Custody · public-key and release disclosure

Custody disclosure

Cloudflare Pages serves the public board and evidence. Publication is separate from signing: each artifact must carry a verifiable signature over its own bytes and name the public key that verifies it. The board snapshot uses did:web:csoai.org#board-attestation-1; issued measurement cards can use a different key. Some supporting fact runs are content-addressed but unsigned, and must be described as such. The historical 22-axis key below identifies a frozen configuration, not today's board count. Check the current count at /api/gspc.

Public key disclosure

Key idAlgorithmSigns
did:web:csoai.org#board-attestation-1Ed25519Public-root envelope (/root.json)
did:web:csoai.org#card-attestation-1Ed25519Measurement cards (card-v0 sig_ed25519; shape-A chain cards, Aug 2026)
did:web:csoai.org#site-release-1Ed25519Site release attestation
did:web:csoai.org#estate-chain-1Ed25519Estate chain links
did:web:csoai.org#gspc-board-22axis-2026Ed25519 (3-party)Historical 22-axis board configuration attestation; not the current board count

Full public key material (JWK): /.well-known/did.json · key-discovery document: /.well-known/scitt-keys (we_operate_a_ts: false — discovery only, never a transparency-service claim).

Rotation & retirement

A signature names the key used at issuance. Verifying an older artifact still requires the corresponding historical public key and the exact signed bytes. If that key or those bytes cannot be retrieved, report the result as uncheckable; do not infer validity from today's DID document. Check the corrections ledger for any disclosed key or evidence changes.

What enforces this page

The release checks below concern publication integrity. They do not prove that every supporting run is signed or Bitcoin anchored:

  • Release gate. The publisher checks the source tree, built output and root witness before uploading.
  • Served-byte readback. The release is checked against the public site after upload; a deploy log alone is not proof of what a reader receives.
  • Corrections ledger. Our own failed attestations stay visible — published, not buried (/api/corrections).

What we do not hold

This page is a custody statement, not a SOC 2 report, not a certification, and not a claim that a ceremony has been independently audited. No HSM claim either. If those ever change, this section changes — with a dated entry in the corrections ledger, not a quiet edit.

  • Verify the signature and key named by each artifact; publication alone is not a signature.
  • No board writes from MCP. MCP stays read-only.
  • Verify a card at /gspc-verify.