Build integrity & timestamps
Public build timestamp
This static build was recorded at (UTC).
Manifest SHA-256: 0e55d5028256b68fd7e295118bb442c9b0e975151c4644e46ea8e3df25e09890
What these records establish
Owned JavaScript and CSS files are pinned with SHA-384 Subresource Integrity (SRI). The Content Security Policy (CSP) authorises hashed scripts and inline style blocks, rejects inline event handlers and restricts resource loading. Native import-map integrity also pins lazy JavaScript modules in browsers that support it.
The filename of each build anchor is the SHA-256 digest of its exact JSON bytes. You can download it and independently compare that digest, then compare its resource digests with the downloaded scripts and styles. Prior anchors are retained when the build archive is available; they do not imply that old assets remain hosted.
The date is reported by our build clock. It is not an independent timestamp authority, proof of first publication, a financial-rule review date or a professional endorsement. These checks do not prove authenticity if the site and its security policy are compromised together.
Calculator source-check and rule-change dates remain separate and are not refreshed by this build.
Policy boundaries
Scripts do not receive an unsafe-inline or unsafe-eval allowance. Calculator and chart style attributes have a narrowly scoped styling exception. Normal pages retain framing protection; explicitly published calculator widgets retain their embedding permission.
The built preview and production Node serving framework apply the CSP as an HTTP response header. A static export hosted elsewhere needs equivalent hosting-level headers. Development hot-reload servers are not the public production serving framework.
Unpinned external scripts and styles fail the build. Mutable third-party loaders need a separately reviewed integration; advertising consent and the existing advertising review hold remain unchanged.