Skip to content

byhumans Transparency log

English español

Transparency log

Every credential we issue is recorded here as a digest. This page shows the root we have committed to, and the signature that pins it.

bh1:log:one

Current head

Entries
9
Merkle root
9071e64e35f707a781252ccce7a361a27f174fcdb218f2238c7b355bf9fdaed8
Signed
signed by the log
Log key
bh1:logkey:fixture-01 Pin this key somewhere we do not control. Serving it next to the signature does not prove it is ours.
Public key
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEzPvacmRfofoOShTnqysuOdxQHkjg2tPXfrs6v5dIYl/1CAwjm9r3Z9AcgBoqoxqYodF2WbUMdq0Xjnfzv5MAZA==
Commitment
ccad3c34067d3cfd8e446206d3dc80b3692ea5e0318cf8b35146d7831d49dea9 Worth keeping. Two of these for one tree size, differing, is proof we published two histories.
Checked
Every check on this page ran while you waited. Nothing here is a stored verdict.

Every head we have published

The head above proves we committed to a tree. On its own that is compatible with our having deleted an entry last week and rebuilt the tree around the gap, because every surviving entry would still prove inclusion against the new root. What rules that out is the chain below: each root has to contain the one before it as a prefix.

  1. Entries 4 5681d9bf5e8ad3d25f543ad81eccfe184c388f352f8458c935ab3283a4444066 signed by the log d54238042f80b7319c7425ae87696092b65d767ed6327ce67c7386600bf421c8
  2. Entries 7 c28cda430ae4faa90140a418c4fe78bdba01c9c0274da05f2494b8e1bffc8f06 signed by the log 1848c78d469323f59325765b4d02843e7700cb1f447ee70165d4c1903fc61338
  3. Entries 9 9071e64e35f707a781252ccce7a361a27f174fcdb218f2238c7b355bf9fdaed8 signed by the log ccad3c34067d3cfd8e446206d3dc80b3692ea5e0318cf8b35146d7831d49dea9
4 → 7
the earlier tree is contained in the later one RFC 6962 consistency proof, 1 hash
7 → 9
the earlier tree is contained in the later one RFC 6962 consistency proof, 5 hashes

How this constrains us

Removing an entry, reordering two, or editing one changes the root, so the signature above stops covering the tree. The old signature does not disappear: anyone who kept it holds two signed heads that disagree, which is permanent public evidence of tampering. That is the whole security argument, and it works only because we cannot un-publish a signature.

What this page does not prove

It does not prove that these are all the heads we ever published. A head we suppressed would leave a chain that still verifies. Only somebody who recorded a head at the time can close that gap, which is why an outside witness is part of the design rather than a courtesy.

Check this yourself

Fetch it on a schedule, record the commitment, and compare. An outside witness keeping that history is what turns this log from a promise into a constraint.