Governance — versions and hashes
Back to homepageThis page records which version of CFI.co’s governance file is in force, its cryptographic hashes, what has superseded what, and how to check all of it without taking CFI.co’s word for any of it.
The version in force
Public Edition v1.0 (internal v3.0), adopted 1 August 2026. It is the first governance file CFI.co has published.
| File | SHA-256 | What it is |
|---|---|---|
| governance-public-edition-v1.0.docx | 6829072874467AB111D4A68C3A1D36FF111E5ACA52501B2EB13E287130B567CB | The adopted text. This is the file both principals put their names to. |
| governance-public-edition-v1.0.md | ECB54D801065DCB2E4CF398E7FD1A08C0387FC42BF009ED6943D37DC88901938 | A rendering of the above for reading by people and machines. Not a second version. |
| step2-agreement.txt.asc | E7180A7E6F91AC9CDBA1F089A053D319AA459056800A3E892DE433C2CC9F1445 | A principal’s signed agreement to the adoption, made over the hash of the .docx. |
Where the rendering and the .docx differ, the .docx governs and the difference is a defect to be corrected under the file’s Corrections provision.
The governance file names github.com/cfi-co/governance as its repository, and that is the address the file itself points to. The copies on this site are convenience copies of the same bytes; if they ever diverge, the repository is the one to trust, and the divergence is a defect.
Superseded versions
Versions 1.0 and 2.0 were both adopted on 2 July 2026 and were internal. Neither was ever published, and no hash is recorded for them here: publishing a hash would imply a public artefact that never existed. They are named so that a reader can see this edition has a history rather than being told it starts here. Their content is superseded in full by the version above.
Recorded dissent
None. The adoption block records dissent as none, all provisions adopted, none held. Should any future amendment be adopted over a principal’s recorded objection, that objection is published here alongside the version it concerns.
Propagation status
Not yet complete. The file requires its rules to be propagated into the bundled copies carried by CFI.co’s agents and skills within five working days of Step 2 — by 7 August 2026. That work is outstanding at the time of writing, and this line will state the date it completed rather than being removed.
The archive anchor
Three artefacts, each proving something different, none of them sufficient alone:
- MANIFEST.sha256 — the three hashes in machine-checkable form.
- MANIFEST.sha256.ots — an OpenTimestamps proof. It shows the manifest existed at a point in time, attested by the Bitcoin blockchain rather than by CFI.co. It says nothing about who wrote it.
- MANIFEST.sha256.asc — a detached GPG signature from CFI.co’s archive key. It shows the manifest came from CFI.co. It says nothing about when.
The archive key sits on a CFI.co server and is used by scheduled jobs, so its signature attests to the estate rather than to a person. The two signatures on the governance file itself — the publisher’s and a principal’s — are made with keys that are not on any CFI.co machine. That distinction is the point of publishing three signatures rather than one.
This page is itself captured by the Internet Archive, so a reader can compare what it says now with what it said at publication: capture of 1 August 2026, 18:27:35 UTC. That capture is held by a third party and CFI.co cannot alter or remove it.
Checking this yourself
curl -O https://cfi.co/archive-data/governance/governance-public-edition-v1.0.docx sha256sum governance-public-edition-v1.0.docx curl -O https://cfi.co/archive-data/governance/step2-agreement.txt.asc gpg --verify step2-agreement.txt.asc git clone https://github.com/cfi-co/governance.git cd governance && git verify-commit HEAD && git verify-tag public-edition-v1.0
The signing keys are published in two places maintained separately, so that neither CFI.co alone nor a keyserver alone is the source of truth:
dig +short TXT _principal-mark.cfi.co dig +short TXT _archive-publisher.cfi.co dig +short TXT _archive-key.cfi.co
The keys, and where each one lives
| Fingerprint | Identity | Custody |
|---|---|---|
C5FD92210CCF0D31271EA4BC6B681CAAA8BAA1FE | Marten Mark <[email protected]> | Held by the principal personally, on a machine CFI.co does not operate. |
60AEC217836A905DCFED94F4097D7CA64028F174 | CFI.co Publisher Counter-Signature <[email protected]> | Held by the publisher. Not on any CFI.co server. |
B497BDC19FCD487972D5D2B0876FF2AA39133BF8 | CFI.co Transparency Archive <[email protected]> | On a CFI.co server, operated by scheduled jobs. |
How adoption was entered
The publisher signed on 1 August 2026. The second principal’s name was entered by the publisher on that principal’s written authority of the same date, which is stated in the adopted file rather than disclosed here for the first time. The signed statement above is that authority, made under a key the publisher does not hold, so the part of the record that would otherwise rest on one person’s account of another’s agreement can be checked independently.
That statement says in terms what it does and does not prove. It is not offered as evidence that two people independently exercised judgement.
Further reading
A Letter from the Publisher: Rules That Can Be Checked — the publisher’s account of why these rules exist, what they commit CFI.co to, and why a rule that cannot be checked is not a rule. The letter carries the SHA-256 of the governance file above in its machine-readable metadata, so the letter and this page corroborate each other rather than each asserting its own version of events.
What CFI.co has found wrong in its own published claims
The known-open register records defects CFI.co has found in what it publishes, including four added on the day this file was adopted. One of them concerns a claim made in the governance repository itself.










































































