Alpha Preview — This software is under active development. Expect rough edges and breaking changes.

Fovea

the fleet's security claims, watched continuously

chain not continuous holding · seq 192 · checked hourly observer 0.5.0 · up 2d 2h

Verified by this portal at 2026-10-08T05:59:39Z UTC; it checks again every 5 minutes.

The pipeline — a claim is probed, signed, kept and re-checked

mcl-fovea
debian-gb-lon
0.5.0
probes the station hourly, signs every verdict
↓ signed 0x23 record
station DHT
station-nl-ams
state holding
the mesh holds only the latest record
↓ keeper fetches, every 15 min
keeper
macula lab machine
2026-10-08T05:37:09Z
keeps only what fovea verify accepts
↓ commits to a public repo
records
764550c…
2026-10-08T05:52:11Z
every fetch time, every refusal, kept apart
↓ this page re-verifies
this portal
released fovea, not this code
re-verified 2026-10-08T05:59:39Z
shows fovea's verdict, never the repos' word

The matrix — the living threat model, lint-enforced

confidentiality
integrity
availability
authenticity
accountability
Actors · origin × agency
internal
external
trusted_partner
machine_agent
Data state · where the data is
at_rest
in_motion
in_use
Environment · what the system cannot keep out
physical_natural
socio_legal
temporal
Lifecycle · the system over time
create
acquire
deliver
operate
admin
decommission

cell colors are the assessment as authored, shown because `fovea lint` reports it clean; the numbers beside it are `fovea score` and `fovea render`, computed here.

scorecard · fovea score
cells
80 / 80
unassessed
0%
unjustified n/a
0
by-design defenses
53.0%
roll-ups · fovea render
actors lifecycle data environment
confidentiality G 4/4 A 6/6 A 3/3 G 3/3
integrity G 4/4 A 6/6 G 3/3 G 3/3
availability A 4/4 A 6/6 A 3/3 A 3/3
authenticity G 4/4 A 6/6 G 3/3 G 3/3
accountability A 4/4 A 6/6 A 3/3 A 3/3
open gaps: 0 · each block shows its weakest cell: G all assessed, A some not yet, R any unassessed

The chain — every hourly verdict, linked to the one before it

claim macula-station-kx slot cd256e6f6528…
records repository
not continuous 192 of 192 records verified, observed 2026-09-30T08:55:12.214Z → 2026-10-08T05:32:06.065Z gap: seq 2 to 3
1 record(s) from spec v0.4, in no chain: unchained-1790755382690-e16724f3f9c610db.hex
Verify it yourself, offline

Every record verifies offline against the io.macula realm key and the assessment it names. Install the released tool, clone both public repositories, and run, from the records clone:

go install github.com/macula-io/macula-fovea/cli/cmd/fovea@v0.4.0
  git clone https://github.com/macula-io/mcl-fovea-assessments.git
  git clone https://github.com/macula-io/mcl-fovea-records.git && cd mcl-fovea-records
  fovea verify --realm-key realm/io.macula.pub.hex --realm io.macula --profile pq_hybrid \
  $(for e in endorsements/*/*.hex; do printf -- '--endorsement %s ' "$e"; done) \
  --repo ../mcl-fovea-assessments --path macula-station-kx --chain records/cd256e6f6528cb46381ed5cfde72ca396de902f3680bcfaf9c19251f1b11ae0a
claim macula-station-kx slot 69f3eba1b1a1…
records repository
continuous 58 of 58 records verified, observed 2026-10-05T20:31:44.245Z → 2026-10-08T05:32:08.358Z
Verify it yourself, offline

Every record verifies offline against the io.macula realm key and the assessment it names. Install the released tool, clone both public repositories, and run, from the records clone:

go install github.com/macula-io/macula-fovea/cli/cmd/fovea@v0.4.0
  git clone https://github.com/macula-io/mcl-fovea-assessments.git
  git clone https://github.com/macula-io/mcl-fovea-records.git && cd mcl-fovea-records
  fovea verify --realm-key realm/io.macula.pub.hex --realm io.macula --profile pq_hybrid \
  $(for e in endorsements/*/*.hex; do printf -- '--endorsement %s ' "$e"; done) \
  --repo ../mcl-fovea-assessments --path macula-station-kx --chain records/69f3eba1b1a19d42072e37cbca28462f1177b375012a5047377657ada89f846f
claim macula-station-kx slot 6787ad3f4ffa…
records repository
continuous 58 of 58 records verified, observed 2026-10-05T20:31:44.949Z → 2026-10-08T05:32:09.071Z
Verify it yourself, offline

Every record verifies offline against the io.macula realm key and the assessment it names. Install the released tool, clone both public repositories, and run, from the records clone:

go install github.com/macula-io/macula-fovea/cli/cmd/fovea@v0.4.0
  git clone https://github.com/macula-io/mcl-fovea-assessments.git
  git clone https://github.com/macula-io/mcl-fovea-records.git && cd mcl-fovea-records
  fovea verify --realm-key realm/io.macula.pub.hex --realm io.macula --profile pq_hybrid \
  $(for e in endorsements/*/*.hex; do printf -- '--endorsement %s ' "$e"; done) \
  --repo ../mcl-fovea-assessments --path macula-station-kx --chain records/6787ad3f4ffa398eba874b76ad9ceffcc3f6a18a6b6f78558b50f85d3fa3136d
claim macula-station-kx slot c162c748e2e4…
records repository
continuous 58 of 58 records verified, observed 2026-10-05T20:31:45.408Z → 2026-10-08T05:32:09.55Z
Verify it yourself, offline

Every record verifies offline against the io.macula realm key and the assessment it names. Install the released tool, clone both public repositories, and run, from the records clone:

go install github.com/macula-io/macula-fovea/cli/cmd/fovea@v0.4.0
  git clone https://github.com/macula-io/mcl-fovea-assessments.git
  git clone https://github.com/macula-io/mcl-fovea-records.git && cd mcl-fovea-records
  fovea verify --realm-key realm/io.macula.pub.hex --realm io.macula --profile pq_hybrid \
  $(for e in endorsements/*/*.hex; do printf -- '--endorsement %s ' "$e"; done) \
  --repo ../mcl-fovea-assessments --path macula-station-kx --chain records/c162c748e2e4006f8066e01cd703eb5bfd9ecd27d1bb97cb7d80c58df8bd63db
claim macula-station-kx slot acd7b32f8883…
records repository
continuous 58 of 58 records verified, observed 2026-10-05T20:31:46.329Z → 2026-10-08T05:32:10.62Z
Verify it yourself, offline

Every record verifies offline against the io.macula realm key and the assessment it names. Install the released tool, clone both public repositories, and run, from the records clone:

go install github.com/macula-io/macula-fovea/cli/cmd/fovea@v0.4.0
  git clone https://github.com/macula-io/mcl-fovea-assessments.git
  git clone https://github.com/macula-io/mcl-fovea-records.git && cd mcl-fovea-records
  fovea verify --realm-key realm/io.macula.pub.hex --realm io.macula --profile pq_hybrid \
  $(for e in endorsements/*/*.hex; do printf -- '--endorsement %s ' "$e"; done) \
  --repo ../mcl-fovea-assessments --path macula-station-kx --chain records/acd7b32f8883f75423abbdab5413a82fc219bd4b4eb95cd943f0a6a2b185b497
claim macula-station-kx slot ddbb3f9e8a8c…
records repository
continuous 58 of 58 records verified, observed 2026-10-05T20:31:46.917Z → 2026-10-08T05:32:11.209Z
Verify it yourself, offline

Every record verifies offline against the io.macula realm key and the assessment it names. Install the released tool, clone both public repositories, and run, from the records clone:

go install github.com/macula-io/macula-fovea/cli/cmd/fovea@v0.4.0
  git clone https://github.com/macula-io/mcl-fovea-assessments.git
  git clone https://github.com/macula-io/mcl-fovea-records.git && cd mcl-fovea-records
  fovea verify --realm-key realm/io.macula.pub.hex --realm io.macula --profile pq_hybrid \
  $(for e in endorsements/*/*.hex; do printf -- '--endorsement %s ' "$e"; done) \
  --repo ../mcl-fovea-assessments --path macula-station-kx --chain records/ddbb3f9e8a8c7e5900816091564dd5b3b4df39f79e365842ed9e3063104121ef
claim macula-station-kx slot 641abba37501…
records repository
continuous 50 of 50 records verified, observed 2026-10-06T04:07:04.068Z → 2026-10-08T05:31:49.337Z
Verify it yourself, offline

Every record verifies offline against the io.macula realm key and the assessment it names. Install the released tool, clone both public repositories, and run, from the records clone:

go install github.com/macula-io/macula-fovea/cli/cmd/fovea@v0.4.0
  git clone https://github.com/macula-io/mcl-fovea-assessments.git
  git clone https://github.com/macula-io/mcl-fovea-records.git && cd mcl-fovea-records
  fovea verify --realm-key realm/io.macula.pub.hex --realm io.macula --profile pq_hybrid \
  $(for e in endorsements/*/*.hex; do printf -- '--endorsement %s ' "$e"; done) \
  --repo ../mcl-fovea-assessments --path macula-station-kx --chain records/641abba37501f662caee70816da6eeca992b820c2d78473b50712a7846ba2d1d
claim macula-station-kx slot 7b89fd8a7456…
records repository
continuous 50 of 50 records verified, observed 2026-10-06T04:07:07.929Z → 2026-10-08T05:31:52.541Z
Verify it yourself, offline

Every record verifies offline against the io.macula realm key and the assessment it names. Install the released tool, clone both public repositories, and run, from the records clone:

go install github.com/macula-io/macula-fovea/cli/cmd/fovea@v0.4.0
  git clone https://github.com/macula-io/mcl-fovea-assessments.git
  git clone https://github.com/macula-io/mcl-fovea-records.git && cd mcl-fovea-records
  fovea verify --realm-key realm/io.macula.pub.hex --realm io.macula --profile pq_hybrid \
  $(for e in endorsements/*/*.hex; do printf -- '--endorsement %s ' "$e"; done) \
  --repo ../mcl-fovea-assessments --path macula-station-kx --chain records/7b89fd8a7456fefbc7915131a7d25871758556b1a905b1030367e0640d06fc57
claim macula-station-kx slot 6da7f2e6f79c…
records repository
continuous 50 of 50 records verified, observed 2026-10-06T04:07:11.148Z → 2026-10-08T05:31:55.72Z
Verify it yourself, offline

Every record verifies offline against the io.macula realm key and the assessment it names. Install the released tool, clone both public repositories, and run, from the records clone:

go install github.com/macula-io/macula-fovea/cli/cmd/fovea@v0.4.0
  git clone https://github.com/macula-io/mcl-fovea-assessments.git
  git clone https://github.com/macula-io/mcl-fovea-records.git && cd mcl-fovea-records
  fovea verify --realm-key realm/io.macula.pub.hex --realm io.macula --profile pq_hybrid \
  $(for e in endorsements/*/*.hex; do printf -- '--endorsement %s ' "$e"; done) \
  --repo ../mcl-fovea-assessments --path macula-station-kx --chain records/6da7f2e6f79c07ac1ff09b84fb558d7efd470a84875ee1ac5f653807a1104887
claim macula-station-kx slot 5af9a0dbf82a…
records repository
continuous 50 of 50 records verified, observed 2026-10-06T04:07:15.037Z → 2026-10-08T05:31:59.248Z
Verify it yourself, offline

Every record verifies offline against the io.macula realm key and the assessment it names. Install the released tool, clone both public repositories, and run, from the records clone:

go install github.com/macula-io/macula-fovea/cli/cmd/fovea@v0.4.0
  git clone https://github.com/macula-io/mcl-fovea-assessments.git
  git clone https://github.com/macula-io/mcl-fovea-records.git && cd mcl-fovea-records
  fovea verify --realm-key realm/io.macula.pub.hex --realm io.macula --profile pq_hybrid \
  $(for e in endorsements/*/*.hex; do printf -- '--endorsement %s ' "$e"; done) \
  --repo ../mcl-fovea-assessments --path macula-station-kx --chain records/5af9a0dbf82aa9826c1e6705b47c69fb1fe6fd4c4dfe9ef999bccbfd3ae21e18
claim macula-station-kx slot fbcbeb8f2a9e…
records repository
continuous 50 of 50 records verified, observed 2026-10-06T04:07:18.383Z → 2026-10-08T05:32:02.361Z
Verify it yourself, offline

Every record verifies offline against the io.macula realm key and the assessment it names. Install the released tool, clone both public repositories, and run, from the records clone:

go install github.com/macula-io/macula-fovea/cli/cmd/fovea@v0.4.0
  git clone https://github.com/macula-io/mcl-fovea-assessments.git
  git clone https://github.com/macula-io/mcl-fovea-records.git && cd mcl-fovea-records
  fovea verify --realm-key realm/io.macula.pub.hex --realm io.macula --profile pq_hybrid \
  $(for e in endorsements/*/*.hex; do printf -- '--endorsement %s ' "$e"; done) \
  --repo ../mcl-fovea-assessments --path macula-station-kx --chain records/fbcbeb8f2a9e06d894117e9b0c034f0c3dc84648e93ba5be1910c79b702749a0
claim macula-station-kx slot 92126a756454…
records repository
continuous 50 of 50 records verified, observed 2026-10-06T04:07:21.617Z → 2026-10-08T05:32:05.564Z
Verify it yourself, offline

Every record verifies offline against the io.macula realm key and the assessment it names. Install the released tool, clone both public repositories, and run, from the records clone:

go install github.com/macula-io/macula-fovea/cli/cmd/fovea@v0.4.0
  git clone https://github.com/macula-io/mcl-fovea-assessments.git
  git clone https://github.com/macula-io/mcl-fovea-records.git && cd mcl-fovea-records
  fovea verify --realm-key realm/io.macula.pub.hex --realm io.macula --profile pq_hybrid \
  $(for e in endorsements/*/*.hex; do printf -- '--endorsement %s ' "$e"; done) \
  --repo ../mcl-fovea-assessments --path macula-station-kx --chain records/92126a7564541d1b117eeb605668600dae256028e102244c1c1a3b0784a6af30

Honest limits

  • The first keeper runs on our own lab machine: off the observer's box and off every station it observes, but not yet independent of us. Anyone can run a keeper and compare.
  • Every state is published as observed. A broken claim becomes public within about 15 minutes of the round that saw it.