Key policy
Machine-readable: /key-policy.json · full document: RAVEN_CRYPTO_AGILITY.md.
Current signed customer contract: POST /receipt/v1, domain raven-receipt, version v1, Ed25519. Current receipts carry signerPublicKey, payloadHash, receiptId, and signature. Verify them with the receipt-v1 vector, then match signerPublicKey to an independently authenticated pin. /pubkey is discovery/cross-check only. Legacy v2 compatibility: POST /verify uses keyId/signatureAlg and the raven-official-attestation domain; those are not receipt-v1 fields. Key rotation remains explicit and versioned. Future algorithms require a separately documented versioned contract; none is claimed today. No quantum-safety, indefinite certainty, token-safety, or investment claim is made.