The receipt detects revision, not invention

Shipped

The strongest honest statement about a signed certificate is that committed inputs have not changed since they were committed. A producer who fabricates at capture signs a receipt that verifies perfectly.

It is tempting to describe a signing-and-replay pipeline as removing the need to trust the issuer. It does not, and the gap matters enough to state on every surface that carries the claim.

What the chain establishes is revision detection: an input committed at issuance cannot be altered afterwards without the alteration being visible. What it cannot establish is invention: a producer who writes a wrong number at capture, then certifies it honestly, produces a certificate that passes every check.

Two further conditions are load-bearing and are easy to omit:

  1. Replay needs your own inputs. Verifying against the copy of the data the issuer supplied establishes internal consistency and nothing else.
  2. The public key must be pinned out of band. A certificate that carries the key used to check it is self-referential. The verifier treats a pinned key as mandatory for a positive verdict for exactly this reason.

On the witness

The design includes a co-signing witness seam. The shipped witness runs co-located with the signer, which means it is not independent — independence here is a property of who operates it, not of the code. Calling it an independent witness would describe a deployment that does not currently exist.

On refusal

Refusal is a signed, first-class outcome carrying its real reason rather than a generic sentence. A system that always returns a number is not more useful than one that says when it cannot stand behind one; it is just less honest about the same underlying uncertainty.

Choose your beta

Choose the beta that fits your work.

Explore the local interface without identity verification, or use the LinkedIn-gated path when you need Alelyon’s hosted DQC-OS.

Open beta

Use the interface without identity verification.

No LinkedIn verification. Use the Terminal UI, Lattice workspace, local calculator, and visible tool traces. Hosted DQC-OS issuance is not included.

  • Local-first Windows interface
  • Open Alelyon toolkit and source
  • No hosted backend entitlement
Free UI build is being preparedOpen source toolkit
Closed beta

Verify with LinkedIn for full backend access.

LinkedIn OpenID Connect verifies control of the account; Alelyon does not scrape your profile. After verification and access policy succeed, the service can produce a unique key for the hosted DQC-OS path.

  • Everything in the open beta
  • Hosted deterministic DQC-OS calculations
  • Signed envelopes and certified answer paths

When the service opens, the key will be shown once. Save it somewhere secure, then enter it when Alelyon Terminal asks during sign-in.

Available now

Ask, and a person reads it.

Prefer to talk to someone first, or need access sooner than the self-serve paths allow? Ask directly.

Requests to this address are read, and access is granted case by case while Alelyon is in closed beta. A public beta environment is planned and will use the same route; it is not open yet, and no response time is promised until it is.

Do not include credentials, account numbers, API keys, or position data in the message.