Verdict signing keys

Every verdict carries a signed attestation. This is the key that signs them, and how to check a signature yourself.

The key in use

Fingerprint (the key id)
b1fe8c2eae8162806ed6f0a0ae1c43d3443f99bcf617a798a033a16ddc21950. The SHA-256 of the raw ed25519 public key, in lowercase hex. The published key file is named by this value, and every attestation envelope names the same value as its signature keyid, so the file name and the key bytes bind each other.
In use from
2026-09-25. Every attestation signed under this key carries an assessed date on or after that day.
Published key
b1fe8c2eae8162806ed6f0a0ae1c43d3443f99bcf617a798a033a16ddc21950.pem, a PKIX ed25519 public key in PEM form.
What it signs
One attestation per verdict, at /verdicts/<slug>/attestation.json: a DSSE v1 envelope carrying an in-toto Statement v1. The statement's subject is the weights file digests of the assessed set, its predicate is the committed provenance artefact for that verdict, and its predicateType is assay.co.nz/attestation/admission/v1. The signature is ed25519 over the DSSE PAE preimage, so any DSSE verifier can check it.
Algorithm
ed25519. One signature per envelope, over the DSSE v1 preauthentication encoding of the payload type and payload.

Key custody

The signing key is a local key, not an HSM. The private half lives on one operator host, is never committed to the repository, and is not held in a hardware security module or a key management service. There is no ceremony service behind it.

If that host is compromised, forged attestations become possible. That is the limit of this design. A rotation would replace the key file here and re-sign every attestation.

How to verify

From a fresh clone of the repository, run python scripts/verify-verdict.py. It checks every published attestation: envelope shape, signature, key binding, the weights digests, and that the signed predicate is exactly the committed artefact. It needs only cryptography (pip install cryptography).

Without Python, the script's openssl section gives the same check, and --dump-pae prints the signed preimage for cross-checking.

Before this key existed

The provenance artefacts published before 2026-09-25 carry an attestation pairing whose key_id is 6113f178663ad94ad4b56ddf36291d92683b375c17b00230fd70679a27408af4. That value is an unsigned sentinel, not a key fingerprint: the SHA-256 of a published seed sentence, so anyone can recompute it and see those artefacts predate signing.

A signature proves a verdict is the one we published. Quality and fit on your own tasks are measured by Compare.

Verifying a published verdict yourself? Every verdict ships its signature so you can check it, and the gate runs inside your environment, on your policy.

Book a discovery session