Case study · 2026-05-06
SSI under stress.
The SSI Protocol™ defines four guarantees every conformant implementation must satisfy. On 2026-05-06, application code in DeAlgo's portal mutated a signed audit-chain column, breaking one row's chain hash. This page records what each guarantee did under that stress — what it exercised in production, what would have failed without it, and the verdict.
Read the full operational narrative on the trust page. This page is the structured proof, not the story.
Outcome summary
- Detected
- 2026-05-06 04:11 UTC
- Resolved
- 2026-05-06 05:48 UTC
- Time-to-detect
- < 1 second after mutation
- Time-to-diagnose
- ~20 minutes
- Affected rows
- 1 of 313
- Downstream corruption
- None — chain halted at the mutation row
- Data loss
- None
- Customer trust property
- Preserved end-to-end
Per-guarantee performance
One row per guarantee. The protocol claim isn't that guarantees never get tested — it's that when they are tested, their behavior is observable and reproducible.
Tamper-evident hash chain
Exercised · workedThe boot-time integrity walk recomputed sha256((previousHash ?? "") + "\n" + canonical(row)) for every row in scope. The mutated row's recomputed value disagreed with its stored chainHash byte-for-byte.
The mutation would have propagated silently. Subsequent rows would have linked to a tampered predecessor; replay and reconciliation queries would have returned results that didn't match what was actually committed. The first place the inconsistency would surface would have been during an external audit.
Fail-closed defaults
Exercised · workedThe integrity walk treated disagreement as a structural impossibility, not a warning. The workspace returned 503 to writes the moment the mismatch was detected. No row was written into a chain whose continuity could not be reproduced.
Writes would have continued accepting new rows on top of a broken chain. Each new row would have been auditable individually but the chain-of-custody property of the workspace as a whole would have silently degraded.
Human authority preservation
Exercised · workedRecovery was gated on explicit operator authorization at every step. The repair script refuses to write unless its reconstruction of the originally-signed bytes reproduces the stored chainHash exactly; the dry-run is mandatory; the production write required a separate explicit approval after the dry-run printed MATCH.
An auto-remediation system could have rewritten history to make the chain look intact again. The protocol's trust property would be reduced to 'we promise we didn't tamper with it.'
Independent verification
Exercised · workedThe decision-detail page's 'Verify this row' button reproduced the diagnosis in the customer's own browser, using SubtleCrypto, with no server round-trip. The 'Verify entire chain' button walked all 313 rows the same way. Both surfaced the broken row before any DeAlgo employee said anything about it.
DeAlgo would be the sole authority on what was actually committed. The customer would have to take our word for the integrity claim — which is exactly the property the protocol exists to eliminate.
What this proves
A vendor that hides integrity violations isn't selling integrity. The four guarantees on the SSI page are operational, not aspirational — every one of them ran in production on this date, against an actual mutation introduced by DeAlgo's own application code, and produced the behavior the protocol specifies. The bug was real. The detection was real. The recovery was real. The reverification was real.
That separation — between what a protocol claims and what it does under stress — is the only test that matters.