About Onyx Mail
Evidence Before Assurance

Onyx Mail is a verifiable privacy infrastructure project, established in 2022. It publishes its identity, policies, Tor access, and verification materials, and stands behind each with a public artifact anyone can inspect.

Institutional Standard

Evidence precedes assurance

Onyx Mail separates implemented controls, published artifacts, institutional statements, and unresolved limits.

What Onyx Mail Publishes

Onyx Mail publishes its identity, policies, access points, and verification materials as inspectable artifacts.

Claim Standard

A public claim must map to source, response behavior, signed material, or a bounded policy.

Architecture

Implemented and bounded controls

These controls describe how Onyx Mail is built and served.

Restricted Runtime

One first-party stylesheet and one first-party script serve the interface. Core content remains readable without JavaScript.

Response Controls

HTML responses publish a restrictive Content Security Policy and transport-sensitive security headers.

Published Trust Anchors

The full canary signing fingerprint, security contact fingerprint, and Tor v3 address are published for comparison.

Explicit Limits

Published controls reduce specific risks. They do not establish universal confidentiality, anonymity, availability, or operator integrity.

Current Record

Onyx Mail trust state

Status is derived from the rotation-owned canary artifact and fails closed when freshness, signature data, or hash-chain integrity is absent.

2022

Published

Live

Same origin

Monthly

Current

Inspect the Onyx Mail record

The registry identifies what is published, how to verify it, and what the result does not establish.

View Verification Registry