Trust & integrity

Nobody plays favorites — here's how that's enforced

The person running this app controls the database. That's true of every attendance system anyone hosts. What matters is whether an edit made outside the rules leaves a trace — here, it does, every time.

The honest starting point

No software running on infrastructure one person controls can make it technically impossible for that person to edit the database directly. Any claim otherwise is marketing, not engineering. What this app does instead is make a direct edit detectable and provable — so the operator has something real at stake if they ever tried, not just a promise.

1. Check-ins never go through a human

The default, and only self-service, way to check in is a rotating cryptographically-signed QR code plus GPS geofence verification — both checked entirely by server code, with no manual step where anyone could quietly approve or reject someone. Only an explicit, logged override (point 2) ever bypasses this path.

2. Every manual override is permanently, verifiably logged

A teacher or organizer can manually mark someone present — for a phone that died, no signal, or GPS that was a little too strict — but that action always writes an audit log entry: who, when, and for whom. These entries are chained by cryptographic hash, each one covering the previous entry's hash, so editing or deleting a past entry — including by direct database access — breaks the chain from that point forward. The chain's current integrity is verified live below.

Live chain verification

This re-walks every audit log entry across the whole platform right now and recomputes its hash from scratch. It doesn't reveal what happened — only whether the record of what happened is intact.

Verifying the chain…

3. Program coordinators can get their own eyes on it

Any organization or classroom can add a coordinator as an admin or teacher with direct, independent access to its audit log — no need to take the operator's word for it, or wait for an export.

4. The source code is public

Every claim on this page is backed by code anyone can read on GitHub — including exactly what appendAuditLog() and the hash-chain verifier do. Nothing here has to be taken on faith. github.com/SushilRaj0177/Kehai-Engine

5. Full data export, on request

Any organization or classroom's attendance data and audit log can be exported (CSV/Excel export is built in for attendance; reach out via GitHub for a full audit log export) — nothing here is locked behind a dashboard only the operator can see.

Kehai Engine — Attendance & Event Intelligence