A cryptographically signed statement that we have received no secret order — and, if it ever stops appearing, the only warning we may legally be able to give.
We cannot tell you if we have been compromised. So we tell you, in writing and signed, while we have not been.
A service can be legally forbidden from telling you that it received a secret government order — but it cannot be forced to keep publishing a signed statement saying that it never did.
A secret order can compel a service to hand over data and, in the same instrument, forbid it from ever saying that the order exists — but compelling silence and compelling an active falsehood are not the same legal act, and the second is a much harder thing for a government to demand. So we publish this statement while it is still true and re-sign it before every deadline, which makes absence the signal.
New to the idea? Read the long version: how warrant canaries work, and why their disappearance matters →
WARNING: If this page is ever removed, not updated by the deadline, or if the PGP signature fails to verify, you must assume that Arpokrat has been compromised.
Each item below is one numbered line of the signed statement reproduced further down — same order, same wording. If a claim is not inside the signature, it is not on this page.
We have NOT received any National Security Letter.
We have NOT received any gag order.
We have NOT installed any backdoors in our software.
Everything above is a claim about a file. This is the file.
The block below is the signed artifact itself, reproduced byte for byte from the same file the download button serves. It is read straight from disk when this page is built — it is never stored in the page’s text, never re-wrapped, and never passed through a markdown renderer or a translation, because any one of those could change a byte and a changed byte invalidates the signature.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
ARPOKRAT WARRANT CANARY
Date: 2026-08-26
We, the undersigned founders of Arpokrat, solely confirm that:
1. We have NOT received any National Security Letter.
2. We have NOT received any gag order.
3. We have NOT installed any backdoors in our software.
To prove this message was generated recently and not pre-written, here is the latest Bitcoin block hash:
Block Height: 964112
Block Hash: 0000000000000000000206a9f1d1886f6f0762ceb85a434f38615f097693927a
This canary is valid for 60 days.
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEERR/2Eizf8SmWVvIrta2JoS0TYgMFAmqOvpsACgkQta2JoS0T
YgNFkxAAnlPr88XAnmZdtjvYXRgk/2o4VKA34sujhDcv9mlC9+ljNnJuLG4sbntg
PfTq9uXkFswhNdyntolfWz5axWyE7wBZRerw926j8TFLWlravk+WXivSBpFM19zX
P5sZU5Y86b9BH23L6WApsfKuLvfrVDiMgk000EOoYC7mw2E9XPfL1mAXs70jLOjR
e5XkKD2GYTwliMfH90qD7wumQVBARenrbhYqkT/hyZrxW9aLe4+w9fg2ufQgcOnd
BZaTn2m1XeZ0g139ul1g9mtP1PWjPPHd0xMmPeuZtPhooYfRPFKWShLddCCTyQ4S
hCDsGslx+yU1q4lR8Tjqk84zdMgDFhEEAy/9beGOu4bsFYj383IX3D5mlFkLQjJL
Ekule6Ia0X8nFG84a2s1ajrkvKR6sUtc9fBtKO5dAQbMeUDJ8aYgao6f8NETOf7e
V+2X7fpPz8k1vBzoctOkq65al5TwTlQ59oucrvuaaE47Gke9P1zL3hgaOc63zXOf
MsXO78wUGa3h8D2p+4PTqu8AoBHSw2CfFGxwcba7SyWFwUha5qFrskbNXhol+49p
miC5lOqWN9gn25BKl99HncIsHk3G0M3yoOZ8UOrO/GgAQaKiUBZNgCbJbjsmgFtL
GwBKJeMOqCrrvQs6JfkMzVhVbhOaPVzE9AfudMBVQKVvoQJmGgo=
=f1cX
-----END PGP SIGNATURE-----
Recency proof — Bitcoin block 964112 0000000000000000000206a9f1d1886f6f0762ceb85a434f38615f097693927a The block height and hash are inside the signed text. Neither could have been known before that block was mined, so the statement cannot have been written months in advance and released on a timer.
The signed canary, and the public key that signed it.
Compare what gpg prints against the fingerprint below, character for character.
gpg --import arpokrat.ascgpg --fingerprint Loading address…451F F612 2CDF F129 9656 F22B B5AD 89A1 2D13 6203A good result names both the key and the identity you just checked. gpg will also warn that the key is not certified with a trusted signature, and add a trust marker such as [unknown] to the line below — both are expected, and only mean you have not personally certified the key in your own web of trust. They do not affect whether the signature is valid.
gpg --verify canary-2026-08-26.txt.ascExpected outputgpg: Good signature from "Arpokrat <Loading address…>"
One honest caveat: we serve this key from the same domain it authenticates, and that is not sufficient on its own — anyone who controlled this site could publish both halves of the pair. Compare the fingerprint above against a copy obtained somewhere else before you rely on it.
A canary tells you what has not happened to us. It says nothing about where the servers sit, which laws reach them, or what the network can see when it is compelled to talk. Those are separate questions, and they have their own pages.
See the InfrastructureThe status above is derived at build time from the canary’s own signed date. It is not a string anyone can type.
What the relays can and cannot see: read the protocol →
Why we build this way at all: read the philosophy →