Stickybit← TelemetryPortuguêsTool · record · 2026
GIRDER · the record that cannot be erased

Trust lives in the key, not in the writer.

Every proof the other tools produce (TUBE's tolerance, SHORE's restore, PLUMB's time) becomes one line in a record that is chained, signed and time-stamped with proof. Editing, deleting or rewriting any line is caught by anyone who kept just the public key.

Specimen · the record of a real session, five lines

5/5lines checked
—first failure
—the proof that caught it
A, keptauditor's key

The kinds of line, the three attacks and where each one is caught come from the 19 Jul 2026 measurement. Line texts are simplified, and the fingerprint here is a simple function that runs in the browser; the product uses SHA-256 with Ed25519 signatures.

In everyday terms

A minute book with pages numbered and stitched.

Think of the minute book of a building association or a notary. Pages are numbered, stitched together, and each one gets a stamp. Tear out a page and the numbering shows a gap. Rewrite a page and you cannot reproduce the stamp.

One trick is left: someone with the whole book rewrites everything from scratch and stamps it with a fake stamp. Only a person who kept a copy of the real stamp beforehand will notice.

GIRDER does exactly this with mathematics. The numbering is each line's number. The stitching is the fingerprint of the previous line, written into the next one. The stamp is a digital signature. And the copy of the real stamp is the public key, which the auditor keeps.

p. 11p. 22p. 33p. 55p. 4 is missingeach page carries the previous stamp
The numbering exposes the missing page; the stitching exposes the swapped page; the stamp exposes whoever had no right to write.
How it works

What each line carries.

Every time a tool in the family finishes a check, it writes one line to the record. The line holds the number, the fingerprint of the previous line, what happened (the kind of check and its result), the time proven by PLUMB (an interval, for example ±10 ms), the fingerprint of all of that, and the signature.

A fingerprint is a short number computed from the content: change one comma and the whole number changes. Only the holder of the private key can sign, and that key stays with whoever produces the evidence (in production, in a key vault). Anyone checks the signature with the public key.

To audit, you run the verifier: it recomputes the fingerprints, checks the stitching, the numbering and the signatures, and returns 0 (intact) or 1 (rejected). The auditor does not need to trust the writer.

number4previous print9e1c…what happenedfreight · latewhen (PLUMB)19/07 ±10 mscontent print41af…signaturekey Aauditorpublic key A✓ redoes the prints✓ checks the stitching✓ checks the numbering✓ checks the signature0 intact1 rejected
One line of the record and what the auditor does with it. Values are examples.
What we measured

Three attacks, three different proofs.

On 19 July 2026 we gathered into one record the real journals of a working session: the telemetry monitor, SHORE's backup proof, a certified twin, PLUMB's clock attestation and a freight dossier. Each line was sealed and stamped with proven time (±10 ms). Verification with only the public key checked all five lines.

Then we attacked the record in three ways. Each attack was caught by a different proof, at the exact spot where it happened.

The third one is what matters: whoever controls the machine can rewrite and sign the whole record with a new key, and it "checks out" against that new key. Against the public key the auditor kept beforehand, it fails at the first line. Trust lives in the distributed key, not in the file.

the attackerrewrites everythingand signs with key Bchecked with key B✓ passes: all consistentchecked with key A,kept by the auditor✗ rejected at line 0
That is why the public key has to leave the building first: with the auditor, published, or anchored in an outside service.
AttackProof that catches itWhereIn practice
Edit the verdict of an old linethe fingerprint no longer matches the contentline 4nobody can "improve" a result after the fact
Delete the line of the backup that failedthe numbering skipsline 2what went wrong does not vanish from history
Rewrite everything and sign with another keythe signature fails against the kept public keyline 0not even whoever controls the machine can forge an accepted history

The same record accepts branches and merges, for AI agents that explore several hypotheses: each hypothesis becomes a branch, the chosen one becomes a merge, and the discarded ones stay sealed. That is exactly what gets disputed later.

Where to use it

Whenever someone will ask "prove it".

A good fit

  • Compliance and audit: the regulator re-derives the verdict without trusting you.
  • Disputes with customers or suppliers: what was measured, by whom and when, instead of word against word.
  • AI agents: it also keeps what was tried and discarded, not just the final answer.
  • The whole family: TUBE, SIEVE, CLAMP, PLUMB and SHORE seal here; it is the piece that joins them in the evidence platform.

Not enough on its own

  • If the result was wrong: the record proves it did not change, not that it was right. Each tool is responsible for its result.
  • If the auditor never got the legitimate key: an attacker can fabricate a whole consistent record.
  • Deleting the file: the record does not prevent it, it only exposes it. Write-once storage is an extra layer.
Three words on this page
Fingerprint

A short number computed from the content. Change one comma and the whole number changes.

Signature

A seal only the private-key holder can make, and that anyone checks with the public key.

Public key

The copy of the real stamp. It must be with the auditor before any dispute.

Limits

Where this could be wrong.

Proves integrity, not truth

It guarantees the line has not changed since it was signed. If the check that produced it was wrong, the mistake is well preserved.

The anchor is the key

Everything depends on the legitimate public key reaching the auditor by another route. In production: publish the key and periodically anchor the head of the record in an outside service.

One key in the test

We measured with a single key. Production needs key rotation, one key per producer and a key vault.

One measured session

The three attacks were tested on five lines of one session. It demonstrates the mechanism; it is not a statistic.

See also

← Certified telemetry · stickybit.com.br

Sources