Proofs & Security
The byte-exact merkle and signature contracts are in the Protocol section: Merkle inclusion proofs, BLS signatures & DSTs, and the four ordered integrity gates.
dig-store's guarantees come from three mechanisms working together: a Merkle commitment over content, signed roots, and host attestation.
Merkle proofs
Each generation builds a Merkle tree with one leaf per resource, where a leaf commits to the exact ciphertext bytes the module serves for that resource. The tree's root is the generation's root hash.
Because the leaf commits to ciphertext (and encryption is deterministic — see URNs & Encryption), the served bytes can be verified against the root without ever decrypting them. A single inclusion proof accompanies a served resource and proves those exact bytes belong to that exact root.
digs cat <urn> --verify-proof
--verify-proof checks that the resource's proof resolves to the trusted root and that the module's program hash matches the expected serving program — so you're verifying both the content and the code that served it.