You download an execution receipt and the verifier says `valid: true`.

Can you trust it?

First ask where the verifier got its trusted public key. A signature proves that a particular key signed the receipt. It does not tell you, by itself, who owns that key.

If the receipt brings its own key and your verifier trusts it automatically, anyone could create a key, sign a claim, and make that claim appear verified.

Before relying on a receipt, check:

1. Did the signature and receipt contents pass verification?
2. Did the key come from a source you trust independently?
3. Does the receipt target the expected deployment and audience?
4. Are any external checks still required?

Offline verification is useful because it can check evidence without calling the issuer. It does not establish the key’s identity for you. Some claims, such as ERC-1271 authorization or an EVM anchor, may also need chain-state checks.

Insight and PriorSeal have separate evidence scopes and trust roots. Connecting their records does not automatically make one product the authority for the other.

A green “valid” result is only useful when you know what was verified, under which key, and what still needs checking.

Where does your verifier get its trust configuration?
#defi