Trust & evidence
Verify the system before you enroll.
Follow the public trust path from published keys to installed policy and the record you can inspect. Each tile opens the underlying surface.
The whole public path
Start with the published signing identities, understand the bootstrap contract, inspect the exact files in the signed bundle, then verify local installation and service readiness.
That each stage has an inspectable source and that no raw service response has to be mistaken for a customer explanation.
Technical verification commands
curl -sS https://governance.mistwire.io/v1/trustcurl -sS https://governance.mistwire.io/v1/bootstrapcurl -sS https://governance.mistwire.io/v1/bundle/stablecurl -sS https://governance.mistwire.io/v1/healthzcurl -sS https://governance.mistwire.io/v1/blob/<sha256> | shasum -a 256The human-readable account and assembled record available to an enrolled user.
What we processCategories, purpose, retention, processors, retrieval, and explicit limits.
A signed receipt binds an enrolled key, observation, bundle, time, and service verdict. It attests installed governance state; it is not a per-action activity log or proof that a customer-controlled machine reported truthfully.
Limitations
A machine you control can misreport what it saw.
The receipt is the service's judgment of a report. If the report is wrong, the judgment is wrong with it. Here is what that looks like today, and what changes next.
- The report says
- Hook present
- The receipt says
- Compliant
- What is recorded
- The report and the disk agree.