Cryptographic verification of the entire Secure Controls Framework. Every number computed, every hash anchored, every claim provable.
The Secure Framework Verification Token is a fully automated system that watches the Secure Controls Framework's entire GitHub repository. One commit from SCF triggers our pipeline —and it doesn't stop until every piece of data is hashed, verified, anchored on-chain, and emailed to the team.
The original source data is blockchain-recorded the moment it's downloaded. Every piece of data we extract and derive is also hashed and anchored independently. After the main pipeline finishes, a fully separate audit system re-reads only the original source PDFs, builds its own Merkle tree, and compares it against the main track.
Two independent systems. Same source. Same answer —or the pipeline refuses to produce output.
The full processing pipeline. Every step is hashed into a 7-block chain producing a Merkle tree over every verified count (27 leaves in the anchored 2026.1.1 release; 31 in the sealed 2026.2 release). Source data, extracted data, derived data —all hashed and anchored independently.
An entirely separate system reading only the original STRM PDFs. It produces its own independent Merkle root. If the two roots don't match, the pipeline refuses to output.
SCF published release 2026.2 on July 8, 2026 and restructured their distribution entirely — every mapping PDF moved off GitHub onto their CDN. The pipeline rebuilt itself around the new format and processed the full release: 249 STRM mapping documents (up from 185), 83,367 verified mapping rows, 1,534 controls across 34 domains (including the new Quantum Security domain), 252 frameworks.
Extraction flagged 875 rows across 38 documents. Every single one was reviewed against the rendered PDF page — no text extraction, no guessing. Result: 842 were extraction artifacts (removed), 13 were real mappings recovered from the page, and 20 are cells SCF left blank in their own PDFs — documented as upstream gaps, never filled in. Nothing is sealed until this review is complete.
Every PDF is also converted through Nutrient's open pdf-to-markdown and compared row-by-row against the pipeline extraction. Across 60,000+ compared rows the two independent readers agreed on 99.94% of values, and every apparent disagreement adjudicated to duplicate rows in the source — zero extraction errors found.
Merkle root over all 31 verified counts:b6b247ae6d8b385b3cb144514241d32a061ac12908d78a057e40913b181b4a2c
On-chain anchoring follows with the next-generation SFVT contract; the live on-chain numbers on this page reflect the anchored 2026.1.1 release until then.
We found the one broken download link in SCF's 2026.2 workbook, corrected it with an auditable errata record, and opened a pull request offering SCF the complete verified PDF set back. A permanent provenance mirror lives at scf-strm-mirror.
Every number is computed, verified, and permanently anchored to a public blockchain. The pipeline checks the data. An independent audit checks the pipeline. The blockchain checks the audit. Three layers deep, each one watching the one before it. There are no estimates, no approximations, no assumptions carried forward on good faith. If it cannot be proven, it is not claimed. If it cannot be reproduced, it is not published. Every hash, every count, every verification checkpoint exists because the alternative was trusting someone's word —and we chose math instead.
Milestones hit, what's in progress, and what's next. The full trajectory from Base L2 anchoring to a sovereign compliance blockchain.
Source acquisition through final validation — every step computed, hashed, and anchored. Watch it run live.
ZK proofs, auditor networks, evidence chain of custody, sovereign compliance chains. What becomes possible once the verification layer exists.
Submit a feature idea, integration request, or something we haven't thought of yet.