When a device ages out, the painful question is not “which cable?” but “can I show that this firmware path was deliberate?” Email receipts vanish when accounts close. Screenshots scatter across phones.

A one-page provenance card

For each air-gapped signer, keep a card with:

  • Purchase channel and approximate date
  • Firmware version at first use
  • Dates and versions of later updates
  • Hash or release tag you verified, written by hand
  • Who performed the update (you, co-owner, supervised session)

What we look for in audits

We are not a manufacturer help desk. We check whether your notes would convince a careful peer six years from now. Gaps are normal; inventing details is not. If a version is unknown, write “unknown — to verify before next large move.”

Pairing with the signing log

Provenance cards explain the device; signing logs explain the authorizations. Keep them adjacent but distinct so a lost notebook of transfers does not automatically expose purchase history you meant to keep quieter.

Bring whatever fragments you have to an audit—we rebuild clarity from incomplete paper more often than from perfect binders.

All journal entries