§ release integrity · a field demonstration

Not security theater.

A sanitized, interactive map of how a Point 53 release earns its way from a dev box to your machine. Every sphere is a machine or a key. Every arrow is bytes moving or a check running. Our coordinates are blacked out — ██████ — the checks are not: every one of them is public, scriptable, and built to fail loudly.

operator machine public host signing key you bytes move a check runs a signature attack ██████ redacted — the value exists; the internet doesn’t get it
§ appendix · what’s shown vs. what isn’t

Public — shown, and checkable

  • · The signing policy: 2-of-4, signer ids and key types, published in three places at once
  • · The append-only release ledger and its detached signatures
  • · Both verifier scripts — small enough to read before you trust them
  • · Reproducible builds: the wheel is a pure function of the tagged source
  • · The package index is derived from the ledger, never the reverse
  • · A daily standing audit that anyone can also run by hand, from anywhere

Redacted — exists, not for the internet

  • · Hostnames, ports, and addresses of everything left of the boundary: ██████
  • · The release machine’s codename: ██████ (it’s a good one)
  • · Physical storage site of the cold key: ██████
  • · Operator scripts and their internals: ██████.sh
  • · The number of other things we are not telling you: ██

That asymmetry is the design: the secrets are locations and credentials. The checks are public. Theater does it the other way around.