Trust State
Fail-closed canonical assessment
A periodic PGP-clearsigned statement. Trust state is current only when the artifact is present, within its validity period, signed, and linked to a valid canonical hash-chain state.
Fail-closed canonical assessment
Next update: 2026-08-24
Compare all 40 hexadecimal characters
The latest five rotation records are shown. Local PGP verification of the clearsigned artifact remains the authoritative user procedure.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Onyx Mail Warrant Canary ======================== Status Date: 2026-07-25 00:00:07 UTC Next Update: 2026-08-24 Rotation: 13 As of July 25, 2026, Onyx Mail affirms: 1. We have received 0 National Security Letters 2. We have received 0 FISA court orders 3. We have received 0 gag orders preventing disclosure 4. We have received 0 law enforcement data requests 5. No backdoors have been installed in our systems 6. We maintain full control of our infrastructure This statement will be updated monthly. Absence of update should be considered a dead canary. VERIFICATION DATA: Signing Key: 7ADF0933 Current Hash: 6ab582f6cbeb38d1 Previous Hash: 0988b3bbce5e1bce Chain Position: 13 of 13 Contact: [email protected] Timestamp: 1784937607 -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE3KS/uLAo5zWWQhD/i7SThF7ReqwFAmpj/IcACgkQi7SThF7R eqwk2Q//dH5AMxPlPL8bIfIwlHVJIs1fqhmmNp412BBLya00OYre/my9qiT1U4zZ ZfAWO91ZiSpf4vZHSLFUFUwA07/Fe1qShezCnIsbppWm9A7YF4zjbhb0lQP8z9Ns JI8n83t8N7uMDe/nhvEmcRJ9hOkhmThKcONbTPRzSR4+10D1a8gjDvb/3laabcvk on+XvWH+vzdeaw4ARjuAfCDqMNr3fgg9psQUV5KGsWdMVCMvMW2yYdj5DGcGHVJW +dxxqz9gN/icMEy+k2PyBE3mt8fr+56XDnRkKSxLmH4sk/6hknFM5mXb1uFmQHSE s8/Dqb4ToPOvVIe8W0b+Ilhz8Auw2RZANkWqszp4BNbycUBQQ8GCq4SzHX4T6607 4O/FIY8HiQB8hRjDzL/S72G6AuW9jm+jqUf+/Ht9Kg+T+fZOODEbGRrWV/t87WDa Wkshdo8VXxTCJ6PSO2l/Xk4TxX3ishwUvQ1Y7hpAqN+ypSZBoKG0Z4JAUsWCn1/0 3UZjnw1L1qd5dNVx4qy2aE1miUY4D0pmTdv9qFv2drXzfriAwFNeeszhKv5daCph cqiLJR9ZhgcdJWhuj0wnR/Vyl72cmba6AiY+wphBfvipLrYMfrkG6j7MTHECHLCm 6d/hiN6t/2gKfAvxiTULkX3+JZItizRZ94q6DRmRpgnRUJmZFss= =BJ3+ -----END PGP SIGNATURE-----
curl -fSLo onyxmail-canary-public.asc https://onyxmail.net/canary/public.asc
gpg --show-keys --fingerprint onyxmail-canary-public.ascCompare the complete fingerprint shown above through another trusted path before import.
curl -fSLo current_clearsigned.asc https://onyxmail.net/.well-known/canary/current_clearsigned.ascDo not alter whitespace or line endings before verification.
gpg --import onyxmail-canary-public.asc
gpg --verify current_clearsigned.ascConfirm a good signature from the expected full fingerprint, then inspect the status and next-update dates inside the signed text.
A valid signature establishes provenance and byte integrity for the signed statement. It does not prove each claim is factually correct, that the signing environment is uncompromised, or that no event occurred after signing. An absent, expired, altered, or unverifiable canary is not a current assurance.