Trust centre · Closed programme
Forgery bounty
The Seal forgery bounty ran from 27 August 2026 to 12 September 2026 and is closed to payment. Nothing in it is retracted. Every Seal surface still says change one field and the check fails, the formats and both verifiers are public, and a report that shows otherwise is still the thing we most want to receive. What has changed is that no payment is offered: we are a small team and cannot service a paid programme responsibly right now. If it reopens, it will be announced here first.
Everything you need is public. The formats and both reference verifiers are at github.com/Aqta-ai/attestation-spec, the key at api.aqta.ai/v1/attestation/public-key, the public log head at app.aqta.ai/transparency. A production receipt to start from is on aqta.ai/verify.
What we want to hear about
Checking an inclusion or consistency proof needs a verifier you can run yourself. That shipped on 27 August 2026: aqta-verify-proof, in aqta-verify-receipt on npm and PyPI, written twice in two languages against RFC 6962 and checked against the published conformance vectors on every change. All five classes above can now be exercised by someone who has never spoken to us.
That class is on the list because our own adversarial sweeps keep finding them: a canonical-number divergence, seven more in an earlier release, in August an encoding defect that let one signature be spelled three ways, and days later the same lenient decoding in our own browser checks. Each was fixed and published, the verifier defects as conformance vectors, and all of it is now checked on every push. In September 2026 two outside reports arrived within a week, an ordering comparator and a replacing UTF-8 decoder, fixed in 1.2.5 and 1.2.6.
The current build has been through 658 mutated receipts across two seeds and both record formats, covering structure, duplicate member names, the canonical-number band, unicode, signature spelling and document bytes, with no divergence between the two verifiers. That is what has been tested. It is not a claim that nothing is left.
What does not
How to report
Published by Aqta Technologies Limited, Dublin. Good-faith research under these rules will not be met with legal action. Checked rather than believed.