05 Legal
Transparency Report
What we can produce when compelled, and the public record of every time we are asked.
Status
QERYX v1.0 has not been released yet, so no reporting period has begun and no transparency report has been published. When the first report publishes, it appears on this page before anywhere else, and every number in it will be a real count — this page carries no statistics until then.
What every report will contain
The format is fixed now, before the first request arrives, so the report can never be shaped around what it has to disclose:
- The number of legal requests received, broken down by type and requesting jurisdiction.
- What was produced in response, item by item — enumerated against the categories the Privacy Policy says exist.
- The number of accounts affected by any production.
- The number of requests we contested or found nothing responsive for.
- Where the law permits us to say nothing about a request, the report says exactly that, in those words.
Publication cadence and the standing commitments around it are set with counsel at first publication and then stated here permanently.
What a legal demand recovers
The architecture fixes the ceiling on any production before a request is ever made. A hostile legal demand recovers opaque ciphertext blobs, aggregate counters, and — for messages still inside the offline queue — opaque routing identifiers under the published retention ledger. Message content cannot be produced because the relay never holds the keys: breaking a sealed conversation requires breaking both X25519 and ML-KEM-1024.
The standing response
“We received your request. The QERYX infrastructure is designed so that we cannot read user message content. What exists to produce is enumerated in our published privacy policy: sealed ciphertext, opaque routing identifiers under a published retention ledger, and aggregate counters.”
We cannot disclose what we do not hold. Conformance evidence an evaluator can verify line by line lives in the Trust Center.