Chapter 119: Clean Enough to Publish
We fixed the copies without touching the evidence, and the difference had its own receipt.
On Thursday, the independent privacy auditor opened her findings in KRR's review room.
The forty-eight-hour release pause remained active while she presented them. No one in the room could shorten it by calling the affected files fixed.
Samuel sat beside the incident register without controlling the audit screen.
Marcus provided technical answers only when the auditor requested them. His own completion notes remained evidence for her review, not a substitute for it.
I watched through the same participant view that would later become public.
The auditor began with the three withdrawn PDF hashes.
Each identified the exact derivative that had failed the metadata test.
The incident log preserved those hashes instead of silently replacing them. Each withdrawn value carried the discovery time and the account that found it.
No withdrawn copy could be mistaken for an approved public file.
She then displayed the protected source identifiers.
Their original hashes matched the values recorded before the incident.
Their custody logs showed no edit, substitution, or new evidentiary claim. The auditor matched the stored bytes against the pre-incident hash register.
The repair had started from authenticated originals under controlled access. Two authorized staff members recorded the extraction and export steps.
It had produced three new derivatives with new public-copy hashes.
The auditor opened each properties panel from a clean account.
Author, company, last-saved-by, template, and revision fields were empty.
Text extraction returned only the visible, approved public content. Searches for each protected username returned no match across the release directory.
Layer inspection revealed no covered text beneath the redactions.
Filenames used source identifiers rather than witness names or old usernames.
Thumbnail caches and embedded attachments were absent.
The auditor repeated the tests on the rest of the release package. Her sample did not stop with the file type that had already failed.
She found no additional legacy identity field. Spreadsheets, image properties, index exports, and embedded links also passed their assigned tests.
That result did not erase the original failure.
Samuel's correction note named the missed control, affected copy count, and pause period. It avoided the word harmless because the witness had not authorized the exposure.
It explained that no public or press release had occurred before discovery.
It also distinguished evidence hashes from derivative hashes in plain language.
The privacy reviewer confirmed that the visible redactions had not changed. She compared the approved field list against each new derivative before signing.
No ruling had been broadened during technical cleanup.
No unfavorable fact had disappeared with a metadata field.
The auditor signed a mapping table for each repaired copy.
One column held the protected source identifier and original hash.
Another held the withdrawn derivative hash and incident status.
The final column held the approved derivative hash and release status.
Every link carried its generating receipt, timestamp, and reviewer. A failed link would stop release rather than fall back to an older copy.
I selected one entry through the public preview.
It led to the approved copy and displayed the matching source identifier.
It did not open the protected original or reveal the witness behind it.
I selected the withdrawn hash from the correction note.
The system returned an incident status, not a downloadable file.
That made the repair visible without republishing the privacy failure. The protected username never appeared in the correction note or public status page.
At 4:06, the auditor certified the full metadata rescan.
Samuel kept the pause active after her signature entered the access log.
Marcus locked the corrected map and generated the release manifest.
The manifest matched every approved public hash to one indexed derivative.
The originals remained separately protected under their existing custody rules.
I could verify the relationship between copies and evidence without receiving either private field.
Samuel opened the final production checklist.
Every technical, privacy, response, and mapping item showed a dated owner.
Only one unchecked line remained: `release package complete`.