The website today
These details come from the published website release. The mail service is still in development.
| Captured | |
|---|---|
| Release | 20261005T095440Z-refresh.4w6hZ5 |
| System | Debian GNU/Linux 13.7 |
| Web server | Caddy 2.6.2-12+deb13u1 |
| Website build | Zola 0.23.6 |
| TLS issuer | Actalis |
| Public IPs | 152.53.22.2482a03:4000:6c:b55::1 |
| Mail service | Not in production yet |
| Independent backup | Not configured yet |
| Independent status page | Not configured yet |
Download the manifest and evidence
The signature covers the exact manifest bytes. The manifest records hashes of the inventories and published files. It is our own dated inventory. Its signature does not replace an independent audit or an availability measurement.
- Website manifest (JSON)
- Detached signature (Ed25519)
- Public verification key (PEM)
- Website components and fonts (CycloneDX)
- Debian package inventory (CycloneDX)
- Files and SHA-256 hashes (JSON)
- Manifest schema (JSON)
Verify the signature
Public key fingerprint (SHA-256 of DER encoding):58f8495990a76f5049e5626e12ebdd4729bcf60abb7720123d0946ea08f3fab9
After downloading the manifest, signature and public key, verify the signature with OpenSSL. Obtain the verification key through a trusted source; downloading it from the same website alone does not establish the operator's identity.
openssl pkeyutl -verify -pubin \
-inkey manifest-public-key.pem \
-rawin -in manifest.json -sigfile manifest.sigWhat the manifest records
The signed sovereignty manifest covers only the public website and its host at the stated observation time. It is generated from the actual host inventory and website release files. Generation from OpenTofu or Ansible state has not been set up.
The downloads contain the manifest, the associated software inventories, the public signing key and the signature. Confirmed operator details are included; unconfirmed provider and location information remains explicitly unresolved. The planned mail platform is outside this operational record.
Verify the signature
The published key lets you check whether the manifest has changed since signing. Verification instructions accompany the downloads. If you know the key independently, you can also establish its origin. When first downloading the key from the same website, trust in that key rests on the website's HTTPS connection.
The signature is a statement by the website operator. It does not replace checks of contracts and data centres or an external security or privacy audit. The inventories are a snapshot; they do not demonstrate continuous availability.
Government requests
An operator-confirmed report is not yet available. We therefore do not currently publish a count of government requests.
For the future mail service, the plan is to review requests legally, notify affected users where permitted and publish regular transparency reports. That policy still needs to be developed.
Audit reports
No external audit or penetration test result has yet been published for this website or the planned mail service. Internal operational checks and package inventories are not external certification. Independent review results are intended to be published before the mail service launches.
Availability
This website is already online; the mail service has not launched. An independent status page has not been set up. A successful request or a release manifest is not a long-term availability record. We currently publish neither a measured availability rate nor an availability guarantee.