TRUST
Security architecture
DAHLIA prepares the evidence package and does not perform the verification. The sections below describe the product's trust boundaries: what sits where, what never touches the server, and where each control applies.
Open the live integrity checkDECLARED RESULT
4,97tCO₂e/t
Sample Plant · March 2027
- seal root
- bee6d1…937d
- knowledge time
- 30 September 2027
- approval
- TR-AK-ORNEK
Boundary of authority
Embedded emissions based on actual data are verified by an accredited verifier — Regulation (EU) 2023/956, Art. 8(1).
DAHLIA prepares the evidence package on which that verification rests. The separation of the party that prepares the evidence from the party that verifies it is a requirement of the system.
Prepares the evidence
DAHLIA
Sealed evidence package
Verifies
Accredited verifier
SEAL
Seal architecture
Each record is digested into its own leaf; the leaves combine in a binary tree and yield one seal root. A node left alone is not duplicated but promoted one level; duplication would allow two different packages to yield the same root.
RECORDS UNDER SEAL
- 01Declaration headerpackage identifier, installation, period, knowledge time
- 02Methodologythe rule under which it was calculated
- 03Input setwhich measurements, at which knowledge time
- 04Lineageevery step to the result
- 05Sourcesmeasurement, flow and supplier records
- 06Document bodythe raw bytes of the embedded document
SEAL ROOT OF THE SYNTHETIC SAMPLE PACKAGE
sha256:bee6d1edb484827bc0df35f81ea271bd30fc033537d8c9a9e04e4863482e937d
- seal format
- 5
- digest function
- SHA-256
- seal root
- bee6d1…937d
The serialisation and the tree shape are DAHLIA's own design; the primitives are standard (SHA-256, Ed25519, RFC 3161). The two reference implementations, TypeScript and Python, agree byte for byte across the golden vectors, and both are written by DAHLIA.
VERIFICATION WITHOUT THE DAHLIA SERVER
A period archive that carries its own verifier
Whoever holds the period archive can verify its seal offline, without the DAHLIA server.
- The digests and the seal root of the synthetic sample package are recomputed in the visitor's browser.
- No DAHLIA account is needed for verification.
- The period archive carries the verification script and its guide inside it.
THE SIGNING-KEY BOUNDARY
A signing key that stays with the person
The verifier's private signing key stays on the verifier's own device, never goes on the network and is never written to browser storage; the server only verifies the signature.
Held on the server
The public key, and verification of the signature
Held by the person
The private key, and signing
Holding the key on the server would mean that DAHLIA could sign on anyone's behalf; that option was considered and rejected.
LEDGER AND LINEAGE
Append-only ledger
Measurement and calculation facts are not deleted and are not silently updated; one value superseding another is recorded in the ledger as a fact of its own.
- In the bitemporal ledger, a fact's valid time and its knowledge time are kept apart.
- Every calculation step to the result is stored in the lineage and enters the seal.
- Tenant isolation is held by Postgres RLS; application code does not bypass it.
- A verifier sees only the records that its own grant covers.
- 01Doğal gazın enerji karşılığı0,69552 TJ
- 02Doğrudan emisyonlar (yakıt yanması)39,018672 tCO₂e
- 03Biyet gömülü emisyon yoğunluğu3 tCO₂e/t
- 04Öncül madde emisyonları72,3 tCO₂e
- 05Toplam gömülü emisyon111,318672 tCO₂e
RETENTION AND RECONSTRUCTION
Backup and time anchor
Off-site backups are uploaded under Object Lock in compliance mode, and the lock of every object is audited. The daily Merkle root is anchored to an RFC 3161 timestamp; the token is kept in the period archive together with its certificate chain.
Lock window
30–3650days
Lower and upper bound of the lock period, by tier.
Golden vectors
The fixed set of vectors over which the two reference implementations are compared byte for byte.
ACCESS MODEL
Access by invitation
An organisation is opened through an audited set-up procedure; later users join by invitation. Operator and verifier identities are separate; one identity cannot both produce the evidence and sign it.
Later users
- Invitation
- Account
- MFA
- Role
Integrity check of the synthetic sample package
The check runs on the home page, in the visitor's browser, and requires no DAHLIA account.
Inspect the sample package