Notarizing · documentation

Notarizing documentation

Developer preview. Not yet production ready. This page is rendered from docs/README.md of the Notarizing repository at revision d23579e737f9d1e16e07b3c6b21a51282d64027e. It describes the behavior of that revision.

Contents

Read these guides in this order:

  1. User guide: set up a workspace, import a change and review it in the browser.
  2. Evidence producer guide: write notarizing.check-report/1 reports.
  3. Operator guide: run serve, back up, restore, purge, move evidence, connect the optional ka2a adapter and connect agents through MCP.
  4. Upgrade notes: back up, then migrate the workspace schema.
  5. CLI reference: the help text of every command.
  6. Release builds: build the release artifacts and verify the files that you receive.
  7. Compatibility: what stays stable between versions.
  8. Threat model: what notarizing protects, and a hardening checklist.
  9. Privacy and accessibility: network connections, stored data and the accessibility checks that ran.
  10. Writing specifications: write an OpenSpec change that notarizing reads well.
  11. CI recipes: produce check reports in CI and import them as a reviewer.
  12. Collaboration: share evidence and review between workspaces.
  13. Limits: every user-visible limit, the measured scale and what is not measured.

The specification of the product is in openspec/changes/reimplement-notarizing/. The acceptance ledger shows which behavior has automated evidence and which gaps remain. These guides describe the behavior of this revision. They do not claim more than the ledger shows.