Security
- Every seal is signed with ES256
- One published key signs them all
- Change one character and it fails
Every seal is signed with one public key. Check it yourself — free, offline, without asking us.

Every product carries a status label. If it isn’t live, the page says so.
Your ID and liveness check runs with our verification partners. We only receive a signed result.
AI-generated imageFour steps, all on your own machine. Nothing is sent to us.
Split it into header, claims and signature.
header.payload.sigMatch its key ID to our public key.
kid 5arz-oracle-2Run the ES256 math on your machine.
ES256 · P-256Valid or not. No network call to us.
valid ✓It’s published for anyone to fetch. Any JWT library can check a seal with it.
{
"keys": [{
"kid": "5arz-oracle-2",
"alg": "ES256",
"kty": "EC",
"crv": "P-256",
…
}]
}
Found a weakness? Tell us privately at security@5arz.com. We won’t take legal action over good-faith research.
Scope and policy: security.txt
Checking a seal is free and unlimited.