SIGNERS
Every byte of data, signed at the moment of creation.
Not after the fact. Not reconstructed from logs. Each product signs with its own Ed25519 key, and every key is published here for independent verification.
How it works
Each DRM3 product signs with its own Ed25519 keypair. Keys are deterministic and product-scoped: DomainDrift signs DNS scans, the signals pipeline signs open-data fetches, the news pipeline signs article analyses. Every key is published here for independent verification.
Every provenance receipt includes the signer's public key. To verify a receipt, check that the public key appears in the registry below, then verify the Ed25519 signature over the receipt payload. Anyone can run the math, and our name is on every key.
The chain of custody
One root of trust, a certificate for every signer beneath it, and every key with its own lifecycle. Retired and compromised keys stay in the record on purpose: that is how a verifier learns which signatures to refuse.
Loading signer registry...
