Evidence Export
Generate a signed ZIP for any compliance framework — every artifact (BAA, register, model card, IA, claim, ledger checkpoint) is included with its signature so an auditor can verify the chain offline using the published key_history.json.
Vault unreachable: Vault admin GET evidence-export/frameworks: HTTP 404 {"error":"evidence export not enabled"}
Once downloaded, drop the ZIP into the auditor verifier. Every signed artifact is checked client-side using the public key history. A single byte tampered anywhere fails verification.