Trust

Built to be verified, not trusted.

A record that must be believed is worth less than one that can be checked. Everything below can be checked by you, with no account and no call to us.

Every fact

Quoted or absent

Each fact carries the verbatim clause, the source URL and the date read. A fact whose quote is not found in the source is held, never published.

Every record

Signed and chained

Snapshots, facts, changes, checks and corrections are appended to one Ed25519-signed hash chain. The recipe and the public key are published at /v1/keys.

Every day

Anchored in public

The chain head is committed to a public git repository daily. Not even the operator can rewrite history without a visible commit.

Every check

A receipt you keep

Counterparty checks return a self-contained receipt. Verify one here, or offline with the public key alone.

Every dispute

Public corrections

Anyone may dispute a fact from its profile. Requests and resolutions are shown on the profile and ledger-entered; nothing is edited silently.

Never

No payloads

The check API takes data classes only; it has no field for content. Watchlists are vendor names. Alert channels are sealed at rest.

Live health

The same report our uptime monitor reads, at https://api.openwake.ai/health/deep.

Health is unavailable right now, which is itself the finding: https://api.openwake.ai/health/deep returns 503 when something is wrong.

What we hold, and where

Our own subprocessors, with the same 30-day notice we expect of vendors: /legal/subprocessors. The full security model: /docs/security. Privacy policy: /legal/privacy. DPA: /legal/dpa.

Security contact: security@openwake.ai. We acknowledge within two business days and fix critical issues within seven. No certifications yet; a SOC 2 Type I is planned. Until then, verify instead: pnpm receipt:verify, pnpm ledger:verify, and the anchors in the repository.