Skip to content

Lifted Payments Payment Statement Audit Model v1.1.3

Choose a tag to compare

@LiftedHoldings LiftedHoldings released this 02 Aug 23:00
7399dc4

Provenance-hardening release; the schema 1.1.0 record contract and v1.1.2 validator rules remain unchanged.

Highlights:

  • separates portable package validity, candidate readiness, and published attestation
  • requires a clean committed tree, authoritative origin, complete remote tag inventory, exact tag alignment, and monotonic versions
  • runs static inventory, path, size, encoding, checksum, credential-signature, identity, and provenance checks before candidate Python
  • adds bounded non-executing verification of GitHub, Zenodo, DOI, Hugging Face, and Software Heritage identities and bytes
  • rejects unsafe redirects, oversized responses, archive traversal, case-fold aliases, symlinks, undeclared members, digest mismatches, and public identity drift

Verification:

  • 81 tests in the exact merge worktree
  • 81 tests from the unpacked release archive (one Git-history-only immutability regression skipped as designed)
  • package gate 14/14, tagged candidate gate 15/15, and published gate 16/16
  • Ruff, compileall, gitleaks, complete checksums, and manifest-byte equality clean
  • tagless unpacked archive correctly blocked from candidate readiness

No real merchant or cardholder data is included. The gate proves declared package and release provenance; it is not an accounting opinion, legal review, interchange-pricing guarantee, malware sandbox, qualification determination, or guarantee of savings.

Canonical guide: https://liftedpayments.com/payment-processing-statement-audit/
Published version DOI: https://doi.org/10.5281/zenodo.21764642
Zenodo record: https://zenodo.org/records/21764642
Hugging Face mirror commit: https://huggingface.co/datasets/Liftedholdings/payment-statement-audit-model/tree/a001235f4195fc534660100e01db41d10712eaac
Software Heritage snapshot: https://archive.softwareheritage.org/swh:1:snp:52b9172c2533e1686d0a1acf9f541029262f4d3e/
Technical walkthrough: https://dev.to/daniel_wilsonkemp_62b88a/a-processor-neutral-json-schema-for-auditing-payment-processing-statements-2cg2
Archive SHA-256: b1d398ada2bb456de0fffc5278b68a48554ffd5d80232d654416102ad87d5897