Home / Registry / Certificate
Certificate · Ed25519 · verified

Certificate

A signed certificate for Bain Operations - SCM US, US·SCM·SMB, 2026-Q2. Its signature is checked below against the committed public key — no trust in this site required.

Signature verifies

The signature is valid for this record under the public key below, checked at build time with Ed25519. Altering any field would break it. Key publishing key · ed25519. The publishing key is issued per GOVERNANCE §3.

The record

A certificate restates a computed position. These are the fields the signature covers — nothing here is set by hand.

Registry id
CNST-2026-Q2-US-SCM-SMB-R02-F3BE
Firm
Bain Operations - SCM US · bain-scm-us
Table
US · SCM · SMB
Period
2026-Q2
Rank
R02
Score
95.74
Rules version
v1.1
Dataset
snapshot/2026-Q2

Step 1 — the canonical payload

The record is reduced to one, and only one, byte encoding: keys sorted, numbers rounded, compact separators (engine/canonical.py). This is what is signed, so the same record yields the same bytes on any machine.

{"category":"SCM","dataset_tag":"snapshot/2026-Q2","firm":"bain-scm-us","firm_name":"Bain Operations - SCM US","geo":"US","milestone":null,"period":"2026-Q2","rank":2,"registry_id":"CNST-2026-Q2-US-SCM-SMB-R02-F3BE","rules_version":"1.1","score":95.74,"tier":"smb"}

Step 2 — the signature and public key

The key signs the canonical payload with Ed25519; the signature and the public half of the key travel with the record. Only the public key is committed — private keys never enter the repository.

Algorithm
ed25519
Signature
5df2e326a67cb3cf212b6ecf95e80fbc23e537fcc5e0cde0a5cb1d6ccfb695b9d4293bc4ac5075e9c4f620ba02897ccfe377b59469c4404d629622c018681104
Public key
f3df0e590092d318ce6e4bc92676d4b9ec3111d173bd1c56809f68047a57f6bf

Step 3 — check it offline

With the record, the signature, and the committed public key, verification needs no network and no trust in this site. Reconstruct the payload with the engine and check the signature:

python -c "import json,sign; from schemas import AwardRecord; \
r=AwardRecord.model_validate(json.load(open('CNST-2026-Q2-US-SCM-SMB-R02-F3BE.json'))); \
print(sign.verify_award(r))"
# → True  (or False)

A passing check confirms the record was signed by the committed key and has not been altered by a single byte. The signature authenticates the record; it is not part of the computation, so determinism holds with or without it.