Keep the “before” fingerprint in the repository you already govern
Synthetic/product-control explanation. Receipt v7 creates a small pre-reperformance anchor package. The preferred model is for the buyer or another approved party to retain that original package in its existing governed VDR, DMS or secure repository—not in a new product-hosted vault.
What it detects
If an anchored event is changed and its envelope hash is recomputed later, the separately retained original manifest no longer matches and the v7 integrity-control pilot fails closed.
Integration, not storage
The product can export deterministic JSON plus an event-index CSV. Repository permissions, version history, activity logging, archive policy and retention remain with the buyer's existing system. Anchor storage is not a separate product or upsell.
What it does not prove
The manifest is unsigned. If an attacker can replace both the event chain and the separately retained original, a new self-consistent chain can still be created. The control does not authenticate origin, prove custody, provide a trusted timestamp, digital signature, notarization, non-repudiation or factual/legal truth.
Pilot gate
Confirm that the chosen buyer-controlled repository preserves the original package/version and keeps replacement authority separate from the re-performance party. If not, downgrade the claim to deterministic reproduction only.