11 Security · Disclosure
Write to us encrypted. Then read our silence.
One address for researchers, one machine-readable file, and a canary mechanism designed so that silence itself carries the signal.
01security.txt — RFC 9116, self-invalidating yearly
Fetch the machine-readable contract.
RFC 9116, served at the canonical path. Human version: write to security@qeryx.com, in English, and the safe harbor at /security#safe-harbor covers good-faith research.
curl -s https://qeryx.com/.well-known/security.txt
Field by field
Contact — the security mailbox. Expires — the file self-invalidates yearly so a stale policy cannot linger. Canonical — the one true location. Policy — the safe-harbor clause. A PGP-clearsigned copy ships after the key ceremony completes; until the signing key exists, the file says so in a comment instead of carrying a signature you cannot check.
02Canary status — nothing is displayed
Look for a live canary. There is none.
No live canary is displayed
The dual-signature reissue ceremony and its monthly cadence have not yet begun for this site. By the canary’s own semantics a stale statement reads as revocation — so this page shows nothing rather than dressing an old date as current. When the ceremony completes, this block carries the signed date, the freshness proof, and the transparency-log reference, renewed monthly.
03Reading it — six observations, six verdicts
Silence is the mechanism.
A gag order can compel silence about a demand. It cannot compel a fresh signature on a statement that is no longer true. The canary affirms, monthly and under two signatures (PGP and ML-DSA-87), that five categories of compelled process have not arrived — and when one arrives, that clause simply stops appearing.
| Observation | Meaning |
|---|---|
| Fresh canary, all 5 clauses, signatures verify | All clear. |
| Not updated by the 15th of the month | Revocation signal — assume compelled silence. |
| A specific clause missing from a new canary | Targeted revocation: that category of process has been received. |
| Signature fails to verify | Key compromise or impersonation. Do not trust. |
| Transparency-log reference missing or unresolvable | Do not trust — the canary may be presented off-log. |
| Freshness proof older than 7 days | Do not trust — possible replay of an old artifact. |
The five clauses
National Security Letters · FISA 702 directives · gagged orders from any jurisdiction · key-disclosure or backdoor demands · compelled silent companion-device linking. Each clause is a separate affirmation, so each can revoke independently.
04The record — the questions we get asked hardest
The hard questions.
Why should I believe a canary at all?
You should believe the mechanism, not the operator: two signatures whose keys live offline, a freshness proof pinned to the news cycle, and a transparency-log entry anyone can resolve. Every failure mode in the table above defaults to “do not trust” — the design errs against us.
What should I do while the canary block is empty?
Treat QERYX as a service without a live canary — because that is what it is today. The architecture is built so the answer to compelled disclosure is the ledger on /security: ciphertext and opaque routing identifiers, whatever is demanded.