# Evidence, references and source custody

Canonical: https://www.meshqu.com/knowledge/evidence-and-source-custody

What does MeshQu do with the evidence behind a decision, and does it establish that the evidence is true?

MeshQu binds evidence by reference. It stores digests, references and metadata rather than the artefact bytes, and binding a digest does not establish that the referenced artefact is authentic, complete or the right one for the policy. A custodian outside MeshQu can sign for an evidence item. Where MeshQu does hold bytes, the custody routes prove byte identity against what was sent, and nothing about the source.

## In more detail

The useful property here is narrow and worth stating exactly. A digest recorded at decision time fixes which artefact was considered, so a document produced later can be checked against what the decision actually used. That is a real answer to a real audit question. It is not an answer to whether the document was genuine. MeshQu hashes what it is given, and it cannot attest that the digests a caller submits reflect reality. Independent custody is where a stronger claim can come from. Custodian signatures are produced outside MeshQu, by banks, vendors or auditors, and MeshQu never holds their private keys, so a verifier supplies the trust roots out of band. Whether a deployment uses independent custodians at all is an operating choice rather than a product property. Where bytes are stored, the documentation is precise about what storage proves: that what was stored is byte-identical to what was sent, and that a later availability check reports what was retrievable at that moment.

## Limits

- MeshQu does not store evidence content. It stores digests, references and metadata.
- Binding a digest does not establish that the referenced artefact is authentic, complete, or the right artefact for the policy.
- The source-artifact record binds only the hash. Type, filename and size are stored but are not bound.
- The source-custody and sealed-review routes have no availability assessment: the 17 July 2026 verified-claims register does not cover them. Availability on this entry is recorded as not publicly confirmed for that reason, and should be confirmed before either route is relied on.
- Whether independent custody is used at all is a deployment and governance responsibility, not something the product supplies.

## Where it applies

- Answer an auditor who asks whether the signed record establishes that the underlying documents were genuine.
- Show which artefact a decision considered, by comparing a document produced later against the digest recorded at the time.
- Decide where independent custody of evidence has to sit before a stronger evidential claim is made.

## Sources

- [MeshQu docs - Receipt reference](https://docs.meshqu.com/concepts/receipt-reference): The reference-based evidence model, the custodian-signature boundary, and the documentation owner's own statement of the copy traps around stored evidence.
- [MeshQu docs - Trust model](https://docs.meshqu.com/security/trust-model): The statement that MeshQu hashes what it is given and cannot attest that submitted digests reflect reality, and the list of deployment and governance responsibilities.
- [MeshQu docs - Source custody: finalise a staged upload](https://docs.meshqu.com/api-reference/source-custody/finalise-a-staged-upload-into-custody): What storing bytes proves, stated by the route itself: byte identity against what was sent, and nothing about the source.
- [MeshQu docs - Retrieve a sealed review submission and its canonical components](https://docs.meshqu.com/api-reference/policy-review/retrieve-a-sealed-review-submission-and-its-canonical-components): How an availability state is produced, and why an unchecked entry is not a finding about the bytes.

## Related answers

- [Decision Receipts: what the record contains](https://www.meshqu.com/knowledge/decision-receipts): What is in a Decision Receipt, and what does it prove?
- [The limits of verification](https://www.meshqu.com/knowledge/limits-of-verification): What does verifying a Decision Receipt actually prove?
- [What a receipt evidences about a responsible-AI commitment](https://www.meshqu.com/knowledge/responsible-ai-evidence): Can a Decision Receipt show that an AI decision was fair, accurate or correct?
- [Independent verification: the bundle, and what replay checks](https://www.meshqu.com/knowledge/independent-verification): How does someone independently verify a Decision Receipt, and what does replay check?

## Next step

[MeshQu trust model](https://docs.meshqu.com/security/trust-model)

Updated 11 September 2026
Machine-readable: https://www.meshqu.com/knowledge/evidence-and-source-custody.json
All reviewed answers: https://www.meshqu.com/knowledge
