Omnel · the public log

A line for every step, and each one holds the last.

A protocol registered, a draw, a report, a mark that stands, a mark withdrawn, a review policy, a reviewer's key, a signed decision: each is a line with the digest of what it says, the hash of the line before, and its own hash. Lines written by our own tests of the system against production stay in the chain and are labelled as such. The last hash of each day is anchored outside us on OpenTimestamps. Download it, recompute it, and you need nobody's word — not ours.

Download (JSON)
Your browser is recomputing the chain…
#WhenKindSaysHash
5010 Oct 2026pool1655e0a87f34d1fd…
5110 Oct 2026evolution2526ebdb38eeaf63…
5210 Oct 2026protocolproof run (not a customer)loops-proof-bd7f62f6 · Selione — loops proof run bd7f62f6 (not a customer) · n=30 · third_party · report0973c67046f2850c…
5310 Oct 2026drawproof run (not a customer)36 items drawn, seed revealed · reportfc64e4a85bc37ecc…
5410 Oct 2026protocolproof run (not a customer)loops-proof-echo-bd7f62f6 · Selione — loops proof run bd7f62f6 (not a customer) · n=30 · first_person · report2006657370c307db…
5510 Oct 2026drawproof run (not a customer)35 items drawn, seed revealed · reportd6e973201a450fb1…
5610 Oct 2026reportproof run (not a customer)loops-proof-bd7f62f6 · 30 judged · bound 7.4% · holds · report563cfbd44e697a37…
5710 Oct 2026reportproof run (not a customer)loops-proof-echo-bd7f62f6 · 30 judged · bound 12.4% · does not hold · withheld · reportd0d32f7351093748…
5810 Oct 2026protocolproof run (not a customer)selione-proof · Selione — proof run (not a customer) · n=36 · first_person · report197406311821eae0…
5910 Oct 2026drawproof run (not a customer)41 items drawn, seed revealed · report1d703c32b59d1854…
6010 Oct 2026reportproof run (not a customer)selione-proof · 33 judged · bound 11.3% · holds · report11cda3287f6ad00c…
6110 Oct 2026protocolproof run (not a customer)selione-proof · Selione — proof run (not a customer) · n=36 · first_person · report01692f6c1b2fba03…
6210 Oct 2026drawproof run (not a customer)41 items drawn, seed revealed · reportefde30dff81fea10…
6310 Oct 2026reportproof run (not a customer)selione-proof · 32 judged · bound 11.7% · holds · report15def8ccd3b20aae…
6410 Oct 2026protocolproof run (not a customer)selione-proof · Selione — proof run (not a customer) · n=36 · first_person · report119fab5c78a7773f…
6510 Oct 2026drawproof run (not a customer)41 items drawn, seed revealed · report98ccd2d9d4232468…
6610 Oct 2026reportproof run (not a customer)selione-proof · 32 judged · bound 11.7% · holds · report51394d91dbde8d99…
6710 Oct 2026policyproof run (not a customer)5967dcdca7e5215b…
6810 Oct 2026statementproof run (not a customer)32b40fe46847136a…
6910 Oct 2026reviewerproof run (not a customer)1d6623f3ab3033c2…
7010 Oct 2026decisionproof run (not a customer)e22c2860eefc43ef…
7110 Oct 2026goldenproof run (not a customer)d99c1469722900fd…
7210 Oct 2026protocolproof run (not a customer)tacit-f05ac1eb0065 · Selione — Tacit proof run (not a customer) · n=47 · first_person · report91da34f391e4e78b…
7310 Oct 2026drawproof run (not a customer)52 items drawn, seed revealed · report127e7b8f05541b17…
7410 Oct 2026reportproof run (not a customer)tacit-f05ac1eb0065 · 41 judged · bound 5.5% · holds · reporte6b983a1404ba838…
7510 Oct 2026markproof run (not a customer)selione-proof · measured, until 8 Jan 2027 · report69ec6b7b43f96a10…
7610 Oct 2026markproof run (not a customer)tacit-f05ac1eb0065 · measured, until 8 Jan 2027 · report1e3c26c52e5fc2c3…
7710 Oct 2026keyproof run (not a customer)reviewer key e0ceb829a4fb83a9 revoked60d50d5cb88547e5…
7811 Oct 2026pool779830b4b67a42b8…
7911 Oct 2026evolution7fd465bbf92c7bc9…
8511 Oct 2026protocolproof run (not a customer)selione-proof · Selione — proof run (not a customer) · n=36 · first_person · reporte95e20aff4054b59…
8611 Oct 2026drawproof run (not a customer)41 items drawn, seeds kept until the close · reporte36e1ac68010790c…
8711 Oct 2026reportproof run (not a customer)selione-proof · 32 judged · bound 11.7% · holds · seeds revealed · report266d27adf990969e…
8811 Oct 2026protocolproof run (not a customer)loops-proof-7ed17865 · Selione — loops proof run 7ed17865 (not a customer) · n=30 · third_party · report8d7809e2bb5bfa7c…
8911 Oct 2026drawproof run (not a customer)36 items drawn, seeds kept until the close · report288e6ef552d7d427…
9011 Oct 2026protocolproof run (not a customer)loops-proof-echo-7ed17865 · Selione — loops proof run 7ed17865 (not a customer) · n=30 · first_person · report443b6c4c48601acf…
9111 Oct 2026drawproof run (not a customer)35 items drawn, seeds kept until the close · report92e9a1434d63c4cf…
9211 Oct 2026reportproof run (not a customer)loops-proof-7ed17865 · 30 judged · bound 7.4% · holds · seeds revealed · report6fc6fbff8eac1c3c…
9311 Oct 2026reportproof run (not a customer)loops-proof-echo-7ed17865 · 30 judged · bound 12.4% · does not hold · withheld · seeds revealed · report7105db31d81b28d1…
9411 Oct 2026protocolproof run (not a customer)tacit-b6cc9a41a24b · Selione — Tacit proof run (not a customer) · n=47 · first_person · reportfdc17857337fdad5…
9511 Oct 2026drawproof run (not a customer)52 items drawn, seeds kept until the close · report90f057d9c56e1dc9…
9611 Oct 2026reportproof run (not a customer)tacit-b6cc9a41a24b · 43 judged · bound 5.3% · holds · seeds revealed · reportf32f15d40dcd8bef…
9711 Oct 2026policyproof run (not a customer)be844e84ba8aeff5…
9811 Oct 2026statementproof run (not a customer)e67093103713db0a…
9911 Oct 2026reviewerproof run (not a customer)e46ecd0c924ac869…
10011 Oct 2026decisionproof run (not a customer)f10901c9774a2dd6…
10111 Oct 2026goldenproof run (not a customer)03ddb9a914891699…
10211 Oct 2026markproof run (not a customer)selione-proof · measured, until 9 Jan 2027 · report5766eb0a0e94628a…
10311 Oct 2026markproof run (not a customer)tacit-b6cc9a41a24b · measured, until 9 Jan 2027 · report2cdcfe7f49b7926d…
10411 Oct 2026keyproof run (not a customer)reviewer key f299c8345a14493f revoked0d73698412796e9a…

Daily roots, anchored

DayLast lineRoot (the day's last hash)OpenTimestamps
2026-10-11797fd465bbf92c7bc9bec9bf4248b80f825bac49072e499ec400485e84b43edb15proof (.ots) · a calendar's promise, waiting for its Bitcoin block
2026-10-10310882eae8057c02fb38fb05723066a3bae0532d3c1bfe5995bcf6168b5b1e05c0proof (.ots) · anchored in a Bitcoin block
2026-10-09310882eae8057c02fb38fb05723066a3bae0532d3c1bfe5995bcf6168b5b1e05c0proof (.ots) · anchored in a Bitcoin block
2026-10-088191baed645de409c41facea070d90a9018515b591d089bf2d3778e43e933b25cproof (.ots) · anchored in a Bitcoin block

Recomputing it yourself

For each line: digest = SHA-256 of the payload as canonical JSON (keys sorted at every depth, compact); entry_hash = SHA-256 of prev_hash + ':' + digest + ':' + kind + ':' + at (ISO 8601 UTC with milliseconds). The first line's prev_hash is 64 zeros. A stretch of the log that does not start at the first line is carried forward to the daily root that covers its last line, which must be reached exactly. A root is the entry_hash of the log's last line when the Night anchored it. Its proof is a detached OpenTimestamps file whose committed digest is the root itself — its 32 bytes, hex-decoded, not hashed again — that is, a timestamp of the line's string prev_hash:digest:kind:at, whose SHA-256 is the root. Verify it with the public client, without us: `ots verify -d <root_hash> <proof.ots>`.

The roots are at /api/lumen/v1/register/roots. A protocol's signed report, with its own anchor, is at /api/lumen/v1/register/<id>; the verifier checks its signature in your browser. Every day the instrument's own state is committed in this chain too: the evolution, day by day.

Auditing it like Certificate Transparency

The log is also a Merkle tree in the shape of Certificate Transparency (RFC 9162 §2.1, SHA-256). Its leaves are the log's lines in index order — leaf 0 is the first line; line numbers may skip, positions never do — and a line's leaf is the 32 bytes of its entry_hash, hex-decoded, so its leaf hash is SHA-256(0x00 || those 32 bytes) and a node is SHA-256(0x01 || left || right). A checkpoint is a C2SP signed note in the tlog-checkpoint format: three lines, each ending with a newline — the origin omnel.selione.ai/log, the tree size in decimal, the root in base64 — then a blank line, then the line '— omnel.selione.ai/log ' followed by the base64 of a 4-byte key ID and the 64-byte Ed25519 signature of those three lines. The key ID is the first 4 bytes of SHA-256('omnel.selione.ai/log' || 0x0A || 0x01 || the 32-byte public key); the public key is the one every signed report carries (the last 32 bytes of its SPKI form), and the verifier key a client pins is 'omnel.selione.ai/log+<key ID in hex>+<base64 of 0x01 || public key>'. Inclusion and consistency proofs are RFC 9162 §2.1.3.2 and §2.1.4.2: any CT library verifies them. Each night a checkpoint is signed with the day's root: its tree ends at that root's line, and its own root is anchored on OpenTimestamps the way the day's root is — the proof commits the Merkle root's 32 bytes, not hashed again (`ots verify -d <root_hash> <proof.ots>`). Keep the last checkpoint you verified: a later one must be joined to it by a consistency proof. Two signed checkpoints that no consistency proof joins are a fork, and the two notes are the evidence.

The newest signed checkpoint is at /api/lumen/v1/register/checkpoint (?format=note for the note alone, ?size= for an earlier one); an inclusion proof at /api/lumen/v1/register/proof/inclusion?idx=<line>&size=<size>, a consistency proof at /api/lumen/v1/register/proof/consistency?from=<size>&to=<size>. The verifier key to pin: omnel.selione.ai/log+10dc08d3+AWfF9+0VImjkBj+VDEqbUyVJZh2F6b/3LqXRVeTJ8lhd.

The open verifier is one file for Node 20 or later, with no dependency. node omnel-verify.mjs chain selione.ai downloads the whole log and recomputes the chain, every daily root and every checkpoint from it; checkpoint, inclusion <line>, consistency <size> and ots <day> check one thing each. It keeps the last checkpoint it verified and calls a fork when the next one does not extend it. What it cannot prove alone: that everyone is shown the same log — only checkpoints compared between several people can — and the Bitcoin block itself, which ots verify checks.

Witnesses. Each checkpoint is served with its witnesses' cosignatures appended after the log's own signature line. A witness is a separate machine with its own key: it keeps the last checkpoint it cosigned, refuses a new one that a consistency proof does not join to it, keeps its own copy of every line and refuses to sign while any line it holds has changed, and only then signs. A cosignature line is '— <witness name> ' followed by the base64 of a 4-byte key ID, an 8-byte big-endian POSIX time and a 64-byte Ed25519 signature (C2SP tlog-cosignature, signature type 0x04). The signature covers the line 'cosignature/v1', the line 'time ' and that time in decimal, then the checkpoint's three lines exactly as the log signed them, each line ending with a newline. The key ID is the first 4 bytes of SHA-256(witness name || 0x0A || 0x04 || the 32-byte public key), and the witness key a client pins is '<witness name>+<key ID in hex>+<base64 of 0x04 || public key>'. A client that pins only the log's key (omnel.selione.ai/log) ignores these lines; a client that also pins witness keys can require a number of them, and refuse a checkpoint that only the log vouches for. The witness keys to pin:

  • omnel.selione.ai/witness/1+3562f553+BGNkkZMmMzcx1EABLyqN6pkQ7Gg0erXnrqc72LcI2anj — Selione — our own witness, on a machine of its own at another host than the site, with a key that never leaves it. It is not independent of us: it guards against a compromised site or base, not against its operator.

node omnel-verify.mjs checkpoint selione.ai --witness <witness key> --min-witnesses 1 refuses the newest checkpoint unless that witness cosigned it. Witnesses run by other organisations, on their own machines, are the next step: until then a witness here guards against a compromised site, not against us.