Open source, all the way down
Every line of code that touches your memory, identity, consent, and payments is inspectable. No hidden kernel, no closed path where the rules quietly change. If it governs you, you can read it.
Every line of code that touches your memory, identity, and consent is open source and third-party auditable. But a pledge is cheap. What matters is that you never have to believe it: the audit is external, the past cannot be rewritten, and no single party — not even us — is the root of trust. Below is not a promise. It is a set of things you can check yourself, right now.
Every line of code that touches your memory, identity, consent, and payments is inspectable. No hidden kernel, no closed path where the rules quietly change. If it governs you, you can read it.
The audit does not depend on you trusting our copy. The proofs are external: anyone verifies inclusion and consistency against a signed root, without our database and without our permission.
Every governed action and every name→key binding is appended to a Merkle log that can only grow. A consistency proof shows the old log is an exact prefix of the new — nothing is altered or dropped.
Independent witnesses cosign each checkpoint and refuse to sign a split view. The anchor-chain tip is notarized on Bitcoin — so even the operator cannot show two faces or quietly unsay the record.
Most systems say transparency. Echo hands you the receipts. Each of these is live today — open it and verify for yourself, without trusting a word we've written.
An RFC 6962 append-only Merkle log with inclusion + consistency proofs and an independent witness cosignature. Run it in your browser — the operator cannot rewrite or drop a past record without being caught.
open the log →A panel of independent Echoes cryptographically endorses that a growth commitment is self-controlled, monotonic, and append-only — without ever seeing a single experience. Proof-only peer review.
meet the witnesses →A public ledger where anyone re-verifies any sealed Factory run's inclusion proof client-side — recompute the Merkle leaf, check it against the signed root, verify the witness quorum. Trust the math, not us.
verify a run yourself →Names bind to keys, first-registration-wins, with issuer-signed revocation. A signature that is valid but unbound is caught as impersonation — identity, signature, revocation and expiry stay separate facts.
inspect the directory →The boundary between the private layer and the public trust layer, made structural: only an opaque commitment ever crosses. A leak is impossible by construction, not by promise. Proof, never data.
see the boundary →The single source of truth for what's official — with signed announcements you verify against a published key. Don't trust messages. Verify the source.
verify the source →Inclusion and consistency proofs, independent witness cosignatures, a hash-linked anchor chain, and a real Bitcoin notarization of the chain tip. Every one of these runs in your browser with plain hashes and signatures — no trust in us required.
The witnesses run as services on one host today — true multi-operator federation is the next step. Bitcoin confirmation is asynchronous, so a freshly notarized tip is pending until a block commits. We name the gap instead of hiding it.
A closed system asks you to trust the people who run it. An open, witnessed, notarized one proves it never rewrote the past and never showed two faces. That is the whole difference between "trust us" and "you don't have to."