# Independent verification: the bundle, and what replay checks

Canonical: https://www.meshqu.com/knowledge/independent-verification

How does someone independently verify a Decision Receipt, and what does replay check?

Where export is enabled, a verification bundle brings the receipt, policy snapshot and applicable proofs together for an offline check. Replay checks the recorded assessment against the supplied context and snapshot; it does not repeat the action. Signature checks require separately trusted keys obtained out of band. Included keys are informational. Confirm deployment export access before relying on it; general production availability is agreed per engagement.

## In more detail

A verification bundle can contain the signed receipt, policy snapshot, applicable chain and transparency proofs, evidence manifest and policy-approval records, plus an integrity manifest. The snapshot can be replayed against the supplied context. Required trust roots come from channels outside the bundle; included keys do not authenticate themselves. A check reports the relevant sub-claims and distinguishes valid, verified with caveats and failed. Integrity recomputation and signature verification are separate checks that work together. None of this establishes true inputs, authenticated actor identity, a correct decision or subsequent action execution. Export is conditional: where it is enabled for the deployment, the receipt and policy snapshot can be exported. The 17 July register's staging-on/production-off observation remains dated historical evidence and has not been upgraded into a fresh environment check.

## Limits

- Replay re-checks the recorded policy assessment. It does not repeat the real-world action and does not recreate a model's internal reasoning.
- The public keys included in a bundle are informational and are never used for authentication; trust roots must be obtained out of band.
- MeshQu's signing-keys endpoint is documented as deprecated and self-asserted, and must not be used as a trust root.
- Bundle export was recorded as enabled in staging and not enabled in production as of the 17 July 2026 register, and the verifier CLI was recorded as unpublished. Confirm availability before relying on it.
- What a successful check does and does not settle is a separate subject: see the limits-of-verification entry.
- Where export is enabled for your deployment, the receipt and policy snapshot can be exported for offline verification. Export enablement is a separate operating condition from the existence of the verifier and bundle format.

## Where it applies

- Where export is enabled, give an external reviewer the receipt, policy snapshot and applicable proofs for an offline check.
- Distinguish valid, verified with caveats and failed outcomes, and inspect which checks apply rather than treating them as one unconditional badge.

## Sources

- [MeshQu docs — Verification bundle](https://docs.meshqu.com/concepts/verification-bundle): What the bundle contains, the sub-claims an offline check reports, and the out-of-band trust-root requirement.
- [MeshQu docs — Concepts overview: Decision Receipt](https://docs.meshqu.com/concepts/overview#decision-receipt): The documentation owner's definition of the record being verified, including the policy snapshot that replay uses.
- [MeshQu docs — Trust model](https://docs.meshqu.com/security/trust-model): What the trust model assumes, read alongside the requirement that trust roots come from outside the bundle.
- [MeshQu docs — API reference: error codes](https://docs.meshqu.com/api/errors): The BUNDLE_EXPORT_DISABLED condition means export is not enabled for the tenant; availability is deployment-specific.

## Related answers

- [The limits of verification](https://www.meshqu.com/knowledge/limits-of-verification): What does verifying a Decision Receipt actually prove?
- [Decision Receipts: what the record contains](https://www.meshqu.com/knowledge/decision-receipts): What is in a Decision Receipt, and what does it prove?
- [What MeshQu does](https://www.meshqu.com/knowledge/what-meshqu-does): What does MeshQu actually do?

## Next step

[What a verification bundle contains](https://docs.meshqu.com/concepts/verification-bundle)

Read more on [docs.meshqu.com/concepts/verification-bundle](https://docs.meshqu.com/concepts/verification-bundle)

Updated 5 October 2026
Machine-readable: https://www.meshqu.com/knowledge/independent-verification.json
All reviewed answers: https://www.meshqu.com/knowledge
