L⊥ — Integrity plane
Status: stub. Day 4 will publish a real signed receipt as a verifiable artifact on this page — this is the cult-brand killer page, and it earns its keep with bytes you can
cosign verify-blob.
Four cryptographic primitives, layered:
- Ed25519 signature over the canonical decision pre-image.
- Merkle tree rolls every decision in a window into a single root.
- Shamir 3-of-5 threshold key distributes the signing key (Cloudflare Workers Secret + 1Password Business Vault + counsel escrow + cross-cloud HSM + cold air-gapped backup).
- OpenTimestamps anchors the Merkle root to the Bitcoin chain on a daily cadence — third-party-verifiable proof of existence.
A decision artifact is reconstructible from:
- the input bytes,
- the policy bytes (DSL hash),
- the published Core Team Ed25519 public key,
- the Merkle inclusion proof,
- the OpenTimestamps anchor.
No part of this chain depends on knowing who shipped the artifact.