Skip to main content
Patrick Colm Audley

Patrick Colm Audley

Hacker · Full-Spectrum Technologist · Polymath

Trust & Provenance

Trust & provenance

This site's authenticity is independently verifiable — identity, keys, signatures, and privacy posture in one place, and checkable live in your own browser.

Verifiable identity and publication history

Each version of the did:webvh 1.0 identity is preserved in a signed, append-only log, allowing historical resolution and verification of authorized key changes. A separate three-version rotation demonstration shows the original key authorizing its replacement, followed by an update signed by the new key. Builds verify the logs with TypeScript and an independent Python implementation.

The publication statement receives an inclusion receipt from the SCITT transparency service operated by Blackcat Informatics. The publisher and log share an operator. Receipts establish registration and byte integrity; they do not establish factual truth or independent endorsement. The service publishes its registration policy, trust anchors, signed tree roots, inclusion proofs and consistency proofs. Architecture: RFC 9943. Receipts: RFC 9942. The SCRAPI interface follows draft-11, which remains a draft.

Choose “Verify this publication” in the evidence browser to verify identity history and the receipt. Scheduled check status reports the last attempt, last success and staleness: identity, receipts and history continuity hourly; MCP, A2A, skills, owner isolation, three languages and exact passages daily.

Verify in your browser

The checks below run locally in your browser (WebCrypto + same-origin fetches): they re-compute hashes and verify the provenance manifest's Ed25519 signature against the published key.

    What these checks prove — and don't

    These checks prove that downloaded artifacts match published hashes, signed artifacts verify against the published artifact-signing OpenPGP key, and the provenance manifest verifies against the published Ed25519 key. They do not prove that every biographical claim is externally verified, nor do they replace independent verification of third-party profiles.

    Identity

    Keys & encryption

    The site publishes a long-term PGP identity key, a separate OpenPGP artifact-signing key, and an Ed25519 key for its provenance manifest. HTTP response signatures are not currently emitted.

    Signed artifacts & content provenance

    Verification recipes

    Import the published key, verify a signed artifact, then inspect provenance:

    # inspect the key's fingerprint BEFORE importing — compare it to the one above
    curl -s https://patrickaudley.com/pgp/github-signing.asc | gpg --import-options show-only --with-fingerprint --import
    
    # then import, fetch a signed artifact + its signature, and verify
    curl -s https://patrickaudley.com/pgp/github-signing.asc | gpg --import
    curl -sO https://patrickaudley.com/llms.txt
    curl -sO https://patrickaudley.com/llms.txt.asc
    gpg --verify llms.txt.asc llms.txt
    
    curl -s https://patrickaudley.com/.well-known/content-provenance.json | jq '.subjects[].sha256'

    Page integrity

    • This page's scripts and styles are pinned with SRI hashes (the live check above recomputes and compares them).
    • Build: e7289c0 · generated

    Security contact

    Privacy posture

    Mail & transport security (DNS)

    Published records for patrickaudley.com (the live check fetches them via DNS-over-HTTPS):

    RecordPosture
    SPF-all (strict) include:spf.blackcat.ca
    DKIMpublished Google selector
    DMARCp=reject sp=reject
    MTA-STSenforce Google MX
    TLS-RPTenabled
    DNSSECsigned ECDSAP256SHA256

    MTA-STS policy

    Standards index

    StandardImplements
    W3C DID/.well-known/did.json
    WebFinger (RFC 7033)/.well-known/webfinger
    OpenPGP WKD/.well-known/openpgpkey/
    RFC 7929 (DANE OPENPGPKEY)…_openpgpkey.<domain> (DNSSEC)
    RFC 9116/.well-known/security.txt
    RFC 9421/.well-known/http-message-signatures-directory
    RFC 9264/.well-known/api-catalog · catalog
    Custom signed provenance/.well-known/content-provenance.json
    NIP-05/.well-known/nostr.json
    GPC/.well-known/gpc.json