TRANSPARENCY LOG · WITNESS POLICY
The log at log.markovianprotocol.com publishes a checkpoint that independent
witnesses cosign. This page states the roster, the acceptance rule, and how to verify both
without trusting the operator.
A checkpoint counts as witnessed when at least 4 of the 7 pinned witnesses below have a verifying Ed25519 cosignature on it. Fewer than 4, treat the checkpoint as operator-only: signed, but with no independent guarantee against a rewritten history.
Witnesses cosign on an hourly round, so a new entry can sit up to about an hour with the operator's signature only, before the next witnessed checkpoint covers it. During that window the entry is committed, not yet witnessed.
Each key is pinned from the operator's own published page, never from this log.
| witness.navigli.sunlight.geomys.org | navigli.sunlight.geomys.org |
| witness.stagemole.eu | witness.stagemole.eu/about |
| transparency.dev/DEV:witness-little-garden | transparency.dev/witnesses |
| staging.witness.transparency.goog/ring-any-bells | transparency.dev/witnesses |
| rgdd.se/poc-witness | rgdd.se/poc-witness/about |
| witness1.smartit.nu/witness1 | witness1.smartit.nu |
| remora.n621.de | remora.n621.de |
Two of the seven also emit ML-DSA-44 (post-quantum) cosignatures alongside Ed25519.
Since July 2026 the published checkpoint also carries the log operator's own ML-DSA-44 timestamped cosignature (c2sp.org/tlog-cosignature, signature type 0x06) alongside the Ed25519 log signature. It authenticates the checkpoint under a post-quantum algorithm. It carries no witness weight and does not count toward the 4-of-7 rule — it is the same operator signing twice, not an independent party. The verifying key:
markovianprotocol.com/log+bda842cb+Bsni4fyz8zp1bzRSi4Q3Urs8SvqNnvLUsvvW0LQpZehhdR5EhI8ecuw4UZSeWzNN9+aInnJM+ifF6f2b0re3q28aAQY+SXiu6wJhREAl7q2mWD1R939JxBSlFfL25keKtKQiYxbmCYDysFe+6gW7HwT1X4vOS2JRXTvUOYJJ6t2aCRD+hzj7fudK4E+FJOGIVnyP50Hcgi2q8bWVd3WTdjmIKSzl4IpE5L9X52tGEKocPTqkOucbhzISOL7mURHCiDyi81l5QL0DJ/7ddP3hiprLhQkaGNA2Iq11O1XqJkmcKGkNn8iy8FqGQ1n7CHKmZccvmKd3r9qQsoK2uaX7EWkV3PeQIkVzVEGB8kfxE35h+jyct9QVHKtpPcXZCDLu4XMbcrNgIzgCb3GFzTu0j57K29Ny4PoFw33BHs/weGr/kaZoiQPY7n1NlEg4oCohJ6MYkoxDRQDH7GaLzQHFA8hCkIQOfjc42D5+mJfchtPq8w6xlu5PESSdTOsz27oS3Lkfi1FIrlpRalH1Id5h883iJO1dpmDnDTjXTtZ2Dyg2kOsch2Hr9/V4GKK18YtI3gOGkVujEdiRar0zovIDV0JMILQniY3XUD5uhagi8kVyuZBKOEEdaNjdWPX7PW9iTfEvIySAkR2LdI7qE65Pdx8Q/PJ/+7lByaM1fdfGlThNpOteVcVXYyNDed2lvrEeSogDe/ZiZqBiOryKR/u6TP1k7VdutLu1bHDLLl9IoGbbOTeAh4nzdbp7h0jEdlgrp1dhB8o54hkF+IyFZ5NPwU0MdsOUIYsqOzGnmDECUo8IEan3cvJxKLP1yuu8FGuSQ296yx4nxJMMI8sGaar9L4e3QpheDhMXMv5Vy4+XJmXhRcr1Whzx/3ifbx26I07/4nRHo2n008P7TWOw+gs85CwBd0/UJawO7HzAbKcF2HYtcREesHPuO/yh7dEiT5aCel3sHNeVyXDMSTFLp5ALAMjn51A+IgaTkZCt2itRg9/1+hFUSIQ0d6C8QN3TZSa/bV3IP3ZUVF3B80Nrcr4zJy2qxekD1HfQBmHNzeRDu7bG2hvko0G4gg8eEpVm4vGSoEZ/ABQ2eruId3QXzaugCbbAkBi5VQtiI3ndTBKcwgbxfLaZa+iFK7Kzr//DmF6/bR1cCjM12NMuaHPojp/l1SEKDpJ74cbnSZXfjvskjFW3BWjlyexLlGyuTUzHfpOa9/Yk9h3lkQENAK3L0Kg5V6JJq+REu6nYsFm8c7mbTlnDeEzqO1v2cj+5zKH9hrXKJl+dwoP73dhikhpKzrye4uMylzTDKqp6VqQqCGatfJC95lF69nuUWyJWQ01o9LtnRc0zukjJiDPhjlf1QqVcIfqv7814Ff/paS99Z8cN2Qz1CxWPnKNeJcCaFXKK61pFYqBnFchadRDHoNEIEUG8IopIffJ/vBrsfXDPo0tbcvdQD5qWHbL3KcZZaDXGSkzI88bjEhbxPjgwG43PshjBUdqHG3kBXX6ZU8vtL+uxN1DBbg32Nnmk4nOF9T6lugHPbb03FUbkoWwin+DtKe5q633SUMljFfJOCjV20UhLl383yI/zOy6D0kB7fgdGrthjN3o7RBXYRJnRrHvnKGqEaVATF9FEnnVGEXWUPam2kCHwtCq1ga+H9a8KGLhYIeqp9P5jV2DHQCaj1kk3WurgHO66L1z835p2nHAS6Ea+uVsilXYSPlf62m/9ODNUoqs0Ldzp3O1ETpsIxOiQOO72Nbs=
The in-page panels on Verify are demonstrations, served by the same operator they check. Independent verification means running your own client against the C2SP cosignature spec. A single-file reference verifier, with the roster keys pinned in its source and their origins cited, is published here:
curl -sO https://markovianprotocol.com/.well-known/verify_checkpoint.py # read it first — the keys and the rule are in the file python3 verify_checkpoint.py
It fetches the live checkpoint, verifies every cosignature, applies the 4-of-7 rule, and exits nonzero if the policy is not met. A cosignature attests that the log is append-only with a single history. It does not vouch for any claim in the log, and it is not an endorsement of Markovian.