256-bit digest where any change to the input — one bit in the model, probe set, or result — yields a completely different hash, and the function is collision-resistant. Pinning each artifact by its digest and binding them into a Merkle root means internal or external compliance recomputes the hashes and detects any alteration. That is what makes a Planisphere record tamper-evident: a third party can recompute the root and confirm nothing changed, without trusting the producer.

02 ·

The mark behind the answer.

SHA-256 / FIPS 180-4 is a provenance standard: it cares about where an artifact came from and whether the chain is unbro…

hash algorithm · per-file pinning primitive.

→ Full reference for SHA-256 / FIPS 180-4

Try SHA-256 / FIPS 180-4 with a free test key.

Start with the free sandbox. Planisphere measures model behaviour and emits a reproducible, sha-pinned record — it does not certify, file, or give legal advice.

API ·

When SHA-256 / FIPS 180-4 asks for proof, hand over records — not assurances.

record the duty · seal the receipt · verify offline

Planisphere records each duty event — an output marked, a disclosure shown, a review made — and seals it into a receipt that verifies offline against our published keys. You send hashes, never content. A record is evidence a third party can check; it is not a certification and not a legal determination.

See how a record is checked