← Transparency log

All checkpoints

Every checkpoint ever created, newest first. Anchored checkpoints link straight to their Sigstore Rekor entry; pending ones are waiting for the next anchor cycle.

A small number of the earliest checkpoints are signed phase1-hmac-v1 and are not externally anchored. Those entries pre-date the HSM-backed audit signing key and the move to Sigstore Rekor. They are still hash-chained into the log, but a third party cannot verify them without our HMAC secret. From checkpoint kms:audit-log-signer-v1 onwards, every checkpoint is signed by a key we cannot extract and anchored on a log we do not run.

Loading…