# Legacy byte-integrity correction

Status: DONE

## Result

The integrity finding is corrected. Excluding only the authorized repaired outer wrapper `index.html`, all 137 original children exactly match the canonical manifest in staged source and in the direct pinned Pages deployment. The three custom-domain raw mismatches are Cloudflare email-obfuscation transformations, not source drift.

## Deliverables and checks

| Deliverable | Requirement or verification | Result | Evidence |
|---|---|---|---|
| [Integrity correction record](/Users/agency/Documents/Agty/KomplexLogopédia/outputs/rita-journey-20261002/evidence/legacy-postdeployment-integrity-correction/integrity-correction.json) | Use `site/review/legacy-evidence/original-sha256.json`; exclude only authorized wrapper; verify staged bytes | PASS | Manifest: 138 entries. `index.html` excluded as the authorized materially repaired outer wrapper. Remaining 137 staged files: 137 exact SHA-256 matches. |
| [Pinned delivery comparison](/Users/agency/Documents/Agty/KomplexLogopédia/outputs/rita-journey-20261002/evidence/legacy-postdeployment-integrity-correction/integrity-correction.json) | Verify all 137 original children against direct pinned Pages deployment | PASS | 137/137 raw SHA-256 matches against `https://0e3bb6cf.cf-review-9e5.pages.dev/komplex-rita-funnel-2026-09-26-v1/`. |
| [Bounded transformation proof](/Users/agency/Documents/Agty/KomplexLogopédia/outputs/rita-journey-20261002/evidence/legacy-postdeployment-integrity-correction/integrity-correction.json) | Explain custom-domain differences for `confirmation.html`, `emails.html`, and `email-enrollment.html` | PASS | Each custom-domain response has Cloudflare `data-cfemail` anchors and the decode script only. Decoded email text is exactly `pelda@example.com`; normalized delivery equals source exactly. Raw values and whole-document hashes vary between two reads. |
| [Verifier](/Users/agency/Documents/Agty/KomplexLogopédia/outputs/rita-journey-20261002/evidence/legacy-postdeployment-integrity-correction/verify-integrity.cjs) | Reproducible source-versus-delivery check | PASS | Read-only fetch and hash normalization. No source, provider, or Cloudflare configuration changes. |

## Limits or consequential decisions

The custom domain must not be assessed by a raw-byte hash for the three transformed HTML files. Its raw response changes on repeated reads because Cloudflare regenerates `data-cfemail` values. The direct pinned deployment is the byte-preservation authority for original-file integrity, while the custom-domain normalization confirms the known delivery-only transform. This correction preserves the earlier live-widget and capture evidence unchanged.
