A check at /tools/verify-image used to end on the screen. Underneath the result there is now a second action: Download the signed report. It produces a single file that records what the check reported for that exact image, at that moment, naming the checker version and the trust-list date it used.
The image still never leaves your browser. Pressing the button sends your file's fingerprint — a SHA-256 hash — together with the findings shown above it. Nothing else, and only when you press it. A check where you do not ask for a report transmits nothing at all, exactly as before, and the sentence saying what leaves sits next to the button rather than in a footnote.
The report is honest about what it is. It says that Qamera's checker, at a named version and trust-list date, ran in your browser and reported these findings — and that Qamera never received the image, did not run the check itself, and has not confirmed the verdict. What it is worth is that it fixes one result to one file, one moment and one named configuration, in a way that cannot be edited afterwards without breaking the signature.
Reading one back is a page of its own. A recipient opens /tools/verify-report and drops the file in. The signature is checked in their browser, against keys this site publishes openly — nothing is sent to us to do it. They can also add the image the report is about, in which case the fingerprint is compared and the whole check runs again with today's checker, so they get their own answer beside the recorded one.
Nothing is stored on our side. There is no register of issued reports and no way to look one up. There is also no expiry and no switch that could turn a report off later: one already in someone's hands is meant to stay checkable for years, including by someone who has never heard of us.