Free local validator – no sign-up

Knowledge Base Export & Recovery Readiness Validator

Inspect a real CSV, JSON, or ZIP export in your browser. Verify archive integrity, article records, assets, links, redirects, visibility metadata, and an optional post-restore package without uploading knowledge content.

Validate an export
Files, not promisesThe engine reads real records and ZIP entries; it is not a vendor questionnaire.
Evidence stays separateIntegrity, completeness, assets, permissions, and round-trip results keep distinct evidence levels.
Private by designNo package content, filenames, counts, or findings enter analytics; no automatic storage, active rendering, remote asset fetches, or account connection.
Step 1 of 4Load exports

Files remain in this browser tab. Reports store evidence and hashes, not article bodies. Closing or clearing the tab removes the loaded packages.

Load the export evidence

A baseline export is required. Add an optional package exported after a controlled restore rehearsal to compare records, assets, visibility, and checksums.

Baseline export

Use the source package, trusted reference export, or a group of related CSV and JSON files from the same scope and timestamp.

No baseline selectedZIP, CSV, TSV, JSON, JSONL, HTML, Markdown, or text.

Post-restore export Optional

Use a package exported after a restore rehearsal. The validator compares observable records; it does not perform the restore.

No recovery package selectedLeave empty for a single-export inspection.
Safety boundary: encrypted ZIPs, unsafe paths, unsupported compression, oversized entries, nested archives, and suspicious expansion ratios are blocked or withheld. Version 1 limits one evidence set to 25 MiB of input, 5,000 entries, 100 MiB declared expanded, 20 MiB per entry, and 8 MiB per structured text file; ratios above 100:1 warn and above 1,000:1 block. The tool never renders exported HTML or SVG and never follows remote URLs.

What the validator can and cannot establish

A readable archive is not the same as a recoverable knowledge base. The report names the evidence boundary instead of turning every signal into a single readiness score.

Single export

Internal package evidence

Tests archive safety, CRC or hashes, parseable records, field coverage, assets, internal references, redirects, and visibility metadata. It cannot prove that the export is complete without an independent reference.

Reference comparison

Observable loss and drift

A trusted baseline with the same scope and timestamp can expose missing, unexpected, or changed records. A manifest stored inside the same ZIP is weaker evidence than an independent record.

Round trip

Scoped restore comparison

A post-restore export can show whether observable records and assets survived a rehearsal. It does not prove production permissions, search, integrations, RTO, or business continuity.

Methodology KBER-1.0

Every domain receives an evidence level and explicit checks. Verdicts are deterministic gates, not a weighted quality score.

Evidence levelWhat was observedWhat it does not prove
E0 – Not testedA required file, field, mapping, or comparison package was unavailable.Absence of risk.
E1 – Internally observedThe candidate package was parsed and checked for internal consistency.Completeness against the source.
E2 – Integrity comparedCRC or SHA-256 values and declared file counts were compared where available.Authenticity if a package and its internal manifest were altered together.
E3 – Reference comparedStable IDs or exact canonical URLs were reconciled against a trusted baseline.Semantic equivalence or correct live behavior.
E4 – Round-trip comparedA package exported after a restore rehearsal was compared with the baseline.Production recovery certification, RTO, search quality, or permission enforcement.
Verdict order: unsafe or unreadable evidence blocks analysis; critical or high failures mean Not ready; internally sound packages without comparison evidence remain unproven; scoped round-trip evidence passes only when the observable recovery gates pass.

Safety controls for untrusted export files

The validator treats every archive and content field as untrusted data.

Archive boundary

No blind extraction

ZIP central directories are inspected before decompression. Traversal paths, encryption, unsupported methods, impossible offsets, and suspicious expansion are surfaced before entry content is retained.

Content boundary

No active rendering

Exported HTML, SVG, Markdown, and URLs are read as text. Scripts, embeds, images, links, and attachments are never opened or executed.

Storage boundary

No automatic persistence

Raw packages are not placed in localStorage, IndexedDB, cookies, analytics, or a server. Evidence exports require a deliberate download.

Export and recovery validator questions

Does the tool upload or crawl my knowledge base?

No. Selected files are read in the current browser tab. The validator does not fetch remote content, crawl live URLs, connect to a vendor account, or send article content to an AI model. Existing site analytics may receive only one of five generic tool events; filenames, sizes, counts, IDs, verdicts, and findings are excluded.

Does a passing ZIP prove that recovery will work?

No. A valid ZIP proves only that the inspected container and entries passed the stated checks. Recovery evidence requires a controlled restore rehearsal and a post-restore comparison.

Can the validator read every ZIP?

It supports ordinary non-encrypted ZIP entries using Store or Deflate. Encrypted, multi-disk, unsafe, oversized, or unsupported entries are blocked or withheld. Browser memory limits still apply.

Why are some checks marked Not tested?

The tool does not invent evidence. If permissions, redirects, versions, translations, checksums, or a recovery package are absent, their checks remain visibly untested.

Does the tool compare article meaning?

No. It compares declared fields, exact stable IDs or URLs, normalized text hashes, file hashes, and explicit relationships. A subject-matter expert must assess whether changed wording is correct.

Can it validate private-content security?

It can detect visibility metadata and restricted-to-public drift between packages. It cannot prove that a live platform enforces access; test real personas in a safe staging environment.

What is stored in the evidence JSON?

The export contains file metadata, hashes, mappings, findings, counts, and reconciliation results. It excludes raw article bodies and raw asset bytes.