Report Verification
Every security report Hal produces is a cryptographically signed PDF. The signature does two things: it proves the report came from Hal, and it proves the contents haven’t changed since Hal signed them. If anyone edits so much as a word after signing, the signature no longer matches.
You don’t have to trust that a report is genuine. You can check it.
Verify a report
Hal hosts a verifier at runhal.com/verify. To check a report:
- Go to runhal.com/verify.
- Drop the PDF onto the page, or select it from your computer.
- Read the result.
The verifier answers one of these:
- Genuine. The report was signed by Hal’s published certificate and has not been modified since signing.
- Changed after it was signed. The bytes no longer match the signature, or content was appended after signing.
- Not signed by Hal. The signature is intact, but the certificate behind it is not the one Hal publishes.
- Unchanged, signer not confirmed. The signature holds, but Hal’s DNS record could not be reached to confirm the signer; the page shows the fingerprint so you can compare it yourself.
- No signature. The PDF doesn’t contain a signature at all, so it cannot be confirmed as a Hal report.
Note
What verification proves
A genuine result confirms two facts:
- The report was signed by Hal.
- The contents are exactly as Hal wrote them, no additions, deletions, or edits since signing.
That covers the cases that matter in practice: someone forwarding a forged report, someone tampering with a real one before passing it on, or you simply wanting to confirm a report you received is authentic before acting on it.
What it doesn’t prove
Verification confirms a report’s origin and integrity. It does not judge the report’s findings, that’s the analysis inside, which the detection pipeline produced. A genuine signature means “this is really Hal’s report, unaltered,” not “the conclusion is correct.” The two are separate questions.
Viewing the signature in a PDF reader
Most people will read Hal reports inline, in email, in their portal, or in a browser, and never see signature details, because those viewers don’t display them. That’s expected. The signature is there for verification on demand, not for passive display.
If you open a signed report in a full PDF reader such as Adobe Acrobat, you may see a note that the signer’s identity is “unknown” or “not trusted.” This is normal and does not mean the report is invalid. It only means your reader doesn’t recognize Hal’s signing identity on its own. The reader will still confirm the document hasn’t been modified since signing, and the verifier is the authoritative way to confirm the report is genuinely Hal’s.
See what Hal surfaces on your own clients.
No deck. Ask us anything first. When you want to see Hal on your own tenants, we sign a short evaluation agreement and stand up your instance; you connect one tenant, Hal watches it for 14 days, and we walk you through what he found.
- 01You ask us your questions. No deck, no demo dataset.
- 02You sign a short evaluation agreement, and we stand up your own instance.
- 03You connect one tenant from your own admin console. Hal watches it for 14 days.
- 04We walk through what he found. Keep going month to month, or revoke the scopes yourself and stop.