codexproof

One answer. Evidence across named domains. Declared provenance checked in your browser.

verifier loading…
/alpha
pineconejs⚷ cbf368eb…
/beta
supabasejs⚷ 6bffb8c9…
/gamma
qdrantrust⚷ b9909ffd…
/delta
streamjs⚷ a91c1b00…
{ node · cid · signer · sig }INTEGRITY → AUTHENTICITY → AUTHORIZATION⚷ /alpha⚷ /beta⚷ /gamma⚷ /deltaENTITY/alpha/evidence/e1ENTITY/beta/evidence/e1ENTITY/gamma/evidence/e1ENTITY/delta/evidence/e1ENTITY/beta/answer/a1
real Ed25519 + BLAKE3, run client-side via WebAssembly
audit log, one line per real verification call

    Per-store performance and unit economics

    Measured off vs JIT latency per store (localhost floor) and the marginal dollar cost the provenance layer adds, re-runnable with cargo run --release -p prov-bench. Prices are list-price assumptions; this measures verifiable provenance, not correctness.

    loading measured numbers…

    Verification under chosen anchors

    Each node's canonical bytes are checked against its content-id, its Ed25519 signature is checked over that content-id, and its signer is authorized under a consumer-chosen anchor whose namespace covers the name. The demo runs its heterogeneous stacks under one operator, and its configured anchor set represents those local choices rather than separate operators; there is zero global authority. A pass authenticates the bytes and signer-declared lineage, not factual truth or the declaration's faithfulness to an actual computation.

    The thin waist

    “A waist that only works in one language is just a library; one that spans React/JS and full-stack Rust is a real interoperability layer, the way IP works identically across any OS or hardware.”

    The WebAssembly verifying this page is compiled from prov-core, the exact Rust crate the backends sign with. Heterogeneity in (Pinecone/JS, pgvector/JS, Qdrant/Rust, and a deliberately unlike intel feed); one verifiable object out.