Kiket docs
Compliance

Audit anchor proofs

Optional cryptographic integrity proofs for finalized reports and evidence — local verification first, public-chain submission on higher tiers.

Kiket treats anchor proofs as an integrity layer on top of PostgreSQL and file-backed configuration. They do not gate workflow execution, finding lifecycle, or report export.

What a proof verifies

  1. Canonical hash — Kiket fingerprints the subject (report snapshot, evidence record, or finding) with a stable JSON canonicalization and SHA-256.
  2. Local Merkle proof — Each proof stores a Merkle root and leaf proof so verifiers can confirm the subject hash was included without calling a blockchain.
  3. Optional chain submission — On Professional and Enterprise plans, pending proofs are submitted asynchronously to Polygon via the AuditAnchor smart contract (same deployment as Kiket 1.0) when POLYGON_RPC_URL, POLYGON_CONTRACT_ADDRESS, and a signing key are configured. Failures are recorded and retried; they never block cases or scans.

Unanchored data is still valid. Customers who only need in-product audit trails and exports can verify hashes locally without ever submitting to a chain.

On-chain contract

Kiket calls submitAnchor(bytes32 merkleRoot, uint256 leafCount, string organizationId) on the deployed AuditAnchor contract:

  • merkleRoot — SHA-256 subject hash (32 bytes)
  • leafCount — 1 for single-subject platform proofs
  • organizationId — Kiket organization UUID

Independent verifiers can call verifyAnchor(merkleRoot) on the same contract address to read the anchor timestamp. Contract source lives in the monorepo under contracts/.

Product surfaces

SurfaceWhat you see
Audit RoomExplainer for unanchored vs local vs chain states; per-report verify and create-proof actions
Cases / findings / evidenceStatus chips (Unanchored, Local proof, Chain pending, Chain anchored)
Platform APIPOST /platform/anchors, GET /platform/anchors/{id}/verify
CLI / MCP / SDKSame contract via kiket anchor patterns and kiket_create_anchor_proof / kiket_verify_anchor tools

Legacy /blockchain/* batch endpoints were removed in Kiket 2.0 — use platform anchor proofs only.

Create a proof

curl -X POST https://api.kiket.dev/api/v1/platform/anchors \
  -H "Authorization: Bearer $TOKEN" \
  -H "X-Organization-Id: $ORG_ID" \
  -H "Content-Type: application/json" \
  -d '{
    "subjectType": "report",
    "subjectId": "REPORT_UUID",
    "subjectHash": "SHA256_OF_REPORT_SNAPSHOT",
    "requestSubmission": true
  }'
  • Free / Starter — requestSubmission: true still creates a local proof (local_only) when the plan does not allow chain submission.
  • Professional / Enterprise — eligible proofs enter pending until the anchor submission worker records anchored with a transaction hash, or failed with an error message when chain credentials are missing.

Plan limits apply to anchor_proofs.retained per billing period (402 when exceeded).

Verify a proof

curl https://api.kiket.dev/api/v1/platform/anchors/PROOF_UUID/verify \
  -H "Authorization: Bearer $TOKEN" \
  -H "X-Organization-Id: $ORG_ID"

The API recomputes the live subject hash (report snapshot, evidence, or finding) and checks the stored Merkle proof. When chain credentials are configured, you can also verify the Merkle root on Polygon by calling verifyAnchor on the AuditAnchor contract at POLYGON_CONTRACT_ADDRESS.

Environment

VariableRequired for chain submission
POLYGON_RPC_URLYes
POLYGON_CONTRACT_ADDRESSYes — reuse existing Kiket 1.0 deployment
POLYGON_PRIVATE_KEY or POLYGON_WALLET_PRIVATE_KEYYes

Scope (intentionally narrow)

Kiket anchors finalized report hashes, evidence bundle hashes, and related integrity subjects — not every operational event, not identity, and not workflow state transitions on-chain. NFTs and token mechanics remain out of scope.

On this page