Pin the key. Then stop trusting us.
A verifier is only worth opening if it can check a signature you did not make. Signet holds one key on the server for exactly that reason. Its address is below. Write it down, and from then on our word about anything it signed stops mattering.
The private half sits in a server environment variable and has never been in this repository, this page, or a build artifact. If it ever leaks, the fix is to publish a new address here and treat everything signed by the old one as unproven from that date.
It signs a number you computed.
You hash your content in your own browser and send the digest. The notary signs that digest and hands the signature back. It never receives the content, so it has nothing to store, nothing to leak, and nothing to hand over.
It proves a moment.
A notary signature says this digest reached this key at this time. That is the entire claim, and it is worth something precisely because it is small.
It proves nothing about the work.
The notary cannot read what you hashed and would not judge it if it could. Correct, useful, safe: none of those words belong on a receipt.
It carries no public timestamp.
Nothing is published on chain, so the time on a receipt is the notary's clock, not the network's. Anchoring would change that and has not been built.