HOW 170TARV WORKS
A record you can
trace and verify.
Cryptographic verification proves that captured evidence has not changed. It does not prove the upstream system was truthful.
Connect with least privilege
170tarv connects through vendor APIs using OAuth, API credentials, service principals or webhook secrets. It is not installed inside your infrastructure. Scheduled, read-only collection is the default; supported webhooks can complement it.
Preserve before interpreting
- Wrap the source record in a SourceEnvelope.
- Store the raw payload unchanged in R2.
- Generate a SHA-256 hash and record source, capture time and connector provenance.
- Normalise into a separately hashed EvidenceEvent in PostgreSQL.
- Link identities, assets, customers, incidents, controls and obligations.
- Core provides standard signed readiness reports and manifests. Reports can be downloaded with unique 170tarv codes. Verification looks up the official signed record by code; an optional SHA-256 checks a report copy. Blackbox adds advanced signed bundles and independent verification packages.
Keep human decisions visible
Timelines distinguish source, observed, ingested and decision times. Human notes explain decisions. Reporting clocks and obligations remain traceable to their inputs.
Three separate security zones
This public website has no customer data or privileged session. Customers use app.170tarv.com for their own workspace. Internal operations use separate staff authentication, mandatory MFA and audited, time-limited access to customer evidence.
What the proof says
“This is what we captured, from this source, at this time, under this connector, and it has not changed since.”
Source completeness, source accuracy and legal interpretation still need human assessment. External verification checks the captured record and its manifest.