Audit anchor proofs
Optional cryptographic integrity proofs for finalized reports and evidence — local verification first, public-chain submission on higher tiers.
Kiket treats anchor proofs as an integrity layer on top of PostgreSQL and file-backed configuration. They do not gate workflow execution, finding lifecycle, or report export.
What a proof verifies
- Canonical hash — Kiket fingerprints the subject (report snapshot, evidence record, or finding) with a stable JSON canonicalization and SHA-256.
- Local Merkle proof — Each proof stores a Merkle root and leaf proof so verifiers can confirm the subject hash was included without calling a blockchain.
- Optional chain submission — On Professional and Enterprise plans, pending proofs are submitted asynchronously to Polygon via the
AuditAnchorsmart contract (same deployment as Kiket 1.0) whenPOLYGON_RPC_URL,POLYGON_CONTRACT_ADDRESS, and a signing key are configured. Failures are recorded and retried; they never block cases or scans.
Unanchored data is still valid. Customers who only need in-product audit trails and exports can verify hashes locally without ever submitting to a chain.
On-chain contract
Kiket calls submitAnchor(bytes32 merkleRoot, uint256 leafCount, string organizationId) on the deployed AuditAnchor contract:
merkleRoot— SHA-256 subject hash (32 bytes)leafCount—1for single-subject platform proofsorganizationId— Kiket organization UUID
Independent verifiers can call verifyAnchor(merkleRoot) on the same contract address to read the anchor timestamp. Contract source lives in the monorepo under contracts/.
Product surfaces
| Surface | What you see |
|---|---|
| Audit Room | Explainer for unanchored vs local vs chain states; per-report verify and create-proof actions |
| Cases / findings / evidence | Status chips (Unanchored, Local proof, Chain pending, Chain anchored) |
| Platform API | POST /platform/anchors, GET /platform/anchors/{id}/verify |
| CLI / MCP / SDK | Same contract via kiket anchor patterns and kiket_create_anchor_proof / kiket_verify_anchor tools |
Legacy /blockchain/* batch endpoints were removed in Kiket 2.0 — use platform anchor proofs only.
Create a proof
curl -X POST https://api.kiket.dev/api/v1/platform/anchors \
-H "Authorization: Bearer $TOKEN" \
-H "X-Organization-Id: $ORG_ID" \
-H "Content-Type: application/json" \
-d '{
"subjectType": "report",
"subjectId": "REPORT_UUID",
"subjectHash": "SHA256_OF_REPORT_SNAPSHOT",
"requestSubmission": true
}'- Free / Starter —
requestSubmission: truestill creates a local proof (local_only) when the plan does not allow chain submission. - Professional / Enterprise — eligible proofs enter
pendinguntil the anchor submission worker recordsanchoredwith a transaction hash, orfailedwith an error message when chain credentials are missing.
Plan limits apply to anchor_proofs.retained per billing period (402 when exceeded).
Verify a proof
curl https://api.kiket.dev/api/v1/platform/anchors/PROOF_UUID/verify \
-H "Authorization: Bearer $TOKEN" \
-H "X-Organization-Id: $ORG_ID"The API recomputes the live subject hash (report snapshot, evidence, or finding) and checks the stored Merkle proof. When chain credentials are configured, you can also verify the Merkle root on Polygon by calling verifyAnchor on the AuditAnchor contract at POLYGON_CONTRACT_ADDRESS.
Environment
| Variable | Required for chain submission |
|---|---|
POLYGON_RPC_URL | Yes |
POLYGON_CONTRACT_ADDRESS | Yes — reuse existing Kiket 1.0 deployment |
POLYGON_PRIVATE_KEY or POLYGON_WALLET_PRIVATE_KEY | Yes |
Scope (intentionally narrow)
Kiket anchors finalized report hashes, evidence bundle hashes, and related integrity subjects — not every operational event, not identity, and not workflow state transitions on-chain. NFTs and token mechanics remain out of scope.