Joopler docs

Verifiable evidence

Every artifact is signed, timestamped, and hash-chained, and anyone can verify it.

Most compliance tools ask you to trust their dashboard. Joopler makes the evidence itself provable.

How it works

Every collected artifact is:

  • Hashed, so any change is detectable.
  • Signed, so its origin is provable.
  • Independently timestamped (RFC 3161), so its time is provable.
  • Hash-chained into a tamper-evident ledger, so records cannot be reordered or removed without detection.

The public verifier

Anyone you share evidence with can confirm it is authentic and unaltered through the public verifier, without a Joopler account and without trusting us. Trust is inspectable, not asserted.

Public transparency log

The head of your ledger is periodically anchored with an independent timestamp and published to a public transparency log. This lets anyone catch after-the-fact edits: a buyer or auditor can record your ledger head today and later confirm the chain still leads to exactly that value, so history cannot be quietly rewritten. It is the same idea as a certificate-transparency log, applied to your compliance evidence.

OSCAL-native

The control catalog and your program export are OSCAL-native, so evidence and structure travel to auditors and government profiles in an open, standard format.