{"schemaVersion":"0.1","generatedAt":"2026-10-09T19:42:28.401Z","entry":{"knowledgeKey":"evidence-and-source-custody","kind":"capability","entityKey":"security-trust","locale":"en","primaryQuestion":"What does MeshQu do with the evidence behind a decision, and does it establish that the evidence is true?","questionVariants":[{"question":"Does MeshQu store my documents?"},{"question":"Can a receipt prove the KYC file was genuine?"},{"question":"What is an evidence manifest?"},{"question":"Who signs for the evidence?"}],"title":"Evidence, references and source custody","answer":"MeshQu binds evidence by reference. It stores digests, references and metadata rather than the artefact bytes, and binding a digest does not establish that the referenced artefact is authentic, complete or the right one for the policy. A custodian outside MeshQu can sign for an evidence item. Where MeshQu does hold bytes, the custody routes prove byte identity against what was sent, and nothing about the source.","explanation":"The useful property here is narrow and worth stating exactly. A digest recorded at decision time fixes which artefact was considered, so a document produced later can be checked against what the decision actually used. That is a real answer to a real audit question. It is not an answer to whether the document was genuine. MeshQu hashes what it is given, and it cannot attest that the digests a caller submits reflect reality. Independent custody is where a stronger claim can come from. Custodian signatures are produced outside MeshQu, by banks, vendors or auditors, and MeshQu never holds their private keys, so a verifier supplies the trust roots out of band. Whether a deployment uses independent custodians at all is an operating choice rather than a product property. Where bytes are stored, the documentation is precise about what storage proves: that what was stored is byte-identical to what was sent, and that a later availability check reports what was retrievable at that moment.","applications":[{"value":"Answer an auditor who asks whether the signed record establishes that the underlying documents were genuine."},{"value":"Show which artefact a decision considered, by comparing a document produced later against the digest recorded at the time."},{"value":"Decide where independent custody of evidence has to sit before a stronger evidential claim is made."}],"limitations":[{"value":"MeshQu does not store evidence content. It stores digests, references and metadata."},{"value":"Binding a digest does not establish that the referenced artefact is authentic, complete, or the right artefact for the policy."},{"value":"The source-artifact record binds only the hash. Type, filename and size are stored but are not bound."},{"value":"The source-custody and sealed-review routes have no availability assessment: the 17 July 2026 verified-claims register does not cover them. Availability on this entry is recorded as not publicly confirmed for that reason, and should be confirmed before either route is relied on."},{"value":"Whether independent custody is used at all is a deployment and governance responsibility, not something the product supplies."}],"nextStep":{"label":"MeshQu trust model","href":"https://docs.meshqu.com/security/trust-model"},"claims":[{"claimKey":"reference-based","statement":"Evidence is handled by reference. The artefact bytes are not stored; only digests, references and metadata are.","qualification":"The documentation names the phrasing to use: evidence references and evidence digests, not stored evidence."},{"claimKey":"binds-what-it-is-given","statement":"MeshQu binds the digests and references it is given and cannot attest that they reflect reality. It hashes what it is given.","qualification":"The same sentence covers the actor identifier, which is the subject of the actor-identity entry."},{"claimKey":"independent-custodian","statement":"An independent custodian, not MeshQu, can sign for an evidence item. Custodian signatures are produced outside MeshQu, MeshQu never holds custodian private keys, and trust roots are supplied to the verifier out of band.","qualification":"Whether a deployment uses independent custodians is an operating choice. The trust model lists independent custody of evidence and ratification under deployment or governance responsibilities."},{"claimKey":"custody-proves-byte-identity","statement":"Where MeshQu does hold bytes, finalising a staged upload proves byte identity of what was stored against what was sent. It proves nothing about the source: not that it is authentic, not that the locator ever served it, not that it is the right source for the policy.","qualification":"The availability of these routes in any deployment is not publicly confirmed. See the entry's limitations."},{"claimKey":"availability-is-an-observation","statement":"Availability of a stored source is a checked observation, never a guarantee. The verified state follows a hash comparison and means the bytes were retrievable at that moment. Where no check ran, the entry records that no check ran, which is not a finding about the bytes.","qualification":"A retrievability observation is not a statement about whether the source is the right source, and it says nothing about future availability."}],"statementKind":"capability","availability":"not-publicly-confirmed","evidenceStrength":"source-reported","publicSources":[{"title":"MeshQu docs - Receipt reference","url":"https://docs.meshqu.com/concepts/receipt-reference","context":"The reference-based evidence model, the custodian-signature boundary, and the documentation owner's own statement of the copy traps around stored evidence."},{"title":"MeshQu docs - Trust model","url":"https://docs.meshqu.com/security/trust-model","context":"The statement that MeshQu hashes what it is given and cannot attest that submitted digests reflect reality, and the list of deployment and governance responsibilities."},{"title":"MeshQu docs - Source custody: finalise a staged upload","url":"https://docs.meshqu.com/api-reference/source-custody/finalise-a-staged-upload-into-custody","context":"What storing bytes proves, stated by the route itself: byte identity against what was sent, and nothing about the source."},{"title":"MeshQu docs - Retrieve a sealed review submission and its canonical components","url":"https://docs.meshqu.com/api-reference/policy-review/retrieve-a-sealed-review-submission-and-its-canonical-components","context":"How an availability state is produced, and why an unchecked entry is not a finding about the bytes."}],"revision":"3734157138c46ed9620bd8c7d86a6b67a77918669017566ba8e1b76ed6559765","updatedAt":"2026-09-11T13:38:45.930Z","canonicalUrl":null,"related":[{"key":"decision-receipts","url":"https://www.meshqu.com/knowledge/decision-receipts.json"},{"key":"limits-of-verification","url":"https://www.meshqu.com/knowledge/limits-of-verification.json"},{"key":"responsible-ai-evidence","url":"https://www.meshqu.com/knowledge/responsible-ai-evidence.json"},{"key":"independent-verification","url":"https://www.meshqu.com/knowledge/independent-verification.json"}]}}