Case study · 2026-05-06

SSI under stress.

The SSI Protocol™ defines four guarantees every conformant implementation must satisfy. On 2026-05-06, application code in DeAlgo's portal mutated a signed audit-chain column, breaking one row's chain hash. This page records what each guarantee did under that stress — what it exercised in production, what would have failed without it, and the verdict.

Read the full operational narrative on the trust page. This page is the structured proof, not the story.

Outcome summary

Detected
2026-05-06 04:11 UTC
Resolved
2026-05-06 05:48 UTC
Time-to-detect
< 1 second after mutation
Time-to-diagnose
~20 minutes
Affected rows
1 of 313
Downstream corruption
None — chain halted at the mutation row
Data loss
None
Customer trust property
Preserved end-to-end

Per-guarantee performance

One row per guarantee. The protocol claim isn't that guarantees never get tested — it's that when they are tested, their behavior is observable and reproducible.

Tamper-evident hash chain

Exercised · worked
What the incident exercised

The boot-time integrity walk recomputed sha256((previousHash ?? "") + "\n" + canonical(row)) for every row in scope. The mutated row's recomputed value disagreed with its stored chainHash byte-for-byte.

Without this guarantee

The mutation would have propagated silently. Subsequent rows would have linked to a tampered predecessor; replay and reconciliation queries would have returned results that didn't match what was actually committed. The first place the inconsistency would surface would have been during an external audit.

Fail-closed defaults

Exercised · worked
What the incident exercised

The integrity walk treated disagreement as a structural impossibility, not a warning. The workspace returned 503 to writes the moment the mismatch was detected. No row was written into a chain whose continuity could not be reproduced.

Without this guarantee

Writes would have continued accepting new rows on top of a broken chain. Each new row would have been auditable individually but the chain-of-custody property of the workspace as a whole would have silently degraded.

Human authority preservation

Exercised · worked
What the incident exercised

Recovery was gated on explicit operator authorization at every step. The repair script refuses to write unless its reconstruction of the originally-signed bytes reproduces the stored chainHash exactly; the dry-run is mandatory; the production write required a separate explicit approval after the dry-run printed MATCH.

Without this guarantee

An auto-remediation system could have rewritten history to make the chain look intact again. The protocol's trust property would be reduced to 'we promise we didn't tamper with it.'

Independent verification

Exercised · worked
What the incident exercised

The decision-detail page's 'Verify this row' button reproduced the diagnosis in the customer's own browser, using SubtleCrypto, with no server round-trip. The 'Verify entire chain' button walked all 313 rows the same way. Both surfaced the broken row before any DeAlgo employee said anything about it.

Without this guarantee

DeAlgo would be the sole authority on what was actually committed. The customer would have to take our word for the integrity claim — which is exactly the property the protocol exists to eliminate.

What this proves

A vendor that hides integrity violations isn't selling integrity. The four guarantees on the SSI page are operational, not aspirational — every one of them ran in production on this date, against an actual mutation introduced by DeAlgo's own application code, and produced the behavior the protocol specifies. The bug was real. The detection was real. The recovery was real. The reverification was real.

That separation — between what a protocol claims and what it does under stress — is the only test that matters.

Read the full narrative →About the four guaranteesGet an API key