Verdict signing keys
Every verdict carries a signed attestation. This is the key that signs them, and how to check a signature yourself.
The key in use
- Fingerprint (the key id)
b1fe8c2e. The SHA-256 of the raw ed25519 public key, in lowercase hex. The published key file is named by this value, and every attestation envelope names the same value as its signature keyid, so the file name and the key bytes bind each other.ae816280 6ed6f0a0 ae1c43d3 443f99bc f617a798 a033a16d dc21950 - In use from
- 2026-09-25. Every attestation signed under this key carries an assessed date on or after that day.
- Published key
- b1fe8c2e
ae816280 , a PKIX ed25519 public key in PEM form.6ed6f0a0 ae1c43d3 443f99bc f617a798 a033a16d dc21950.pem - What it signs
- One attestation per verdict, at /verdicts/<slug>/attestation.json: a DSSE v1 envelope carrying an in-toto Statement v1. The statement's subject is the weights file digests of the assessed set, its predicate is the committed provenance artefact for that verdict, and its predicateType is assay.co.nz/attestation/admission/v1. The signature is ed25519 over the DSSE PAE preimage, so any DSSE verifier can check it.
- Algorithm
- ed25519. One signature per envelope, over the DSSE v1 preauthentication encoding of the payload type and payload.
Key custody
The signing key is a local key, not an HSM. The private half lives on one operator host, is never committed to the repository, and is not held in a hardware security module or a key management service. There is no ceremony service behind it.
If that host is compromised, forged attestations become possible. That is the limit of this design. A rotation would replace the key file here and re-sign every attestation.
How to verify
From a fresh clone of the repository, run
python scripts/verify-verdict.py. It checks every published
attestation: envelope shape, signature, key binding, the weights digests, and
that the signed predicate is exactly the committed artefact. It needs only
cryptography (pip install cryptography).
Without Python, the script's openssl section gives the same check, and
--dump-pae prints the signed preimage for cross-checking.
Before this key existed
The provenance artefacts published before 2026-09-25 carry an attestation
pairing whose key_id is
6113f178.
That value is an unsigned sentinel, not a key fingerprint: the SHA-256 of a
published seed sentence, so anyone can recompute it and see those artefacts
predate signing.
A signature proves a verdict is the one we published. Quality and fit on your own tasks are measured by Compare.
Verifying a published verdict yourself? Every verdict ships its signature so you can check it, and the gate runs inside your environment, on your policy.
Book a discovery session