TwoHearths

TwoHearths report information

Understanding report verification

Every TwoHearths Common Wellbeing report includes a verification receipt ID and a SHA 256 fingerprint. In plain English, the receipt identifies one export, while the fingerprint represents the standardised set of records and supporting data used to build it.

This is an information page, not a verification portal. It does not look up receipt IDs, check fingerprints or access any TwoHearths report data.
Tim the Turtle waving

Integrity is not truth.

Verification is about whether the report data is consistent with the data used when the export was created. It does not establish whether a statement is factually correct, whether an event occurred, or why a child felt a particular way.

On the report

What the verification fields mean

ID

Verification receipt ID

A unique reference for the export receipt created when that copy of the report was produced. It identifies the receipt, not the child, parent or Hearth.

SHA

SHA 256 fingerprint

A repeatable digital fingerprint calculated from the standardised report data and supporting information used for the export. This standardised set is called the canonical dataset.

Record summary & integrity information

The export receipt records information such as the report range, supporting data range and record counts associated with the fingerprint. The report may also show integrity and trusted timing information, including where older historical records do not have the same integrity or server timing support as newer records.

These fields describe the report data and export process. They do not validate the accuracy, meaning or cause of anything recorded by a child.

A new receipt is created for each export

If the same unchanged dataset is exported more than once, the reports can have the same SHA 256 fingerprint but different verification receipt IDs.

Fingerprint = data. Receipt ID = export.

The fingerprint represents the dataset. The receipt ID identifies that particular export receipt.

Record integrity

What does “record check passed” mean?

TwoHearths did not find a source record integrity problem in the records checked for that export.

It means the integrity checks completed successfully. It does not mean TwoHearths checked whether a child’s statement was true, whether an event happened, or what caused a feeling.

Reading verification correctly

What it can — and cannot — establish

What verification can establish

Verification can support a check that the report data is consistent with the standardised dataset used when the export was created.

It can also help explain the record counts, date ranges and integrity information shown with the report.

What verification cannot establish

  • that a child’s statement is factually true
  • that an event happened
  • why the child felt something
  • that a parent or Hearth caused a feeling
  • that one home is better or worse than another
  • that the report is a clinical, safeguarding, legal or forensic assessment

TwoHearths preserves what a child chose to record without assigning blame or drawing conclusions about a parent, home or situation.

The data fingerprint

The fingerprint belongs to the data, not the PDF design

The SHA 256 fingerprint is calculated from the standardised report data and supporting information used for the export. TwoHearths calls this the canonical dataset. The fingerprint is not calculated from the PDF file itself.

Records + supporting data
Canonical dataset
SHA 256 fingerprint
PDF report

This means harmless visual changes such as layout, pagination, fonts or rendering differences do not by themselves change the fingerprint of the underlying dataset.

The fingerprint is intended to represent the canonical dataset used for the export and its supporting calculations, not one exact visual rendering of the PDF.

What happens at export

What the receipt confirms

When a report is created, the TwoHearths app calculates the SHA 256 fingerprint in a repeatable way from the standardised report dataset. It then stores the fingerprint and export details in Cloud Firestore as an export receipt with a server generated creation time. The receipt is designed to be immutable, meaning it is not edited after creation.

The server does not independently rebuild the report data or recalculate the fingerprint itself. The receipt records what the app stored at export time. It is not independent third party validation and it is not a cryptographic digital signature.

A different question

Why isn’t the PDF itself digitally signed?

A digital signature on a PDF is designed to show whether that exact file has changed since it was signed.

TwoHearths instead fingerprints the standardised data used to create the report. This means formatting or rendering changes to the PDF do not alter the fingerprint when the underlying dataset has not changed.

The verification information is not a digital signature, certification or official endorsement of the report.

For grown-ups and professionals

If you have received a TwoHearths report

A Common Wellbeing report is a record of what a child chose to record in TwoHearths over a period of time. It can show recorded Check Ins, later reflections and transition feelings, depending on what was included in the report.

The verification information helps explain whether the report data is consistent with the dataset used when that export was created. It does not tell you whether the child’s account is factually true or why they felt that way.

The report should be read in context. TwoHearths does not assess either parent or home, decide what caused a feeling, or decide what weight a solicitor, school, healthcare professional, court or other organisation should give the report.

TwoHearths

Child first. Neutral by design.

TwoHearths is designed to help children express how their days feel across two homes. Its integrity features exist to protect the reliability of those records, not to turn a child’s feelings into an argument between adults.

A Hearth & Hero Studios product