Verify evidence

Paste the manifest.json and its signature from a SiteGauge evidence bundle. We recompute the hash and check the Ed25519 signature against SiteGauge's public key, proving the export is authentic and unaltered. No account needed.

A bundle may also contain timestamp.tsr, an RFC-3161 trusted-timestamp token proving when the export existed. Verify it with openssl ts -verify.