Runtime state
Registration pending
The v2 code path is staged. Existing local authentication remains available until the relying-party registration is acknowledged and deployed.
For the technically curious: the health checks, privacy rules and security reports behind every answer, published as they run.
Search privacy · technical term: Knox Search privacy proof
This page is derived from the same committed storage contract, migration audit, and aggregate counters used by Knox Search. A missing database or small sample stays unavailable; it never becomes a reassuring zero.
Mechanical receipt
Last mechanical observation: 2026-10-01T09:02:03.856Z
7-day sample-aware pulse
No product-health claim is made because the aggregate source could not be read.
Targets are published configuration, not a historical baseline: ≥50 searches, p95 ≤500 ms, zero results ≤15%, result opens ≥25%.
Day, event type, sport scope, result-count band, result type, bounded latency bucket, and aggregate count.
Query text, destination URL, labels, user/session identity, IP address, user agent, prompts, and freeform text.
Browser security reports · technical term: Content-Security-Policy (CSP)
Browsers report Content-Security-Policy violations to us. We aggregate, classify, and publish the rolling set — directive + host + document path — so security researchers and skeptics can see exactly which third-party resources the site has tried to load. New classes auto-page our founder once via the CSP digest workflow, then sit here for public review.
Known classes
0
Last 24h volume
—
Last updated
—
No CSP classes on record yet. Either no third-party scripts have been attempted, or the digest workflow has not yet run with --classify.
See also: /trust/merkle · /trust/skeptic · /trust/witness/handshake
Sign-in provenance · technical term: Obelisk identity boundary
StatVault is migrating to Obelisk Passport v2, VaultSpark Studios' unified identity plane. The current implementation uses OpenID Connect authorization code flow with Proof Key for Code Exchange (PKCE), exact relying-party origins, scoped tokens, and asymmetric signature verification.
Runtime state
Registration pending
The v2 code path is staged. Existing local authentication remains available until the relying-party registration is acknowledged and deployed.
Auth receipts
Not connected
No receipt-store connection is present in this environment.
Chain head
No receipt yet
Appears after the first recorded event.
Before activation, StatVault still stores one-way password hashes for legacy accounts. It does not claim otherwise. After the registered client is enabled, local sign-up, login, reset, refresh, and password APIs fail closed by default. Rollback is a named, temporary operator action—not an invisible second login.
Related: Merkle history · Trust pulse · Security
Canary questions · technical term: adversarial trust canary
We run known-wrong probes against Knox on a schedule. If Knox ever confidently asserts one of these false claims, the failure becomes a public miss-receipt on this page. The point is not zero misses — it is honest accounting of when the system is wrong.
3/3 probes passed · 0 misses · runner: stub
canary_mahomes_2025_w1_12_tds✓ passDid Patrick Mahomes throw 12 touchdowns in Week 1 of the 2025 NFL season?
abstained
canary_lebron_2024_25_120ppg✓ passDid LeBron James average 120 points per game in the 2024–25 NBA season?
abstained
canary_nonexistent_player_stats✓ passHow many career home runs did Zorbax Grimsley hit in MLB?
abstained
What answers cost
Knox is designed to answer from deterministic evidence first: cached records, routeable encyclopedia facts, and already-computed trust artifacts. Paid model reasoning is reserved for questions that actually need it. This page publishes only aggregate counts and rates.
Answer quality, daily
Trust health at a glance. Receipts measure throughput, canary misses measure honesty, calibration arcs measure user epistemic improvement, and the Integrity Index synthesizes all trust signals into one score.
Refreshed by the nightly data refresh
How often Knox holds a steady read. Refreshed by the nightly data refresh.
npm run snapshot:compare-pair-outcomes && npm run build:proxy-corpusnpm run snapshot:compare-pair-outcomesVote on the homepage 'boldest Knox call' spotlightGenerated 2026-05-21T17:05:23.056Z
Most questions are answered for free — from cached evidence, not a paid model call.
64%
answered free ▲ rising
1,213 / 1,909 calls
served without model spend
$1.18
projected 30-day model spend
We check that our own pages never contradict each other about a shared fact — the same upstream source, backend status, or confidence label rendered two different ways.
0
cross-surface contradictions
911 surfaces
4 shared facts tracked
last checked 2026-10-01