← Back

Build transparency

Confirm that the app you're using was built from our public source by an auditable, signed pipeline — not just a claimed commit hash.

Version
0.1.0
Source commit
50c8dd3322a1
Image
694992586161.dkr.ecr.eu-west-1.amazonaws.com/dmtrading-app@sha256:f74db4a33f4324206101bce290a672424edd729d0a93f32ae27158ecd11dd801
Built at
2026-09-21T21:05:11Z

Verify it yourself

With the GitHub CLI, this checks the signed provenance attestation binding the running image to the commit and workflow that produced it:

{@build.verify_command}

Front-end bundle fingerprints

The digested filenames embed each bundle's content hash — your browser downloads exactly these, so the front-end is verifiable end to end.

assets/css/app.css
assets/css/app-35329ee422df85db67f2295a4d1422c8.css
assets/js/app.js
assets/js/app-83a697448762f8333a92193dfb607561.js

What this does and doesn't prove

  • Verifiable: the container image was built by our GitHub Actions workflow from the commit above, and the front-end bundles your browser loads match that source.
  • Not proven here: exactly what the server process is executing. Proving that to a remote party requires trusted-hardware attestation; today it rests on this provenance chain plus operational trust.

Looking for plain-language answers about your funds and safety? See how it works & your safety.