The key never leaves the hardware.
No one at BurnLedger can sign a verification record by hand. The Ed25519 signing key exists only inside an AWS Nitro Enclave: sealed hardware that measures the code it runs. AWS KMS releases the key to that exact measured build and to nothing else. The build is deterministic: we rebuild every release from the same commit and confirm it measures identically. We do not publish the source or toolchain that would let you repeat that rebuild, and that is a settled decision rather than a gap we are working on — the enclave source is the product. So that particular check is ours, not yours, and we would rather say so than imply a publication that is not coming. What a certificate carries for you to check is the signature and the log entry: it holds no hardware attestation, so enclave custody is our operational claim, not your arithmetic. What we can do is put the claim somewhere we cannot quietly edit: every measurement we have run in production is published with its date at enclave measurements.