Verify an assessment

Independent check · no account needed

If someone has handed you an ASIScan assessment report, this page confirms whether it is genuine, unaltered and still current — without you having to take their word for it, or ours.

Step 1 — enter the report ID

Printed in the Provenance section of the report, in the form P42-XXXX-XXXX.

What this page does and does not show

The registry stores a cryptographic hash of each countersigned report, its issue and expiry dates, and its status. It does not store the name of the assessed company, the scope, or any findings. That is deliberate: a public registry listing customers would itself be a disclosure, and no organisation would consent to appear in one.

The hash is enough. It covers the entire document, including the company name printed inside it, so a matching hash proves both that the report is one we issued and that not a single character has been changed since.

Reading the result

ValidIssued by Protocol 42 and still within its currency period.
ExpiredGenuine, but past its stated currency date. Assessments describe one commit at one moment; reviewers generally expect evidence dated within the last 6–12 months.
RevokedWithdrawn by Protocol 42 — for example because a material error was found after issue. Do not rely on it.
Not foundNo such ID. Either a typo, or the document was not issued by us.

Self-assessed reports

ASIScan is open source, and anyone may run it and generate a report about their own code. Those reports are watermarked "Self-assessed — not independently verified" and carry no report ID, because nobody outside the assessed organisation has reviewed them. They are perfectly legitimate as an internal engineering artifact. They are not third-party evidence, and this page will not confirm them as such.

Questions about a specific report — hello@protocol42.io