Server-side authorship verdict (re-verified against the trusted key valid at event time).
Local re-verification of the sealer signature (when the server returned the public key).
Decoded per the declared content type (string for text/plain, parsed JSON for application/json).
Server-side authorship verdict (re-verified against the trusted key valid at event time).