Docs · Concepts

Evidence and export

Every value SourceFinch gives you can be traced to what the source actually said, and when. That is the difference between a monitored record and a scraped row: you can show it to someone else and they can check it.

What a run keeps

Raw captureThe exact bytes fetched (or the rendered page, in browser mode), retained for your plan's evidence window.
Content hashSHA-256 of that capture. Any later edit to the file would change the hash.
TimestampsWhen the source was acquired, when records were extracted and when they were validated.
ProvenanceThe URL fetched, the recipe version, and the selector or path behind each field of each record.
ValidationThe checks the run passed (record count, required fields, health against recent runs) before it could become your current data.
Signed manifestA manifest of all of the above, signed with SourceFinch's published evidence key, and where available anchored to an RFC 3161 timestamp.

In the console, open any run and select a record to see its evidence: the capture, hash, timestamps and the selector behind each field. After your plan's evidence retention (14 days on Free, 90 on Pro, a year on Business) the raw capture is deleted, but hashes, records and change history remain.

Getting data out

CSVCurrent records, one row per record. Opens anywhere.
JSONRecords with their field values and evidence references.
NDJSONOne record per line, for pipelines and large sources.
XLSXA spreadsheet with a frozen header row.
Evidence bundleA ZIP (WACZ) with the run's captures, the signed manifest, its timestamp anchor and the public key: everything a third party needs to check the run without trusting us.

Download from any source or run page in the console, or over the API: GET /v1/runs/{run_id}/export for records and GET /v1/runs/{run_id}/bundle for the evidence bundle. Signed webhooks and delivery destinations can push changes to you as they happen; see the API reference.

Checking a bundle

A bundle is self-describing: its sourcefinch/README.txt explains each file. To verify one, check that each capture's SHA-256 matches the manifest, that the manifest's Ed25519 signature verifies with the included public key, and that the key's ID appears in our published keys at /.well-known/sourcefinch-evidence-keys.json. When the run was anchored, the RFC 3161 token proves the manifest existed at that time.