PDI Med restarted on a clean system before launch
On September 30, 2026, before any physician other than the founder had used PDI Med, we deleted the pre-launch data and started again from an empty system. The site was offline for about seven minutes, from 2:12 to 2:19 PM Central.
What was deleted.
- Every account, sign-in record and device token. There was one account: the founder’s.
- Both server databases, replaced by new, empty ones.
- Every encrypted vault object in storage, including all earlier versions of each.
- All 35 daily backups of the server’s file system.
What remains, and for how long.
- Held offline by the founder: the old ledger (hashes only), the audit record of calls to the AI model (one-way fingerprints and metadata, not the text sent), and the founder’s own verified export of the old vault. They are on one computer, with no second copy.
- Public and permanent: the Sigstore log entries that anchor the old ledger’s final hash. They hold hashes, event counts and timestamps, not clinical content.
- Server logs: application logs are kept indefinitely; the record of operator commands run on the server is kept for 365 days; network connection records (addresses, ports and byte counts, no content) are kept for 7 years.
How to check it yourself. The ledger is PDI Med’s tamper-evident record of vault events. It holds hashes, never clinical content.
- The old ledger ended after 24 events, recorded from August 18 to September 30. Its final hash was anchored to the public Sigstore log before the restart: 48dec8dbd473c818491d43dc165f8845a761710af4e894a36cef95cb0a37c09d
- The new ledger’s first event is a reset record that names that final hash, the event count and the old ledger’s first hash. Anyone can read it at app.pdi-med.com/.well-known/pdi-ledger-genesis
- The new ledger’s first hash was anchored to Sigstore the same afternoon: 7760a1d40f4bd691b5f56bbe191f73d5751bcf225850f462093f293130acc54e
- The current head is published at app.pdi-med.com/.well-known/pdi-ledger-head and anchored about every six hours.
- Sigstore entries: old final hash 108e9186e8c5677a907bd017d496223861e5d85f52c2ff4e98aaf0baeb66da5f9803ec8fa479ac7f; new first hash 108e9186e8c5677a706dbd56a7b42ad0827953a8a65903d14abb69b70c0bac5ae9b1763a29e45d5d
To check all of this at once, run the script below with Python 3; it needs no extra packages. It reads only the public addresses above, recomputes the reset record’s hashes, and asks Sigstore for both entries. It stops with an error if anything does not match.
import json, hashlib, urllib.request
enc = lambda d: json.dumps(d, sort_keys=True, separators=(',', ':'), ensure_ascii=True).encode()
get = lambda u: json.load(urllib.request.urlopen(u))
def rekor(digest):
req = urllib.request.Request('https://rekor.sigstore.dev/api/v1/index/retrieve',
data=json.dumps({'hash': 'sha256:' + digest}).encode(), headers={'Content-Type': 'application/json'})
return json.load(urllib.request.urlopen(req))
G = get('https://app.pdi-med.com/.well-known/pdi-ledger-genesis')['record']
head = get('https://app.pdi-med.com/.well-known/pdi-ledger-head')
ci = {k: G[k] for k in ('prev_hash', 'payload_hash', 'event_type', 'encounter_id_hash', 'scope', 'ts_utc', 'meta')}
assert hashlib.sha256(enc(ci)).hexdigest() == G['chain_hash'] == head['genesis_hash'], 'the reset record is not the first event of the live ledger'
assert hashlib.sha256(enc(G['meta'])).hexdigest() == G['payload_hash'], 'the reset record was altered'
m = G['meta']
old = {'schema': 'pdi_ledger_anchor_v1', 'chain_hash': m['prev_chain_hash'], 'count': m['prev_count'],
'genesis_hash': m['prev_genesis_hash'], 'first_event_at': m['prev_first_event_at'], 'last_event_at': m['prev_last_event_at']}
d_old = hashlib.sha256(enc(old)).hexdigest()
assert d_old == m['prev_anchor_sha256'], 'the reset record misdescribes the old ledger'
new = {'schema': 'pdi_ledger_anchor_v1', 'chain_hash': G['chain_hash'], 'count': 1,
'genesis_hash': G['chain_hash'], 'first_event_at': G['ts_utc'], 'last_event_at': G['ts_utc']}
print('old ledger: final hash', m['prev_chain_hash'], '|', m['prev_count'], 'events | Sigstore:', rekor(d_old))
print('new ledger: first hash', G['chain_hash'], '| Sigstore:', rekor(hashlib.sha256(enc(new)).hexdigest()))
What this proves, and what it does not. The restart is announced by the ledger itself and tied to the old ledger’s last public hash, so it cannot be quietly rewritten later. It cannot prove what the old ledger contained.
What you need to do. Nothing. Every account created from today starts with an empty vault.