← Back

Build transparency

Confirm that the app you're using was built from our public source by an auditable, signed pipeline — not just a claimed commit hash.

Version
0.1.0
Source commit
b3e27c493dc3
Image
694992586161.dkr.ecr.eu-west-1.amazonaws.com/dmtrading-app@sha256:89112cba8004b61e5b19ad6df82419e5d779e28dc917d2b33d729aa97337d117
Built at
2026-07-30T09:35:15Z

Verify it yourself

With the GitHub CLI, this checks the signed provenance attestation binding the running image to the commit and workflow that produced it:

{@build.verify_command}

Front-end bundle fingerprints

The digested filenames embed each bundle's content hash — your browser downloads exactly these, so the front-end is verifiable end to end.

assets/css/app.css
assets/css/app-3040e997efa170948da91608e72373c8.css
assets/js/app.js
assets/js/app-8b6b131bb1416a19577daf0c19bf5792.js

What this does and doesn't prove

  • Verifiable: the container image was built by our GitHub Actions workflow from the commit above, and the front-end bundles your browser loads match that source.
  • Not proven here: exactly what the server process is executing. Proving that to a remote party requires trusted-hardware attestation; today it rests on this provenance chain plus operational trust.

Looking for plain-language answers about your funds and safety? See how it works & your safety.