LIVE STATUS: /uptime·PUBLIC CATALOGUE · SOURCE-ATTRIBUTED
DATA WITH RECEIPTS · ED25519 · RFC 3161·--:--:-- UTC
VERIFY · DON'T TRUST

Don't trust us. Verify us.

Everything we claim is checkable. Every answer is Ed25519-signed, every datapoint names its source and licence, our record is an append-only transparency log, and our security posture is stated plainly, including what we haven't built yet. Check all of it yourself, even against us.

VERIFY IN 60 SECONDS

Four ways to check us.

in your browser

Verify a signature

Fetch or paste any signed response and check its Ed25519 signature client-side at /verify, change one byte and it fails.

published keys

Our public keys

Every signature verifies against the keys at /.well-known/keys. Reference verifiers exist in Python, JavaScript and Rust.

append-only

Transparency log

Signed records are committed to a public Merkle transparency log and time-stamped by an independent RFC 3161 authority (proof it existed at time T, and tamper-evidence), a history that can't be quietly rewritten.

open spec

Read the standard

The signing and canonicalization spec is open at /standard, so you can verify independently. You never take our word for it.

WHAT WE HOLD, AND DON'T

We ground machines, we don't monitor people.

Dynamic Feed is a read-only data source. The MCP endpoint is keyless; an optional API key only adds rate and usage controls and identifies your account. We don't require, and by construction don't store, personal data, we don't keep your prompts or queries, and we never sell or share data with third parties. Every value we serve carries its source and licence, and any datapoint can be checked at /sources.

SECURITY & COMPLIANCE, WHAT'S TRUE TODAY

Straight talk, because buyers verify.

Exactly where we stand. Nothing we haven't built is implied as live.

transport

TLS everywhere

All traffic is served over HTTPS/TLS, with a Content-Security-Policy enforced site-wide.

data boundary

No personal data

Keyless reads; no prompts or queries stored; nothing sold or shared. Read-only by design.

audit trail

Signed & time-stamped

Ed25519 over canonical bytes; fingerprints time-stamped by an independent RFC 3161 authority. Independently verifiable, even against us.

provenance

Licensed sources

Source, licence and freshness attached to every value; inspect any datapoint at /sources. Full catalog at /sources.

sso · rbac

On the roadmap

SSO / SAML and role-based access are not live yet, available on an enterprise contract. We won't claim them before they ship.

soc 2 · dpa

On request

SOC 2 and a signed DPA are pursued against a signed enterprise requirement, not claimed speculatively. We hold no certification we haven't earned.

ALWAYS-ON

Live status, measured.

Real-time health and measured uptime are public at /uptime and /ops. A formal uptime SLA and priority support are part of an enterprise agreement. For data-handling questions or a DPA, contact [email protected].

PROOF, NOT PROMISES

Verify everything. Trust nothing on faith.

That's the whole point of Dynamic Feed, a data layer an agent or a robot can check, not just consume.