SHA-256
GCCAP records SHA-256 fingerprints for supported source/report records. A different digital file produces a different fingerprint, which helps detect later changes to sealed content.
Evidence integrity
GCCAP records SHA-256 fingerprints for supported source/report records. A different digital file produces a different fingerprint, which helps detect later changes to sealed content.
Where supported, reports identify the source filename, capture record, parser version, observation window and limitations used to create the report.
A hash does not prove that the original measurement was accurate, that a product was safe, or that a legal requirement was met. Those questions require the underlying measurement context and any applicable rules or specifications.
During launch, reports remain review-gated. GCCAP does not automatically release a customer report simply because a file was processed.