Who is accountable
ActaSeal is built by Xavier Goshi. One person is responsible for the product, the published verifier, and everything written on this site. If a claim here turns out to be wrong, there is no committee to route it through.
Standards work
The design decisions behind ActaSeal are argued in public rather than asserted here. In the IETF SCITT working group:
- Issue #461 — an evidence-binding trust-boundary finding on the architecture draft.
- Pull request #463 — receipt profile requirements for verification results, with an implementation status section covering two independent implementations.
ORCID: 0009-0006-0583-6968. Code: github.com/actaseal.
What that means for a buyer
Decisions here are made by one person rather than a committee, and that is stated plainly because it changes who you are dealing with. There is no SOC 2 Type II report; if your vendor qualification names one, ActaSeal does not meet it today. What none of this changes is whether the evidence works — the verifier is published separately under the Apache License 2.0 and runs offline, so nothing about the product's correctness depends on this company still existing.
Contact
xavier@actaseal.com for anything about the product or the standards work. security@actaseal.com for a vulnerability report — see the disclosure policy.