What the operator commits to depends on how you use this instance. The notice periods and retention in sections 6–8 apply to paid countersigning only. Free and trial use has the same terms as the open witness, and none of those commitments: see section 10. Sections 1–5 and 9 describe how the instance works, which is the same for every request.
A countersignature is a signature by a party other than the producer over a bundle digest, accompanied by a statement of which claims that party recomputed and with what result.
This instance accepts an Evidence Bundle with every payload withheld (digests only), recomputes a
fixed set of structural checks over it, and signs the bundle digest together with its own identity and the
statement of which checks ran and their results, so none of those can be altered without the signature
failing. It records the statement's SHA-256 in its own append-only log, so the returned entry carries a
receipt. It accepts only bundles that declare every payload withheld (payloads_mode: none, no disclosures) and refuses any other before anything
is recomputed.
The software is the open-source capsule-anchor codebase with its countersign module
switched on. On this hostname only the countersign registration route and read-only endpoints are
served; the codebase's open witness routes are not. The capsule-anchor commit running now is published
at /status.json.
Every check returns exactly one of five results. They are never combined into a score, a grade, or a single pass/fail.
| Result | Means |
|---|---|
established | the check ran and its condition held |
failed | the check ran and its condition did not hold |
not present | the bundle carries nothing this check operates on |
not checked | the check could not run |
inconclusive | the check ran but only partially resolved |
The checks, as run by the version of the software this instance serves:
| Check | What it recomputes |
|---|---|
| Range membership | The bundle's range proof and per-record inclusion proofs, verified against the
bundle's checkpoint. Reads inconclusive when the checkpoint carries no independently
verifiable signed statement. |
| Profile conformance | Whether each record kind in the bundle is covered by a profile's own
checks. No profile's own checks are loaded on this instance in version 1, so this
check reads not checked whenever the bundle's records declare a kind, and
not present when none does. |
| Chain consistency | Reads not present: the bundle carries one checkpoint, not a
history. |
| Cadence | Reads not present: the bundle declares no window to bound against. |
| Key hygiene | Reads not present: records carry no per-record signer key. |
Never checked, on any countersignature from this instance: capture coverage (whether everything that happened was recorded) and outcome correctness (whether a judged outcome was right). The statement inside a returned entry lists only check names and results; these two exclusions are stated here because the entry does not carry them.
This instance runs a strict registration policy. A request is accepted only if its requester is
enrolled in this instance's issuer allowlist, the requester key matches the one key enrolled for that
requester, and the requester's signature over the bundle digest verifies under it. A request that
fails any of these is refused before any check runs. The full policy is section 5 of COUNTERSIGN.md in the
capsule-anchor repository.
A countersignature over a bundle the operator itself produced is well formed, and should be read as
not independent. This instance's own sample countersignatures are of that kind: they are over
bundles from the operator's own demo ledger, so a verifier that lists the operator's keys as the
producer's renders them not independent. The independent field an entry carries
compares only the requester's key with this instance's key; verifiers decide independence
themselves.
This instance signs with one Ed25519 key. Its public half is published at
/.well-known/did.json and
/anchor/authority-pubkey.
The private key is a 32-byte seed generated once during a recorded key ceremony, stored in Google Cloud Secret Manager, and injected into the running service at start. It is held in process memory only while the service runs. It is not held in a hardware security module in version 1. Read access to the secret is granted to the service's own runtime identity; the only other principals able to read it are the operator's cloud project administrators.
This key is used for nothing else. It is not the key of any other service the operator runs.
This instance checks every hour whether its log has grown since its last publication to the public
Sigstore Rekor log, and if it has, publishes its current signed tree head there. Anyone can compare the head this instance shows them with the head
it published, and detect a rewritten or forked history. The latest publication is at
/anchor/public-log/latest.
This instance can rotate its signing key. Rotation works as it does on the open witness
(capsule-anchor OPERATOR_GUIDE.md, "Key rotation"): it does not
invalidate what was signed before it, and what was signed before it stays verifiable against a key only while
that retired key remains published. Two things differ here. Each countersignature entry carries the full public
key that signed it, so its signature can be checked from the entry alone. And this instance's countersigner
list, at /countersigners.json, lists every key it has used; a
verifier confirms that a key was this instance's there, after checking the list against its SHA-256, published at
/countersigners.json.sha256. A rotation changes the list, and
so its digest.
For paid countersigning, a rotation is announced in this statement before it happens, except when it is forced by an incident, and retired keys stay published for as long as section 8 says.
If the signing key is exposed or suspected exposed, the operator stops accepting registrations, rotates the key, publishes a notice in this statement naming the affected log range by tree size, and updates the countersigner list. Countersignatures from the affected range should then be treated as unverified.
Security reports, from anyone: security@actionstate.ai.
For paid countersigning, notice of an incident is published within 72 hours of the operator learning of it.
For paid countersigning: if this instance stops operating, the operator gives 90 days' notice on this page and stops accepting registrations on the announced date. The public log and the verification keys stay readable for at least 5 years after that, or are handed to a successor or a foundation.
For every countersignature, the signature on an entry already issued remains verifiable offline from the entry alone.
The countersign module is part of the open-source capsule-anchor codebase. Anyone can run an
instance: set CAPSULE_ANCHOR_REGISTRATION_POLICY=strict and
CAPSULE_ANCHOR_COUNTERSIGN=1, give it its own signing key, database, and hostname, and enroll the
issuers you accept. See COUNTERSIGN.md and deploy/DEPLOY.md in the
repository.
Countersignatures issued without a paid agreement, including free and trial use, get the same terms as the
open witness at witness.agentactioncapsule.org, published with its software:
"Retention" and "Key rotation" in capsule-anchor's
OPERATOR_GUIDE.md. The key may rotate without advance notice, and there is no commitment to a notice
period or to how long the log and keys stay readable. None of the paid commitments in sections 6–8 cover them.
The entry itself is the same kind of entry either way; only what the operator commits to afterwards differs.