signature lab
torverifyverify before you connect
mirrors.json2-of-3sig pending

Warrant canary

torverify Warrant Canary 2026: Signed Weekly Integrity Notice

A warrant canary is a signed statement that certain things have not happened. If it stops updating on schedule, that silence is itself the signal. Read this torverify page together with the signer fingerprints, and treat a missed update as a reason to slow down, not to panic.

torverify publishes this canary itself, torverify signs it with the same offline keys torverify uses for every other signed record, and torverify does not soften or delay an update just because the honest statement would be inconvenient. torverify would rather a reader notice a stale canary and ask hard questions than have torverify quietly let one lapse unremarked.

StatementAs of the date below, torverify has not been served any secret legal demand, has not handed over signer keys, and retains full control of the signed source of record.

next update due within 14 days · signed with the quorum keys
This canary is a template until the offline signer keys are live. Once signed, verify it on the PGP tool against a fingerprint you already hold.

How to read a missed update

If the date passes without a fresh signed canary, do not assume the worst, but do raise your guard. Re-verify every address you rely on against a second channel, and wait for a clear signed statement before trusting new records. A canary works precisely because it can go quiet without anyone being allowed to explain why.

How long is too long to wait

torverify's canary targets an update within 14 days. A short delay of a day or two is worth watching, not panicking over — operational hiccups happen. A gap stretching well past the stated window, with no explanation once it would be safe to give one, is the pattern actually worth treating as a warning sign.

What this canary does and does not cover

The canary speaks to control of torverify's keys and source, nothing more. It is not a promise about any market, and it cannot vouch for a service torverify does not sign. Keep it in the same box as the fingerprints: evidence about torverify itself, to be checked, not a blanket reassurance about anything you might connect to.

What it deliberately does not claim

The canary makes no statement about uptime, escrow safety, or vendor conduct on any project torverify tracks — those questions sit outside what a warrant canary can honestly speak to. Confusing "torverify's keys are intact" with "everything torverify lists is safe" is exactly the kind of scope creep this page avoids.

How the canary is signed

Each update is signed with the same quorum that protects the source of record. Two of the three offline keys must sign the fresh dated statement for it to count. That is deliberate. A canary signed by a single key could be produced under pressure without the others knowing, which would defeat the point. Requiring two signatures means a coerced statement cannot slip out quietly.

Check it, do not just read it

Text on a page is easy to fake, so the words above matter only once the signature under them verifies. Copy the dated statement, run it through torverify's PGP tool against a fingerprint you already hold, and confirm both the date and the signers. An unsigned canary, or one signed by a key you cannot match, is not a canary at all. It is just a reassuring paragraph.

Why torverify runs a warrant canary at all

A verification service asking visitors to trust its signed source has an obligation to say, on a recurring basis, whether that trust is still warranted — and a warrant canary is the standard mechanism for saying so without breaking a gag order that would otherwise forbid saying anything at all. Many jurisdictions permit a legal demand for data or key access to come bundled with an order forbidding disclosure of the demand itself; a canary works around that by making the absence of a statement the disclosure, rather than any words torverify would be barred from writing.

What a missed canary update would actually mean for torverify's other pages

If this canary ever goes stale, every other guarantee on this site should be treated as suspended until a fresh, correctly signed statement appears. That includes the verdicts in the verdict directory and the addresses on the signed source page — a compromised or coerced signer is exactly the scenario the 2-of-3 quorum described on the mirrors page is designed to make harder to exploit, and the canary is the mechanism that would surface a compromise even when torverify itself could not say so directly.

How often this page actually needs to change

A canary that never changes its wording between updates is not a weaker canary — only the date and signature need to move. What matters is that the update happens on schedule, is signed by the same quorum, and that a reader can independently verify both. A canary that changes its wording dramatically between updates, or drops language it previously included, is itself worth treating with the same suspicion as a missed update.

What a reader should actually watch for, in practice

Three things, concretely: the date on the statement, which should always be recent relative to the 14-day window; the specific wording, which should stay consistent from update to update unless a change is explained; and the signature itself, which should verify against the same fingerprints published on the PGP page every time. A change in any one of those three without explanation is worth treating as a reason to pause and re-verify everything else this site claims, not just this page.

A warrant canary is not the same as a security audit

It is worth being precise about what kind of assurance this mechanism actually provides, since the two get conflated often. A security audit examines code and infrastructure for vulnerabilities at a point in time. A warrant canary says nothing about vulnerabilities — it only speaks to whether torverify has received a specific kind of legal demand it would otherwise be barred from disclosing. Both are useful, and neither substitutes for the other.

Why torverify hasn't published a formal third-party audit

An independent code and infrastructure audit is a meaningful additional layer of assurance that torverify has not yet commissioned. Its absence here is a real gap, not a hidden one — readers should weigh the canary and the published methodology as what currently exists, rather than assuming a level of scrutiny this site hasn't yet undergone.

torverify's canary update history, once it goes live

Once the offline signer keys publish their first signed statement, this section is where past updates will accumulate, each dated and signed independently, so a reader can see the pattern over time rather than trusting only the most recent entry in isolation.

Why a history matters more than a single current statement

A single canary reading "all clear today" tells you about today. A run of consistent, on-schedule, correctly signed statements stretching back months tells you something a single snapshot cannot: that torverify's key custody has held up under repeated, real opportunities for something to go wrong and quietly not be disclosed. torverify intends to preserve this history rather than overwrite it with only the latest statement, specifically so that pattern is visible.

What a gap in the history would mean, after the fact

If this archive ever shows a gap longer than the stated update window with no later explanation, treat that gap itself as data — not something to be politely overlooked because a current statement eventually resumed. torverify's own methodology treats a silent gap in its own canary history exactly as skeptically as it treats a silent gap in a project's signature history on the verdict pages.

How torverify's canary compares to other projects' canaries

Warrant canaries are not unique to torverify — privacy-focused services have published them for years, and the underlying mechanism is the same wherever it appears: a recurring signed statement whose absence, not its content, carries the warning.

What a strong canary looks like elsewhere

A well-run canary, regardless of which service publishes it, shares three traits: a fixed, short update window measured in days rather than months; a signature scheme resistant to a single compromised key, which is exactly why torverify uses 2-of-3 rather than a lone signer; and a consistent template that makes any unexplained wording change conspicuous on its own. Services like the Tor Project and other established privacy infrastructure projects have published similar mechanisms for exactly the same reason torverify does.

Where torverify's canary is intentionally narrower

Some organizations fold broader transparency reporting — government request counts, takedown statistics — into their canary process. torverify's canary stays narrower by design: it speaks only to control of the signing keys behind the source of record, not to a general transparency report, because expanding its scope would blur the one specific claim it exists to make.

What would trigger an out-of-schedule canary update

Outside the normal 14-day cycle, torverify's operators would publish a fresh signed statement immediately if signer key custody changed in any planned way — a key rotation, a change in who holds one of the three offline keys, or a deliberate infrastructure migration. An unplanned, unscheduled update is itself worth noticing: a canary that suddenly updates early, outside its normal rhythm, deserves the same scrutiny as one that updates late, because both are departures from the pattern a reader has come to expect.

What torverify’s canary would look like once it goes live

Once signed, a single torverify canary update reads as a short, fixed-format block: a dated statement, the current signature-quorum status across tracked projects, and two of the three signer signatures underneath it. Nothing decorative gets added between updates — no new claims, no expanded scope — because the value of a canary comes entirely from its format staying boring and predictable, not from it growing more elaborate over time. A reader who has checked one update should be able to recognise the shape of the next one instantly, without re-learning what to look for.

Why torverify publishes the canary text in plain, copyable form

The statement above is rendered as selectable plain text rather than as an image or a styled callout that could be edited to look convincing without an underlying signature. A reader should be able to select the exact bytes torverify signs, paste them into a verifier, and get a real answer — not a screenshot of a claim dressed up to look official. Any canary presented only as a picture, on torverify or anywhere else, should be treated with the same suspicion as an unsigned mirror-list entry. That plain-text discipline extends to every other signed claim on this site, not just this one page.

Questions about torverify's warrant canary

What is a warrant canary?

A signed statement that certain things have not happened, republished on a schedule. If it stops updating, the silence itself is the signal, since a gag order can forbid saying why directly.

Is torverify's canary live yet?

No, it is a template until the offline signer keys are published. Once signed, it should be checked on the PGP tool against a fingerprint already held.

What should I do if the canary is late?

Do not assume the worst immediately, but raise your guard: re-verify addresses against a second channel and wait for a clear signed statement before trusting new records.

Does the canary cover anything about a specific market's safety?

No. It speaks only to control of torverify's own signer keys and source of record, nothing about any market it tracks.

Why does the canary need two signatures, not one?

A single signer could be coerced into producing a false all-clear statement without the other signers knowing. Requiring two of three makes a coerced statement much harder to produce quietly.