Live production acceptance — September 12, 2026 (Pacific)
Production completed its first full 465,000,000-hash generation. The automated acceptance check passed at 2026-09-12 04:22:28 UTC (September 11, 21:22 PDT). At 2026-09-13 03:08 UTC (September 12, 20:08 PDT), a fresh pinned SDK attestation still verified readiness, Graviton5, the expected non-debug code, 465M work policy, and Mullvad. A new GET command returned HTTP 200.
Confirmed
post.json: 102,400-byte POST over public GET transport, exact echoed body.paste.json: 102,400-byte password-tagged paste write/read, wrong-tag isolation, and the same epoch puzzle as the POST.s3.json: anonymous complete-byte hash checks for the record, paste, puzzle, bundle, and attestation.solver.json: actual native solver and a nonempty checkpoint at acceptance.live-check.json: fresh readiness and GET check, anonymous archive recheck, current 30-day COMPLIANCE Object Lock, and a retained production record version. Solver PID 2459188 was still live; its checkpoint advanced from segment 10, iteration 2,020,000 to iteration 2,030,000 between observations.
The deployed source remains 30feebbeea8588fb1d1aa7b5ef40c9903bec0df5, with
24 enclave cores. The faster process/JIT benchmark prototype is not deployed.
Stored attestations and this report are historical evidence; clients must make
their own fresh pinned verification.
Remaining limits
- Automatic public publication of recovered keys and decrypted records is not deployed. Solvers save keys locally; users can independently solve public puzzles.
- Work targets roughly seven days from puzzle publication, not each request. Daily key reuse reduces the remaining delay for later records; faster solvers also reduce it. Full production key recovery and rollover are not yet verified.
- S3 mirroring is asynchronous. Object Lock protects uploaded versions; the enclave does not independently verify S3 persistence before returning a response.
- This is functional evidence, not proof that the code has no confidentiality vulnerabilities. The threat model's metadata and post-release record-provenance limitations still apply.
No generation, solver, or production service was restarted for these checks.