revocationCheckedAt

When this device last established the issuer's revocation status (fetched/synced the online status list). null means it never has — so revocation can't be confirmed offline and the verdict is "valid offline, revocation not established" rather than a full green. The verifier UI surfaces this as "Last established: …" so an officer knows how current the revocation answer is.