Skip to content
FonteumPublic-records evidence
Integrity attestations

Snapshot-attestation coverage, with gaps disclosed.

When a snapshot-attestation row identifies source bytes and a SHA-256 digest, re-fetch the named archive if it remains available and compare it with shasum -a 256. Historical rows do not all hash complete source bytes, and no claim-level signature linkage is inferred.

100 attestations on file across 10 source families. Foundation layer for the Certificate-Transparency-style attestation chain — hashes ship first, chain semantics layer on top once 30+ snapshots have accumulated.

How to re-hash a snapshot →

Append-only corrections

When a past snapshot recorded a wrong value, we append a signed correction — we never rewrite it.

The chain is immutable: a signed snapshot is never edited, deleted, or re-signed. A correction is a separate appended record that references the affected snapshots and is itself Ed25519-signed by the same chain key. The wrong value stays on the record verbatim; the correction explains it. Full machine-readable list: /api/v1/chain/corrections.

snapshot-zero-count-nppes-pecos-2026-06-19·nppes pecos_ppef·2026-05-312026-06-18·38 snapshots

Recorded value: 0 Correction: indeterminate for the affected window — the snapshotter never counted the real table, so the true historical row count for these dates is unknown and is NOT reconstructed here. The dataset was non-empty throughout (current nppes_providers ≈ 9.0M rows, pecos_providers ≈ 2.98M rows); the recorded 0 was a table-mapping defect, not a real measurement of an empty dataset.

The daily-dataset-snapshotter mapped source_id `nppes` to a non-existent `providers` table and `pecos_ppef` to a non-existent `cms_pecos_providers` table. The daily COUNT(*) returned no row and was recorded as record_count=0, then attested, witness-signed, and chained once per day for the affected window.

Forward fix: PR #1035 (commit 8f66f482) repointed the source_ids to the real nppes_providers / pecos_providers tables; the source_id keys are unchanged so the bitemporal history continues under the same family key. · Issued 2026-06-19

Security & compliance

What we run on, and what we hold.

SOC 2
Fonteum does not currently hold SOC 2. The hosting and data tiers run on SOC 2 Type 2 attested infrastructure (Vercel, Supabase).
Infrastructure
Hosted on Vercel (edge network). Data warehouse: Supabase (PostgreSQL). All data at rest encrypted. All data in transit TLS 1.2+.
Data scope
Public-domain federal regulatory records only. No PHI. No PII beyond what appears in federal public records. No BAA required.
Snapshot integrity
Every ingestion run produces a SHA-256 hash stored in snapshot_attestations. Verify any snapshot at /verify/[id].
Security contact
security@fonteum.com
Recent attestations

100 attestations on file across 10 source families.

cftc-enforcement-actions 23 attestations

cpsc 4 attestations

dea-registrant-enforcement 4 attestations

eu-sanctions 2 attestations

fincen-enforcement-actions 1 attestation

ncua-enforcement-actions 26 attestations

ofac-sdn 6 attestations

phmsa-pipeline-enforcement 1 attestation

sec-enforcement 12 attestations

un-sanctions 21 attestations

Open & scoped

Live FHIR R4 API, stored SHA-256 attestation rows, and an open methodology. A displayed hash covers the object identified by its attestation row; it does not prove the source trail or sign every value.

FHIR R4 API
US Core 6.1.0
live · /api/fhir
Attestation chain
SHA-256 snapshot manifests
artifact-level · /chain
Methodology
version v2026.05.0
public · /methodology
Provenance
nullable response fields
source · date · limitations when supplied
Source registry
active production source registry
status is not loaded, complete, or fresh coverage · /sources

What’s on file, by the numbers

Platform snapshot · 2026-08-24

13.4Mproviders & companiesProviders, organizations, owners, and facilities on file
26.2Msource-linked factsSource-linked field facts in the dated platform snapshot
90sources with dataDistinct snapshot source IDs with at least one positive record count
70fresh sourcesDistinct source IDs whose latest positive-data snapshot falls within the preceding 45 days
111sources integratedActive registry rows; integration does not establish a load
13state Medicaid jurisdictionsDistinct states represented in the state-exclusions serving table

Integrated, with-data, and fresh-observation counts are separate. No platform-wide source-completeness count is published. Completeness is source-specific and must be evaluated against the named source's expected scope. State coverage is a separate jurisdiction measure.

Source authority is record-specific

Use the issuer named on the record.

Fonteum spans federal, state, and global public publishers. A source page or returned record identifies its issuer and dataset where that metadata is available. A platform registry count does not assign every page to one authority or establish loaded, fresh, or complete coverage.

Browse source records and their stated limitations →

Reproducible by design

Inspect the evidence each published figure actually supplies.

Source and date

Research pages expose the named public file and observation date where those fields are available. Source-file SHA-256 coverage is separate; facts do not currently link deterministically to signatures.

Available derivation

Studies with a retained release and committed derivation link the SQL or method used. Other studies state the evidence and reproduction limits they actually have.

Daily observations

Dated table row-count observations can detect local drift. They do not imply that an upstream publisher released or Fonteum ingested new data that day.

Named medical review

Reviewed by Jennifer Montecillo, MD, medical reviewer. Non-practicing medical reviewer.

Read the full provenance and attestation methodology →

Request access