Build Provenance

This site can prove how it was built. Every page is generated by a static-site generator written in Coherence Language, verified by automated gates, and hashed so you can check that what you are reading is what was built.

The pipeline

The generator (pipeline/ssg/src/build.cl) is compiled and run by the Coherence Language toolchain: it assembles every page, the curve figures computed in-language, the feeds, and the sitemap. A post-build step then renders binary assets, and runs two kinds of gates: banned-copy checks (retired claims, dead evidence paths, and the em-dash character fail the build) and required-content checks (if load-bearing copy or pages go missing, the build fails instead of shipping). Only output that passes both gates is deployed.

Build stamped: 2026-08-27 11:57 UTC

Signed release

This release is Ed25519-signed. The signature covers the canonical manifest, so every hash in it, and therefore every deployed byte, is bound to one signed release: change any file without re-signing and verification fails.

Pinned release key: a64d4af965fe220ce1c881f70ebabe5355ab9abbf17f7f3d8fb71ee911d2c493

This release’s signature: eb5672f6583a2f6cd0d05e156de965f00f91…918a5c5f9a0d

Re-verify it yourself, offline, against the pinned key (not the key the file carries):

python -c "import json,urllib.request as u;from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PublicKey as K;q=u.Request('https://coherenceenergylabs.com/build-manifest.json',headers={'User-Agent':'CEL-Release-Verifier/1'});m=json.load(u.urlopen(q));r=m.pop('receipt');b=json.dumps(m,sort_keys=True,separators=(',',':')).encode();K.from_public_bytes(bytes.fromhex('a64d4af965fe220ce1c881f70ebabe5355ab9abbf17f7f3d8fb71ee911d2c493')).verify(bytes.fromhex(r['signature']),b);print('RELEASE SIGNATURE VALID')"

Get the key from somewhere we do not control

Do not trust the key printed on this page. A signature checked against a key served by the same origin as the thing it signs proves only internal consistency: whoever controls this origin could replace the page, the key, the manifest and the signature together, and verification would still pass. To check authenticity rather than consistency, fetch the public key from a location this website does not control:

  • The public evidence repository, entry claims/site-release-key, on GitHub.
  • The DNS TXT record at _release-key.coherenceenergylabs.com, which is served by the domain's authoritative nameservers rather than by this site.

If the key you fetch out of band does not match the one shown above, the release you are looking at is not ours. That is the check we would want a hostile reviewer to run, so we are telling you how to run it.

What the manifest covers, and on which hosts

The manifest lists paths from one asset store, and that store is served on two hosts by design: coherenceenergylabs.com for the corporate site, and demos.coherenceenergylabs.com for the interactive demos, which run on a separate origin so their relaxed policy can never reach the main site. A path listed as /demos/gauntlet/index.html is therefore the same signed bytes you get at demos.coherenceenergylabs.com/gauntlet/; the demos are canonical on the subdomain, and the apex /demos/* paths 301 there so older links keep working. Everything else in the manifest is canonical on the apex.

Every artifact hashed

Every deployed artifact, HTML, CSS, JavaScript, images, and demo proof fixtures alike, is listed with the SHA-256 hash of its exact bytes in the signed manifest at /build-manifest.json. Fetch any file and hash it; the values must match. The table below is a readable excerpt.

curl -s https://coherenceenergylabs.com/about/ | sha256sum
ArtifactSHA-256 (first 16 hex)
/404.html4736fb85f96cbc31…
/about/index.htmlce994f9201d7feaf…
/accessibility/index.html80b0cc2eb76866b0…
/ace/index.html970620184d5b26cf…
/applications/index.htmlb048db63d9aff6c9…
/coherence-lang/index.html60ca11f9e5b47d42…
/contact/index.htmlff014784378ce1f8…
/demos/babel/index.html197da8d33add11ea…
/demos/coherence-energy/index.htmle4afab144fe4bcda…
/demos/coherence-field/index.html82c2960c807c2d43…
/demos/exact-float/index.html379beced2c8acfda…
/demos/figure/index.htmlee90b27f7041d5f4…
/demos/forge/index.htmlefca849cd42cf455…
/demos/gauntlet/index.htmld39e35a1468e4f3b…
/demos/gpu-exact/index.html891d2d62d32a939c…
/demos/index.html9377c7b80a6208b9…
/demos/live-compiler/index.html9ee19d193c1db3e9…
/demos/one-mind/index.htmlf856ff7152daa8e2…
/demos/prove-three-ways/index.html3630e75c631e27f2…
/demos/prover-advantage/index.html6e2376491e17ca65…
/demos/routing/index.htmldc441f01dc502b14…
/demos/transparency/index.htmlefe297859eec6f1e…
/demos/verify/index.html4696d659e3ff9567…
/demos/volume/index.html8ced6df6f1ad3662…
/demos/webcam/index.html7a7e319b8bd35c23…
/demos/whole-model/index.html90e5b5cae2b30b9b…
/disclaimer/index.html11790c76fe7c53f0…
/do-not-crawl-this/index.html1300a4dfd0ae3bb2…
/feed.xml070973a321754c79…
/index.htmled59b06d6e5b1f52…
/privacy/index.htmlc2a302cbce3a5e8d…
/research/index.html37a0e4c5830c4387…
/security/index.html1bdd46b1c18fe92c…
/sitemap.xmleaa0e8fdcdfa1650…
/terms/index.html4f73c44ac45d1b6d…
/trust-roots/index.html4deccaad1fbcdd4d…
/updates/index.html1491faebeedc6964…

The signed manifest covers every deployed artifact except itself and this page; a document cannot contain its own hash.