Same bytes is not the same as reviewed content

Synthetic/product-control explanation. Receipt v7 separates private-document byte verification, content review and origin authentication.

Preferred review environment

Use the buyer's existing approved VDR/DMS/review environment where possible. The product should not create a new document-upload perimeter merely to perform bounded review. Any future connector is buyer-earned and must preserve the buyer's permissions and audit expectations.

Byte verification

BYTE_VERIFIED_IN_REVIEW_ENVIRONMENT means the bytes available in the approved review environment hash to the supplied SHA-256. It is mutation/reproducibility evidence.

Content review

SCR-04 can PASS only when the facility document is present and its bounded content review is explicitly recorded as CONTENT_REVIEWED. A matching hash alone cannot satisfy SCR-04.

Origin authentication and EA trusted ingress

Ordinary private evidence still reports ORIGIN_NOT_AUTHENTICATED; hashing/content review does not provide digital signatures, notarization or non-repudiation. EA separately records whether the source has an accepted trusted-ingress provenance basis such as a governed repository object/version or authenticated delivery channel. That state must not be relabeled as cryptographic origin authentication.

Manifest-only boundary

A digest/locator-only workflow can exercise other bounded controls, but it cannot claim facility-document completeness without actual content review.

Download synthetic byte-verification demo