§ release integrity · a field demonstration
Not security theater.
A sanitized, interactive map of how a Point 53 release earns its way from a dev box to your machine. Every sphere is a machine or a key. Every arrow is bytes moving or a check running. Our coordinates are blacked out — ██████ — the checks are not: every one of them is public, scriptable, and built to fail loudly.
operator machine
public host
signing key
you
bytes move
a check runs
a signature
attack
██████ redacted — the value exists; the internet doesn’t get it
§ appendix · what’s shown vs. what isn’t
Public — shown, and checkable
- · The signing policy: 2-of-4, signer ids and key types, published in three places at once
- · The append-only release ledger and its detached signatures
- · Both verifier scripts — small enough to read before you trust them
- · Reproducible builds: the wheel is a pure function of the tagged source
- · The package index is derived from the ledger, never the reverse
- · A daily standing audit that anyone can also run by hand, from anywhere
Redacted — exists, not for the internet
- · Hostnames, ports, and addresses of everything left of the boundary: ██████
- · The release machine’s codename: ██████ (it’s a good one)
- · Physical storage site of the cold key: ██████
- · Operator scripts and their internals: ██████.sh
- · The number of other things we are not telling you: ██
That asymmetry is the design: the secrets are locations and credentials. The checks are public. Theater does it the other way around.