Custody · public-key and release disclosure
Custody disclosure
Cloudflare Pages serves the public board and evidence. Publication is separate from signing: each artifact must carry a verifiable signature over its own bytes and name the public key that verifies it. The board snapshot uses did:web:csoai.org#board-attestation-1; issued measurement cards can use a different key. Some supporting fact runs are content-addressed but unsigned, and must be described as such. The historical 22-axis key below identifies a frozen configuration, not today's board count. Check the current count at /api/gspc.
Public key disclosure
| Key id | Algorithm | Signs |
|---|---|---|
| did:web:csoai.org#board-attestation-1 | Ed25519 | Public-root envelope (/root.json) |
| did:web:csoai.org#card-attestation-1 | Ed25519 | Measurement cards (card-v0 sig_ed25519; shape-A chain cards, Aug 2026) |
| did:web:csoai.org#site-release-1 | Ed25519 | Site release attestation |
| did:web:csoai.org#estate-chain-1 | Ed25519 | Estate chain links |
| did:web:csoai.org#gspc-board-22axis-2026 | Ed25519 (3-party) | Historical 22-axis board configuration attestation; not the current board count |
Full public key material (JWK): /.well-known/did.json · key-discovery document: /.well-known/scitt-keys (we_operate_a_ts: false — discovery only, never a transparency-service claim).
Rotation & retirement
A signature names the key used at issuance. Verifying an older artifact still requires the corresponding historical public key and the exact signed bytes. If that key or those bytes cannot be retrieved, report the result as uncheckable; do not infer validity from today's DID document. Check the corrections ledger for any disclosed key or evidence changes.
What enforces this page
The release checks below concern publication integrity. They do not prove that every supporting run is signed or Bitcoin anchored:
- Release gate. The publisher checks the source tree, built output and root witness before uploading.
- Served-byte readback. The release is checked against the public site after upload; a deploy log alone is not proof of what a reader receives.
- Corrections ledger. Our own failed attestations stay visible — published, not buried (/api/corrections).
What we do not hold
This page is a custody statement, not a SOC 2 report, not a certification, and not a claim that a ceremony has been independently audited. No HSM claim either. If those ever change, this section changes — with a dated entry in the corrections ledger, not a quiet edit.
- Verify the signature and key named by each artifact; publication alone is not a signature.
- No board writes from MCP. MCP stays read-only.
- Verify a card at /gspc-verify.