A transparency log is only a security guarantee if somebody independent is checking it. Key Transparency now ships to billions of users across five production deployments, and until this witness there was no operator-independent party verifying that any of those logs were append-only — the property the whole design rests on. kt-witness downloads every published audit proof, re-verifies the tree arithmetic itself, cosigns what checks out, and permanently records what does not. It also measures a failure mode the ecosystem has no other visibility into: epochs whose proofs are no longer retrievable at all, and so can never be audited by anyone. Operators cannot audit themselves; this fills that gap and publishes the whole record, so anyone can check the checker.
Fund this project