Skip to main content
The Operations module must be enabled for your workspace. You also need the appropriate operations permissions. Contact your workspace administrator if you cannot access these features.
Record integrity verification requires the Admin, DOM (Director of Maintenance), or Safety Manager role. The Records module must be enabled for your workspace. If you cannot access Ops > Record Integrity, contact your workspace administrator.
By the end of this guide, you will have navigated to the record integrity dashboard, selected an aircraft, reviewed its hash chain status, run a verification check, interpreted the results, and exported a proof bundle suitable for an auditor or regulator.
The integrity dashboard covers all protected record types — not just maintenance. Safety reports, investigations, corrective actions, flight logs, dispatch releases, crew training records, and other regulatory records all appear in the integrity dashboard alongside maintenance records. See Tamper-Evident Aviation Records for the full list of 19 protected record types.
For background on how the record integrity system works, see Tamper-Evident Aviation Records.

Select an aircraft and view its hash chain

Run a verification check

Interpret verification results

Green status: all records verified

Every record’s hash matches its stored value and the chain is unbroken. All RFC 3161 timestamps have been confirmed. OpenTimestamps anchors that have had sufficient time to confirm (typically 10—60 minutes after creation) are confirmed. No action is required.

Amber status: pending anchors or stale verification

Amber most commonly appears for one of two reasons: Pending anchor confirmation. Recently created records (within the last hour or two) may show OpenTimestamps anchors as pending. This is normal — the Bitcoin anchoring process requires a block confirmation, which takes approximately 10 minutes on average. The status will resolve to green automatically as confirmations arrive. Stale verification. If a full verification has not run in more than 30 days, the dashboard flags the status as amber to prompt a fresh check. Run a new verification as described above to resolve this.

Red status: hash chain break detected

A red status means at least one record’s hash does not match the value stored at the time the record was created. This indicates one of the following:
  • The record’s content was modified after it was saved.
  • A system error corrupted the record’s data.
  • The hash storage itself was modified.
The verification summary identifies the chain position of the first break. Records before the break are unaffected. Records at and after the break position require review.
Do not manually edit or delete records flagged by a red integrity status. Doing so may further alter the chain and complicate investigation. Contact PlaneConnection support immediately. For records that are critical to an ongoing regulatory audit, notify your Principal Operations Inspector (POI) if the affected records cannot be confirmed within 24 hours.

Export a proof bundle for auditors

Tamper-Evident Aviation Records

Understand the trust model behind hash chains and external anchoring.

Record Integrity Anchors Reference

Technical specifications for RFC 3161, OpenTimestamps, and EVM anchor types.

Manage Work Orders

Creating maintenance work orders that feed the hash chain.

Export Data

Full data export options for compliance and audit purposes.
Last modified on April 11, 2026