SECOND MEASUREMENT SM-005

Meta's whitepaper says its private-AI log refreshes every 3 hours. Since January it's been every 6

Markovian ProtocolMeasured 2026-09-30Status: sent to Meta 2026-10-01, response pendingDOI: 10.5281/zenodo.23122986

When WhatsApp or Meta's AI glasses hand a request to Meta's private AI servers, those servers may only run software listed in a public log that Cloudflare keeps. Meta's whitepaper says the list of pulled software is republished every 3 hours. We fetched all 2,690 entries since June 2025: it slowed to every 4 hours in October and every 6 since January, and the whitepaper's March update still says 3. The server software is described as weekly, but only 37 of 70 weeks have a new entry, including a six-week stretch with none.

The short version

Disclosure: Markovian Protocol holds no financial position in any organisation named here, was paid by no one for this work, and showed it to no one before publication except the organisation measured. How we work.

Details

Private Processing runs requests on locked-down servers (confidential virtual machines). Before a phone sends anything, it checks the server's software against Meta's public log, which Cloudflare runs through its key transparency auditor, Plexi. Two kinds of thing go in: images of the server software, and a list of software that's been pulled. A phone needs a fresh copy of that list, because each signed list expires after 24 hours.

What they said, what we found

Meta saidWe found
“The list is published every 3 hours” (whitepaper V2, March 2026)1Every 3 hours until September 2025, every 4 from October, every 6 since January. V2 was written two months after the switch to 6.
“each signature expires every 24 hours”1The longest gap between lists is 19.2 hours (April 2026), so none expired. But at 6 hours, a phone can now miss 3 updates in a row before its list expires, down from 7.
Server software “releases are on a weekly cadence”137 of 70 weeks have a new entry. The longest stretch without one is six weeks, mid-December 2025 to late January 2026.
“an append-only, publicly-witnessed transparency ledger” (blog post, 23 September)2Their own whitepaper calls it “not a Merkle-tree based transparency ledger but a simple log maintained by a third-party”.1 Each record carries one signature, Cloudflare's. Without a tree, nobody can prove an old record was never swapped out.

The list that slowed down

Month (UTC)IntervalsMedian gap (h)Longest gap (h)
2025-062183.09.4
2025-072903.06.0
2025-082563.03.1
2025-092393.06.0
2025-101894.04.6
2025-111834.04.0
2025-121864.04.0
2026-011416.06.0
2026-021156.06.0
2026-031256.015.7
2026-041206.019.2
2026-051266.06.1
2026-061246.06.0
2026-071266.06.1
2026-081276.06.0
2026-091246.08.0

Every pulled-software list, prod.pc.revocation_list numbered 1 to 2,690, 7 June 2025 to 30 September 2026. None missing.

None of the 2,690 lists is missing. The schedule changed twice, and the whitepaper didn't.

The weekly software that isn't weekly

NamespaceIn the whitepaper's listEntriesFirstLast
prod.pc.orchestrator.cvmyes192025-06-062026-04-15
prod.pc.predictor.cvmyes242025-06-062026-06-22
prod.pc.cvmno772026-03-032026-09-29

Entries on Plexi, 30 September 2026.

The busiest of the three, prod.pc.cvm, isn't in the whitepaper's list at all. It started in March and has entries in 16 of the 30 weeks since. There are two ways to read the gaps: Meta released less often than weekly, or servers ran software that never got a new entry. The log alone can't tell which. The whitepaper says software expires “on the order of weeks”, which is why the six-week stretch is the one worth Meta's answer.

What kind of log it is

Each record carries one signature, from Cloudflare's auditor key.3 Records are numbered in order, and the whitepaper says there's no Merkle tree, so there are no proofs that the log only grew. Anyone can show that today's records are signed and numbered, but not that an earlier one was never replaced. Each record's fingerprint is public. The whitepaper doesn't say whether that fingerprint is the software measurement itself or a hash over a record containing it.

How we checked

Plexi serves one signed record per numbered entry for each name in the log. It doesn't say which number is the newest, so we found the newest by halving the range until we hit it. Then we fetched every pulled-software list from 1 to 2,690 and every entry for the three server-software names, and counted the weeks that have at least one. One mistake we caught: our first run sent 8 requests at once and got rate-limited, and the failures looked like gaps of up to 162 hours. The numbers here come from a slower run where all 2,690 came back.

The evidence

Every quote below was checked against a saved copy, fetched 2026-10-02T18:08:34Z. Copies and SHA-256 hashes: SHA256SUMS.

Exhibit 1 · The schedule, whitepaper V2 (16 March 2026), page 17

“The revocation list and its signature is included as part of the attestation bundle… The list is published every 3 hours, and each signature expires every 24 hours.”

ai.meta.com/static-resource/private-processing-technical-whitepaper · saved copy meta-private-processing-whitepaper-v2.pdf

Exhibit 2 · The server software, same page

“For the CVM base image, releases are on a weekly cadence to pick up the latest kernel updates, so expiration is on the order of weeks.”

saved copy meta-private-processing-whitepaper-v2.pdf

Exhibit 3 · What kind of log, page 16

“Note: this is not a Merkle-tree based transparency ledger but a simple log maintained by a third-party.”

saved copy meta-private-processing-whitepaper-v2.pdf

Exhibit 4 · The list today, from Cloudflare’s log

epoch 2694   2026-10-01 19:01 UTC
epoch 2695   2026-10-02 01:00 UTC
epoch 2696   2026-10-02 07:00 UTC
epoch 2697   2026-10-02 13:00 UTC

Four in a row, six hours apart.

plexi.key-transparency.cloudflare.com/namespaces/prod.pc.revocation_list/audits/<epoch> · raw plexi-revocation-latest4.json

Disclosure timeline

1 OctPublished; sent to Meta through its whitepaper’s feedback channel.

Waiting on Meta since 1 Oct.

What we can't be sure of

Run it yourself

The scripts are also on GitHub: github.com/MarkovianProtocol/second-measurements/sm-005.

python3 pp_revocation.py   # the pulled-software lists (about 2,700 requests; keep concurrency low)
python3 pp_cvm_weeks.py    # the server-software entries and week counts
python3 pp_cadence.py prod.pc.cvm   # head and gap summary for any namespace
3935e6f73cdd88b2c5d9d2f89410608345afa496574ba1a9138bd97e9ad5ded3  pp_revocation.py
548d0ec0c238db12093b638b36e8c9ad3bffa34227f9740edf94b0b660bab06c  pp_cvm_weeks.py
6a3711c303f807ac405cfe2cbe90bbeefbe8a1cf91018add8db4215571694364  pp_cadence.py

Reproduced from the public repository on 3 October 2026 on a clean machine: exact (2,701 epochs, median gap 4.0 h, longest 19.2 h; 37 of 70 weeks with a server entry). Full table on the track record.

What you can do with this

References

  1. Meta. Private Processing for WhatsApp Overview, technical whitepaper, V1 2025-06-10, V2 2026-03-16. ai.meta.com/static-resource/private-processing-technical-whitepaper. Pages 16–17.
  2. Meta. Bringing Private Processing to Meta AI Glasses. Engineering at Meta, 2026-09-23. engineering.fb.com/2026/09/23/security/private-processing-meta-ai-glasses.
  3. Cloudflare. Plexi and the Key Transparency Auditor API. github.com/cloudflare/plexi; plexi.key-transparency.cloudflare.com/namespaces.

Cite as

@misc{markovian-sm005,
  author = {{Markovian Protocol}},
  title  = {Meta's Private Processing whitepaper against its own transparency log},
  number = {SM-005},
  doi    = {10.5281/zenodo.23122986},
  year   = {2026},
  month  = sep,
  url    = {https://markovianprotocol.com/measurements/sm-005.html}
}