The finding is only as strong as the record that proves it.
Custody and verification is the course that makes the difference between a finding and an allegation. A practitioner who cannot read the custody record, replay the retrieval and produce the accompanying documentation cannot present a finding in a proceeding — regardless of how correct the finding is.
LLX-ACADEMY-CRS-03 · R1
This course is required at every level.
Custody and verification is the only course that is required for all three certification levels — operator, analyst and expert. The custody record is the foundation of every finding at every level. This course must be passed before any certification level can be granted.
No prior certification required
This course can be taken at any point in the Academy curriculum. However, practitioners who take it before prompt craft may find some practicum exercises harder without the retrieval context.
Access to a sealed corpus
The practicum exercises require a live sealed corpus. The custody record exercises require the corpus to have been through at least one full ingestion cycle so that seals are present.
What the custody record contains and what each field proves.
The PARALLAX RC® custody record is an append-only log that records every ingestion event, every seal, every retrieval and every operator action. This session teaches the structure of the record and what each field is legally and technically capable of proving.
Ingestion events
The ingestion event record: file path, file hash, handler version, ingestion timestamp, hardware marker. What the hardware marker proves (the environment) and what it does not prove (the content of the file before ingestion).
Passage seals
The passage seal record: passage_id, byte_start, byte_end, sha512, ingestion_event_id. The chain from passage seal to ingestion event to file hash. How the chain is followed to verify that a passage came from a specific file in a specific state.
Retrieval records
The retrieval record: retrieval_id, query_plan, result_set_hash, operator_id, timestamp. What the result_set_hash proves: the full result set at that moment. How to use the retrieval record to replay a retrieval.
The append-only guarantee
The custody record cannot be edited, only extended. What this means for the integrity of a finding: once a retrieval is recorded, it cannot be removed. What happens if a finding is found to be in error after the fact.
The digest is a proof. Know what it proves.
Every sealed entity in PARALLAX RC® — file, passage, retrieval, ingestion event — carries a SHA-512 digest. This session teaches the practitioner to read, verify and present each type of digest, and to explain in plain terms what the digest proves and what it does not.
File digest
The file digest is computed over the full binary content of the file as it was read by the handler. It proves that the file at the time of ingestion had that exact content — not that the file was not modified before ingestion.
Passage digest
The passage digest is computed over the byte range. It proves that the passage at positions byte_start to byte_end in the file with digest file_hash had that exact content. Practicum: verify a passage digest against the source file.
Retrieval digest
The retrieval digest is computed over the full result set. It proves that the result set for that retrieval_id contained exactly those passages in that order at that timestamp. How to use it to prove a result set has not been altered.
Presenting digests to non-technical audiences
How to explain what a SHA-512 digest proves in plain terms — to a tribunal, to an opposing expert, to a client. What questions to expect and how to answer them without overstating or understating the proof.
Any certified practitioner should be able to replay your retrieval.
Replaying a retrieval means running the same query against the same sealed corpus version and verifying that the result set matches the recorded retrieval digest. This session teaches the practitioner to perform a replay, to record the replay, and to present the replay record as part of a finding.
Locating the retrieval record
How to find a specific retrieval in the custody record using the retrieval_id. How to extract the query plan from the retrieval record for re-execution.
Re-executing the query plan
Running the extracted query plan against the same sealed corpus version. How to verify that the corpus version is the same: matching the corpus-level ingestion hash.
Verifying the result set
Computing the result_set_hash of the re-executed result and comparing it to the recorded value. If they match, the replay is successful. If they do not, the course teaches how to diagnose why.
Recording the replay
A replay itself becomes a new entry in the custody record. The replay record: original_retrieval_id, replay_timestamp, operator_id, result_set_hash_match. Practicum: perform a full replay and produce the replay record.
The document that accompanies the finding.
A finding produced with PARALLAX RC® must be accompanied by a custody document that a tribunal, an opposing expert or a supervising authority can use to verify the finding independently. This session teaches the practitioner to produce that document.
The custody document structure
What the custody document must contain: the retrieval_id, the corpus version hash, the query plan, the result_set_hash, the passage citations, the operator certification identifier and the examination date.
What the document asserts
How to write the assertion: the practitioner asserts that the passages listed in this document were retrieved from the sealed corpus identified by [hash], using the query plan recorded in retrieval [id], at [timestamp], and that the retrieval can be replayed by any practitioner with access to the same sealed corpus.
What the document does not assert
The custody document does not assert that the finding is correct — only that the retrieval is verifiable. The forensic judgment of what the passages mean is separate from and subsequent to the custody documentation.
Presenting the document
How to introduce the custody document in a proceeding. Typical questions from opposing counsel and how to answer them. What to do if the opposing party claims the corpus was modified after ingestion.
Produce a custody document for a given retrieval.
The assessment provides a sealed examination corpus with a set of pre-recorded retrievals. The practitioner selects one retrieval, replays it, verifies the result, and produces a complete custody document. The examiner independently replays the same retrieval and verifies the document.
Replay execution
The practitioner locates the retrieval in the custody record, extracts the query plan, re-executes it and computes the result_set_hash. The hash must match the recorded value.
Custody document production
The practitioner produces the custody document in the required format. The document must include all required fields. Omission of any required field is a failing submission.
Examiner verification
The examiner independently replays the retrieval and verifies the custody document against the replay result. The practitioner must be available to answer questions about any field in the document.
Custody and verification is required for all three certification levels.
Passing custody and verification is a prerequisite for the Certified operator, Certified analyst and Certified expert examinations. No certification can be granted without it. It is the course that turns a retrieval into evidence.