Back to How it works

Attestation Record

tg.attestation · schema 1.0

Attestation Record

Cryptographically signed chain-of-custody artifact for one object transferred between cloud providers.

tg_id: 26e0e72027abd4501c4bf5ced83dbb85b1e6b4fc70495b662922fd839b12c391
Verification passed
6 PASS · 0 WARN · 0 FAIL
● FINAL STATE: COMPLETE — ATTESTED
Attestation scope. Transfer General attests only to operations executed within the TG-controlled pipeline — from the moment TG read this object at the source through the moment it signed this record after the destination write was confirmed. TG does not attest to the object’s prior history, who placed it in the source bucket, or events outside the TG pipeline. Those facts are the customer’s accountability layer. Two categories of customer-supplied content appear in the signed payload: customer-declared fields entered at deployment, recorded verbatim but not verified by TG.
§1Subject & Pipelinewhat was transferred · between where
Subjectin signed payload
Object namepatient001_study002_series05_img010.dcm
Size256.0 MB (268,444,629 bytes)
Content hashSHA-256: 7756cef737283c3232dfd806…
Source ETagCOGq1++cnJUDEAE=
Destination ETag"4e2ab3115963d7378ffe43d8a5cef3b0-26"
Pipelinein signed payload
Pipelineaws-gcp
RouteAWS (us-east-2) → GCP (us-central1)
Pipeline ID03f8d448-4563-453b-a6ed-b6b3fc7d83f0
Source bucketaws://tg-7c4f1e-aws-gcp-source
Destination bucketgcp://tg-7c4f1e-aws-gcp-dest
§2Integrity Verificationthe hash that the destination must match
Hash comparisonintegrity anchor
AlgorithmSHA-256 (NIST FIPS 180-4)
Source hash7756cef737283c3232dfd80639d6…
Destination hash7756cef737283c3232dfd80639d6…
Match✓ hash_match = true
EncryptionFIPS-validated
AlgorithmAES-256-GCM
FIPS postureAll crypto operations performed by the OpenSSL FIPS Provider, CMVP certificate #4985 (FIPS 140-3, Level 1)
Crypto librarycryptography 46.0.7 / OpenSSL 3.1.2 1 Aug 2023 (FIPS provider enabled)
PatternEnvelope (encryption key wrapped by customer’s KMS)
§3Key Managementcustomer encryption key · customer ASK
KMS encrypt (source)evidence row
ProviderGCP
AlgorithmSYMMETRIC_DEFAULT
Key IDprojects/meridian-health-prod/locations/us-central1/keyRings/tg-7c4f1e-keyring/cryptoKeys/tg-7c4f1e-key/cryptoKeyVersions/1
Called at2026-09-14T21:49:58.417673+00:00
KMS decrypt (destination)evidence row
ProviderGCP
AlgorithmSYMMETRIC_DEFAULT
Key IDprojects/meridian-health-prod/locations/us-central1/keyRings/tg-7c4f1e-keyring/cryptoKeys/tg-7c4f1e-key
Called at2026-09-14T21:51:13.433184+00:00
Attestation signing key (ASK)in signed payload · owned by the customer, in the customer's own KMS
AlgorithmEC_SIGN_P384_SHA384
Key IDprojects/meridian-health-prod/locations/us-central1/keyRings/tg-keyring/cryptoKeys/tg-attestation-signing-key/cryptoKeyVersions/1
Public key fingerprintSHA-256: b0d7ce9c0cf19d76da0b16fbf04d16077b26824abbe2a8c8c359d572e2f7f495
Payload digestSHA-256: 95337201177964715e151a5f5f4ca5760c45cc391dc41779e4660a71abc3b4e5
CanonicalizationRFC 8785 / JCS
Signature sequence1
Context tagTG-ATTESTATION-V1
§4Transfer Timeline22 events · 21 evidence rows · 1m 25.999s under operational custody
1Encryption at SourceAWS · us-east-2 · source → staging
Content hash computed21:50:04.655
Integrity record written21:50:04.817
Encryption key wrapped (KMS)21:50:04.950
Encrypted object written to staging21:50:05.222
Source object removed21:50:05.396
Operation completed21:50:05.527
2Cross-Cloud Transferstaging → landing · object encrypted throughout
Integrity record read21:50:15.534
Integrity record written21:50:15.948
Object transferred21:50:24.645
Staging copy removed21:50:24.826
Operation completed21:50:24.982
3Decryption at DestinationGCP · us-central1 · landing → destination → sign
Integrity record read21:51:11.930
Encryption key unwrapped (KMS)21:51:20.931
Content hash recomputed21:51:20.973
Content hash verified21:51:21.198
Object written to destination21:51:21.280
Encrypted copy removed21:51:21.457
Operation completed21:51:21.497
Attestation recorded21:51:21.865
Time-ordered events recorded by TG at the moment each occurred. Marker rows denote KMS operations, the integrity anchor, and the signing event. All 21 evidence rows appear in the signed payload, each individually Merkle-proven in the immutable ledger.
§5Immutability Anchordefense in depth · independent of TG’s signature
immudb ledger anchordefense in depth
Ledger / tx_id at signingtgaudit / 1648
Prior checkpoint tx_id1084 (signed by immudb + KMS)
Evidence rows21 (all chain-linked via Merkle hashes)
immudb state signatureSHA-256: 688d0025b30972300705… (server-signed; key cross-checked against KMS-signed checkpoint)
Beyond the ECDSA signature, the record is anchored in an append-only immudb ledger that produces its own cryptographic state — verifiable even by an auditor who distrusts the appliance. The ledger’s prior checkpoint (tx_id 1084) is itself signed by both immudb and the cloud KMS.
§6Accountabilitycustomer-declared · TG-observed
Customer-declareddeclared at deployment
Initiating organizationMeridian Health Network
Authorized byA. Whitfield
RoleVP, Information Security
Authorization basisHIPAA Data Movement Policy SEC-001
Authorization date2026-05-01
TG records these declarations verbatim and does not verify their accuracy. The customer is solely responsible for their truth.
TG-observedobserved at sign time
Pipeline nameaws-gcp
Pipeline ID03f8d448-4563-453b-a6ed-b6b3fc7d83f0
Deployment date2026-05-23T00:12:00Z
tg_id26e0e72027abd4501c4bf5ced83dbb…
Cloud context & execution identityTG-observed · from cloud metadata APIs
Source provider / accountAWS · 441903772074 · us-east-2
Destination provider / accountGCP · meridian-health-prod · us-central1
TG identity (source)arn:aws:iam::441903772074:role/tg-7c4f1e-worker-role
TG identity (destination)tg-7c4f1e-worker@meridian-health-prod.iam.gserviceaccount.com
§7Verify Independentlyoffline · cloud-native
Level 1 — Portable (offline ECDSA)
Reconstruct the signing input from the canonical payload, schema version, and context tag; verify against the ASK public key with any standard ECDSA library. No network call. Suitable for long-term archival.
# offline, no Server General contact
node tg/verify.mjs --bundle ./attestation-bundle \
  --pubkey sg-public-key.pem \
  --checkpoint checkpoint.json
Level 2 — Authoritative (cloud-native)
Call the originating cloud’s KMS Verify API against the ASK key resource. Returns a cloud-native verification receipt — legally defensible for formal compliance proceedings.
# cloud-native receipt
gcloud kms asymmetric-signature verify \
  --key tg-attestation-signing-key --version 1 \
  --input-file payload.bin \
  --signature-file sig.bin
Evidence completeness: this attestation contains all TG-recorded events for this object transfer — none omitted, summarized, or redacted from the canonical payload.
Generated automatically by Transfer General at transfer completion. One signed attestation per object. The canonical JSON is the authoritative artifact; this report is a viewer.
Representative sample — infrastructure identifiers redacted.   tg.attestation 1.0 · EC_SIGN_P384_SHA384 · RFC 8785 / JCS
{
  "schema": "tg.attestation",
  "context_tag": "TG-ATTESTATION-V1",
  "attestation_version": "1.0",
  "attestedAt": "2026-09-14T21:51:21.865439Z",
  "nonce": "a0808468746d129bd5a449694b5c0202eb0d242f751dab039650e332f843a629",
  "installation": {
    "installationId": "tg-7c4f1e",
    "applianceUrl": "https://tg-appliance.meridian.internal:8443"
  },
  "pipeline": {
    "pipelineId": "03f8d448-4563-453b-a6ed-b6b3fc7d83f0",
    "label": "aws-gcp",
    "from": "gcp",
    "to": "aws",
    "fromRegion": "us-east-2",
    "toRegion": "us-central1",
    "sourceBucket": "tg-7c4f1e-aws-gcp-source",
    "stagingBucket": "tg-7c4f1e-aws-gcp-staging",
    "landingBucket": "tg-7c4f1e-aws-gcp-landing",
    "destBucket": "tg-7c4f1e-aws-gcp-dest"
  },
  "accountability": {
    "customer_declared": {
      "initiating_organization": "Meridian Health Network",
      "authorized_by": "A. Whitfield",
      "role": "VP, Information Security",
      "authorization_basis": "HIPAA Data Movement Policy SEC-001",
      "authorization_date": "2026-05-01"
    },
    "tg_observed": {
      "pipeline_name": "aws-gcp",
      "pipeline_id": "03f8d448-4563-453b-a6ed-b6b3fc7d83f0",
      "deployment_date": "2026-05-23T00:12:00Z",
      "cloud_context": {
        "source": {
          "provider": "aws",
          "account_id": "441903772074",
          "region": "us-east-2"
        },
        "destination": {
          "provider": "gcp",
          "account_id": "meridian-health-prod",
          "region": "us-central1"
        }
      },
      "tg_execution_identity": {
        "source": "arn:aws:iam::441903772074:role/tg-7c4f1e-worker-role",
        "destination": "tg-7c4f1e-worker@meridian-health-prod.iam.gserviceaccount.com"
      }
    }
  },
  "subject": {
    "tgId": "26e0e72027abd4501c4bf5ced83dbb85b1e6b4fc70495b662922fd839b12c391",
    "objectKeyAtSource": "patient001_study002_series05_img010.dcm",
    "objectKeyAtDest": "patient001_study002_series05_img010.dcm",
    "sourceEtag": "COGq1++cnJUDEAE=",
    "destEtag": "\"4e2ab3115963d7378ffe43d8a5cef3b0-26\"",
    "source_hash": "7756cef737283c3232dfd80639d60a5d184e1db727576ade8eeb249afc2e1fad",
    "destination_hash": "7756cef737283c3232dfd80639d60a5d184e1db727576ade8eeb249afc2e1fad",
    "hash_match": true,
    "contentHashAlgorithm": "SHA-256",
    "bytes": 268444629,
    "bytesHuman": "256.0 MB (268,444,629 bytes)",
    "transfer_started_at": "2026-09-14T21:49:55.866875Z",
    "transfer_completed_at": "2026-09-14T21:51:21.497294Z"
  },
  "cryptoPosture": {
    "encryptionAlgorithm": "AES-256-GCM",
    "fipsValidated": true,
    "fipsPostureDescription": "All crypto operations performed by the OpenSSL FIPS Provider, CMVP certificate #4985 (FIPS 140-3, Level 1)",
    "cryptoLibrary": "cryptography 46.0.7 / OpenSSL 3.1.2 1 Aug 2023 (FIPS provider enabled)",
    "pattern": "Envelope (encryption key wrapped by customer’s KMS)"
  },
  "immudbAnchor": {
    "db": "tgaudit",
    "txIdBeforeSigning": 1648,
    "txHashBeforeSigningHex": "86a13b8265ad28d2b3283494513472f956ed03f5bf82033b9574db6ca610768c",
    "txIdAfterSigning": 1648,
    "txHashAfterSigningHex": "86a13b8265ad28d2b3283494513472f956ed03f5bf82033b9574db6ca610768c",
    "serverSignatureB64": "MEUCICEDeSjnmguwtx73APgTynwSULH6yqsNbgoY\u2026",
    "serverPublicKeyB64": "BMFnD485hFsOz1BRRDxCcR/k7FR/ZcrdmQG7jupG7xuvo5ZcqEUvfm1AsutchXdjWxovRTjHkeGDbDY+94rAtYQ="
  },
  "evidence": [
    {
      "timestampUs": "2026-09-14T21:49:55.866875Z",
      "event": "ENCRYPT_START",
      "severity": "AUDIT",
      "data": {
        "dst": "aws://tg-7c4f1e-aws-gcp-staging/patient001_study002_series05_img010.dcm.aes256",
        "sourceEtag": "COGq1++cnJUDEAE=",
        "src": "aws://tg-7c4f1e-aws-gcp-source/patient001_study002_series05_img010.dcm"
      },
      "chainHash": "5ec365a104e7d26442635b7eef02c754fa4533d36b463e4f891b86fea06add5c",
      "proofB64": "CpgFCMMJEosCAk0uAAAAAgAAAACAA/jUSEVjRTum7baz\u2026 [truncated]"
    },
    {
      "timestampUs": "2026-09-14T21:50:04.655324Z",
      "event": "KMS_ENCRYPT",
      "severity": "AUDIT",
      "data": {
        "dst": "aws://tg-7c4f1e-aws-gcp-staging/patient001_study002_series05_img010.dcm.aes256",
        "kms": "{'algorithm': 'SYMMETRIC_DEFAULT', 'bulkCipher': 'AES-256-GCM', 'cryptoLibrary': 'cryptography 46.0.7 / OpenSSL 3.1.2 1 Aug 2023', 'fipsEnabled': True, 'keyId': 'projects/meridian-health-prod/locations/us-central1/keyRings/tg-7c4f1e-keyring/cryptoKeys/tg-7c4f1e-key/cryptoKeyVersions/1', 'operation': 'encrypt', 'provider': 'gcp', 'timestamp': '2026-09-14T21:49:58.417673+00:00'}",
        "src": "aws://tg-7c4f1e-aws-gcp-source/patient001_study002_series05_img010.dcm"
      },
      "chainHash": "beaa539eb2da275690f261b8fc9c442edb10bbfdbebb33f709f3b0c5fd1b5c69",
      "proofB64": "CuQHCMwJEosCAk0uAAAAAgAAAACAA/jUSEVjRTum7baz\u2026 [truncated]"
    },
    "\u2026 19 more rows (full bundle in download)"
  ],
  "checkpointAnchorPriorTxId": 1084,
  "attestedSequenceNumber": 1,
  "signature": {
    "algorithm": "EC_SIGN_P384_SHA384",
    "keyResourceName": "projects/meridian-health-prod/locations/us-central1/keyRings/tg-keyring/cryptoKeys/tg-attestation-signing-key/cryptoKeyVersions/1",
    "publicKeyFingerprintSha256": "b0d7ce9c0cf19d76da0b16fbf04d16077b26824abbe2a8c8c359d572e2f7f495",
    "payloadSha256": "95337201177964715e151a5f5f4ca5760c45cc391dc41779e4660a71abc3b4e5",
    "sig": "MGQCME07/ExxQzvsf/WmwKowb1uJv6UF4CthTrPxKaUNNxeo\u2026",
    "canonicalization": "RFC8785/JCS"
  }
}
Representative redacted sample. The full canonical JSON — all 21 evidence rows with Merkle proofs — is the authoritative artifact and downloads with the bundle.
Verification passed.
6 PASS · 0 WARN · 0 FAIL · the appliance ran tg/verify.mjs
StatusCheckDetail
PASSsignatureECDSA P-384 / SHA-384 against EC_SIGN_P384_SHA384
PASSchain integrity21 rows; head matches last row’s chain_hash
PASSmerkle proofs21/21 rows verified via VerifiableSQLEntry
PASSimmudb state signatureanchor + 21 rows; immudb key sha256=acb5bf7ded4ddb1e…; key cross-checked against KMS-signed checkpoint
PASSprior-checkpoint anchortx_id 1084, signed by immudb + KMS
PASSschema sanitytg.attestation
Note: this verifier runs on the appliance itself, so it confirms the artifact is internally consistent but cannot prove the appliance is not tampering with its own output. For independent verification, download the bundle and run node tg/verify.mjs <bundle-dir> on an outside machine.