The cosigner bar
Why this page exists
BlueFox Edge appends every signed receipt to a public, append-only transparency log and publishes a signed checkpoint of it on an hourly cadence, under the origin line edge.bluefox.ai/transparency/reliance/v1. Anyone can fetch the checkpoint, check consistency proofs between published sizes, and hold the log to its own history.
As of 10 September 2026 the served checkpoint carries cosignatures: []. Until that changes, trust in the log key is trust in BlueFox, and the house's published checker prints exactly that sentence. A cosigner is what makes it stop being printable.
A cosigner is an independent operator that watches the log's checkpoints, remembers the largest tree size it has seen, refuses any checkpoint inconsistent with what it has already accepted, and signs the ones it accepts. "Cosigner" here is the C2SP noun: a cosignature is a cosignature/v1 line on the checkpoint note, in the form the C2SP tlog-witness and tlog-cosignature specifications define. A checkpoint that carries such a line is "cosigned": independently countersigned, in the C2SP tlog-witness sense.
What a cosignature proves, and what it does not
It proves that at the moment of signing, that cosigner saw this exact checkpoint, this size and this root hash, and found it consistent with the history it had already accepted. If the same cosigner ever signs two inconsistent heads, both signatures verify, and together they are a proof of misbehaviour by that cosigner or by the log.
It does not prove that any claim inside any receipt is true. A checkpoint is not a verdict on contents, and neither is a cosignature.
It does not prove independence.Cloud, region and administrator separation are operational facts, not facts a signature proves. The house records them as an operator declaration, in the cosigner's own words, at the cosigner's own address, and commits to the exact bytes of that declaration. The signature proves the commitment, never the contents. The house does not audit a cosigner; it publishes what the cosigner said and where, so that anyone can read it and judge.
It is detection, not prevention.One cosigner makes a split view self-incriminating when that cosigner has seen both halves. Two views cosigned by disjoint sets of cosigners never meet in one signer's chain, so a quiet result means "no shared cosigner contradicted itself", never "the log did not equivocate". The machine tests below are minimum heuristics: distinct domains can share an operator, a network or a public-key infrastructure. That is why the organizational tier exists, and why it is declared rather than proved.
The bar
A cosigner is enrolled only if it clears Tier 1 by machine and states Tiers 2 and 3 in its own declaration. Tier 4 is welcome and optional.
Tier 1 — machine-checked
A key that fails any of these is not enrolled.
| # | Test | What it means |
|---|---|---|
| T1 | Own trust anchor | The cosigner's verifier key is its own, published at its own origin in C2SP vkey form (key type 0x04, Ed25519). It is never a key BlueFox issued: BlueFox's published key set carries only its receipt key and its log key. |
| T2 | Origin separation | The registrable domain of the cosigner's key origin differs from every registrable domain BlueFox operates. Today those are bluefox.ai and bluefoxedge.ai. A cosigner hosted under either would pass a narrower test and fail independence in substance, so the test is against the whole set. |
| T3 | The refusal test | Before enrolment the cosigner is handed a deliberately inconsistent checkpoint and must refuse it: a size it already holds is answered with the held size, and a shrinking or forked tree is rejected. A cosigner that signs a bad checkpoint is not enrolled. This is the behaviour the C2SP tlog-witness specification already requires; the test checks that it is there. |
| T4 | One key, one cosigner | Quorum counts distinct raw public keys, never names. Two rows over one key never make two cosigners. |
Tier 2 — declared: the six operational statements
Each cosigner states, in its own words at its own address, that it:
- controls its own cloud account or host, and the cosigner's administrative access;
- generated the cosigner's private key on that host and never sends it to BlueFox;
- exposes the cosigner over TLS on a stable endpoint;
- hands BlueFox only the public cosigner record and the endpoint;
- cosigns a supplied checkpoint and lets BlueFox verify the result offline;
- authorizes publication of its name only if it wants to be named.
Tier 3 — declared: the organizational statements
These are declared, not proved. The limit is stated beside each one.
| Statement | What is declared | What backs it | The limit |
|---|---|---|---|
| Organizational separation | No common parent, no common control, no shared officers or directors with Format Dynamics, the operator of BlueFox Edge. | The cosigner's own corporate identity at its published origin. | Distinct domains can share an operator. This row is a statement, and the house treats it as one. |
| No financial dependence | Not a customer, not a vendor, no fee for cosigning, no equity, no revenue share. Whatever the commercial relationship is, including "none", is stated in one line. | The declaration itself. | This is the row an offer could break; see what BlueFox offers and refuses, below. |
| Own key custody | The key was generated on hardware or hosts the cosigner controls, and the private half has never been transmitted to BlueFox. | Tier 2 statement 2, plus the structural fact that BlueFox's published key set cannot carry a cosigner's key. | The strongest row: it has a structural backstop, not only prose. |
| Published identity | A named, reachable legal entity, or a named project with a public governance page. | The origin itself and what is published there. | Anonymity is a legitimate way to run a cosigner in general. It weakens the claim this bar exists to support, so this bar asks for a name. |
The one-unit clause.Cosigners under common ownership or common control count as one independence unit in the house's quorum arithmetic, however many keys they run and however many companies operate them. "Independent of BlueFox" is not the same as "independent of each other". The operators of one existing set of three have said this of themselves: "even though the three witnesses are operated by separate companies, all three have the same parent company and so are dependent in some ways" (Glasklar Teknik, "Named policies for Sigsum", 4 February 2026). A policy that named such a set as three would describe one. This bar counts it as one.
Tier 4 — time-anchored, optional
A cosigner may timestamp its own declaration, for example with an OpenTimestamps proof anchored in Bitcoin or with a qualified electronic timestamp, so that the date of what it said is checkable without trusting either party. The house welcomes this and does not require it.
The declaration
The declaration is prose, hosted at the cosigner's own origin, and committed to by its SHA-256 digest in the house's signed cosigner policy. The house commits to the exact bytes. If the declaration changes, the digest changes, and the policy is re-issued as a new document. What the digest proves is that this is what the cosigner said; whether it is true is for the reader.
A model declaration is at the end of this page. It is adapted from a statement one existing testing cosigner published unprompted: "Neither I nor my employer are operating any transparency logs or are affiliated with any entities that do." Written by someone with no stake in this bar, it is close to what the bar asks for.
What BlueFox offers a cosigner, and what it refuses
Offered:public credit, named in the signed policy, on this site and in any announcement, only if the cosigner wants to be named; engineering help with the integration, the refusal test and the documentation, on the cosigner's own hosts, with the key never leaving them; and this page, a standing public invitation.
Refused, by policy and in writing:a fee; equity or any revenue share; product benefit of any kind, including free service, credits or early access; and any commercial relationship with a cosigner while it is enrolled. A cosigner that is paid is a vendor, and a vendor's independence is a claim its invoice contradicts. Declining a fee in public is the shortest proof that the independence being claimed was not purchased.
Disclosed rather than avoided:if any value ever moves in either direction, it is stated in the declaration. A declaration that says "we receive engineering support from BlueFox and no payment" is stronger than one that is silent.
BlueFox does not today offer to cosign a cosigner's own log in return. If it ever does, that is a separate service, and the mutual dependence is disclosed in both declarations.
Why the first policy names one cosigner, and why the path is three
Who cosigns is a row in a signed policy document, not a line of code. The document names a policy id, a quorum, and the enrolled keys; enrolling, retiring or replacing a cosigner is a new document under a higher policy id. A retired key stays in the policy for ever, so old cosignatures keep verifying years later. Retirement is not revocation.
A policy is refused at signing unless twice the quorum exceeds the number of active keys, and a reader holding a policy that fails that test is never granted a quorum grade from it: each cosignature is still checked on its own, but the set arithmetic is not credited. That arithmetic is what makes a double view self-incriminating: a quorum that a single captured signer could satisfy on both sides proves nothing. Its consequences for small sets are fixed:
| Active keys | Quorum | Accepted? | What it means |
|---|---|---|---|
| 1 | 1 | yes | One cosigner. An absence is reported as a shortfall, never hidden. |
| 2 | 1 | refused | A two-key set may not run at quorum one. |
| 2 | 2 | yes | Both must answer, every time. Either one down is a shortfall. |
| 3 | 2 | yes | The first configuration that tolerates one absence. |
So the first policy names one cosigner, because one is what removes the sentence above, and two buys no spare: it is refused at quorum one and fragile at quorum two. The intended end state is three cosigners at quorum two, and three independence units, not three keys under one roof.
The house's checker prints the arithmetic it finds on every run: how many of the required distinct keys verified, out of what set. A thin set discloses itself and is never smoothed.
What the house does not claim
- Not prevention. Cosigning detects a split view that a shared cosigner has seen; it does not prevent one.
- Not audited. The house commits to the bytes of the declaration and publishes where to read it. It does not verify the declaration's contents.
- Not a verdict. Neither a checkpoint nor a cosignature says anything about whether a receipt's claim is true.
- Not stronger than the reader's own key handling. A reader who pinned the cosigner set out of band may reach a quorum grade; a reader who accepted it on first use gets continuity, never identity; a set the checked artifact vouches for itself is displayed and never used.
How enrolment works
- Publish an about page at your own origin carrying your verifier key in C2SP vkey form (key type 0x04, Ed25519), your add-checkpoint endpoint, and your declaration.
- Pass the refusal test. BlueFox submits a deliberately inconsistent checkpoint and records the refusal.
- Be enrolled as a row: the key's own name, its algorithm set, the key, the key origin, the enrolment date, and the SHA-256 digest of your declaration, in a new signed policy under a higher policy id.
- Retire by document when you stop. Your key stays in the policy, and your old cosignatures keep verifying.
To start the conversation, email [email protected]with the subject line "Cosigner".
Model declaration
We operate a cosigner for the BlueFox Edge transparency log at ORIGIN. We generated its key on hosts we control and have never transmitted the private key to BlueFox. We are not a customer or a vendor of BlueFox Edge or of Format Dynamics, we hold no equity in it, and we receive no payment for cosigning. We share no parent company, controlling owner, officer or director with Format Dynamics, and we are not under common ownership or control with any other cosigner of this log. We do, or do not, wish to be named. If any value moves in either direction, for example engineering support, it is stated here. This statement is dated DATE and is published at URL; BlueFox commits to its SHA-256 digest in its signed cosigner policy.
Sources
- The C2SP specifications: tlog-checkpoint, signed-note, tlog-witness and tlog-cosignature, at c2sp.org.
- The served checkpoint: api.bluefoxedge.ai/v1/transparency/checkpoint. Walking the log: /docs/walk-the-log. What a checkpoint deliberately does not do: /learn/the-checkpoint.
- The published checker that prints the sentence above: api.bluefoxedge.ai/verify_consistency.py.
- The house's published key set: api.bluefoxedge.ai/.well-known/jwks.json.
- Glasklar Teknik, "Named policies for Sigsum", 4 February 2026. The unprompted statement quoted under "The declaration" was published by the operator of a testing cosigner at remora.n621.de and read on 3 September 2026.