{
  "manifest_id": "mfst_evidencepkg_v1_2026-05-18",
  "schema_version": "1.0.0",
  "synthetic": true,
  "synthetic_notice": "All artifacts in this manifest reference SYNTHETIC sample data. Hashes are real (computed over the actual file bytes); signer key (vke_synthetic_2026-05) is synthetic and intentionally exposed for reproducibility.",
  "audit_period": {
    "from": "2026-05-18T00:00:00Z",
    "to": "2026-05-18T23:59:59Z"
  },
  "sample_criteria": "synthetic; single workflow; demonstration only",
  "artifacts": [
    {
      "path": "receipt.json",
      "sha256": "a55e30ffb8a88913c640a2e8abd53c87c7605ed1e69e8cce3e5846faa0387e58",
      "bytes": 2190,
      "description": "Synthetic healthcare workflow receipt"
    },
    {
      "path": "framework_mapping.md",
      "sha256": "4a7a60cd844870f517a7977bc5258276bb479d7de744e2d1b42af51bda0cc720",
      "bytes": 5054,
      "description": "Mapping of receipt fields to AIUC-1, NIST AI RMF, ISO 42001, Article 50, HIPAA, SOC 2, Reg S-P"
    },
    {
      "path": "README.md",
      "sha256": "6ca3f2864d3831f2e9725c902c14e2079bc56739311711cde7e494017f116c53",
      "bytes": 5521,
      "description": "Package overview and verification instructions"
    },
    {
      "path": "verifier_cli.py",
      "sha256": "9cf8b924f3b465a655d9763239da67f86a7b189e23c4623545da73680f9d30a7",
      "bytes": 9587,
      "description": "Standalone Python verifier; depends only on the `cryptography` package"
    },
    {
      "path": "sign_and_verify.py",
      "sha256": "8e81728c05ce1e4aa0e8324fcf95244c3593031ed09b1c05c301ad2643fdb104",
      "bytes": 10606,
      "description": "Build script: generates synthetic Ed25519 keypair, signs receipt + manifest, runs verifier"
    },
    {
      "path": "public_key.json",
      "sha256": "95e29f4b959fe6f7b4a37c6f7a9bbc5045baca07744d37dc21c249e47c44c024",
      "bytes": 445,
      "description": "Synthetic Ed25519 public key (vke_synthetic_2026-05) for offline verification"
    },
    {
      "path": "LICENSE",
      "sha256": "8135def8677f2c9d3ec8c9b4255094a934c488b5c9600412f08e697fd5792400",
      "bytes": 1073,
      "description": "MIT License for the verifier tool"
    }
  ],
  "signer_key_id": "vke_synthetic_2026-05",
  "signer_public_key_hex": "d75a980182b10ab7d54bfed3c964073a0ee172f3daa62325af021a68f707511a",
  "manifest_signature": "ed25519:b3df383d9b5629cf89e251464fc05be8007afd7fd3317f4059271d011f4e5808dbcc1ca0382abf748cdd2ab30e40ee1b8b062a5d1f13d701c09c3515508b1c05"
}
