Overview
Witness network
Independent witnesses co-sign your history's growth, so hiding or rewriting the recent past stops being deniable.
Receipts verify offline, forever. The one thing an offline check cannot prove is that you are looking at the latest history.
Two attacks exploit that gap, and both are free:
| Attack | What it looks like |
|---|---|
| Withholding | Recent records "don't exist" — you get a truncated history that verifies cleanly |
| Equivocation | Two verifiers are shown two different histories, each internally consistent |
Witnesses co-sign every step forward. Rolling history back then means contradicting signatures sitting in append-only logs — the rollback stops being a deletion and becomes evidence.
Start here
I publish attestations
Anchor your aggregate so a rollback is attributable.
I verify attestations
Check an anchor and read the freshness result.
I want to run a witness
One container, five minutes.
Two things never change:
- Verification stays offline and free. An anchor adds one labeled fact —
fresh,stale, orunanchored— beside the verdicts, never inside them. - Witnesses see aggregates only. No per-call rows, no counterparties, no tool names. Your private log never leaves your infrastructure.