We keep building at
@arkisxyz to make sure both what we release and how we release it can be verified. We started with attestation, built with
@spearbit. Now we've established a governance board with
@sparkfinance , responsible for enforcing that record before any release ships.
Here are the layers we built into that enforcement process: Kyverno rejects unattested images before they can run, an MPC wallet separates the team that builds a release from the team that can approve it and the governance board executes verification on their own infrastructure, recomputing the release identifier and checking every implementation hash against the attestation before signing.
None of these layers share a failure mode: compromise one, including us, and the next still catches it, so a single break-in is never enough. This is the security institutions lending into Arkis get - protection for their capital that no single point of failure can break.