Reconstruct RFC 8785 bytes, reproduce the manifest digest, and verify the auditor Ed25519 signature.
Trust the seal.
Then trust the key.
Profile 0.2-V1 proves the manifest was signed by its declared auditor key. Profile 0.2-V2 closes the self-declared-key gap with an issuer-signed credential, pinned registry root, target authorization, bounded status freshness, validity, and revocation checks.
Verify the bytes.
Then verify the signer.
The audit seal covers every manifest claim except its own digest and signature. Inside that seal, a separately issuer-signed credential binds the auditor and organization to the exact audit key, targets, and a bounded-fresh registry status proof.
Require the credential issuer key and minimum registry version to match a locally configured trust root.
Match auditor, organization, raw key, key digest, and requested certification target exactly.
Require active, valid, unrevoked status whose issuer-signed freshness window covers the audit signing time.