Governance — what binds CFI.co, and how to check it
Back to homepageThis page reproduces part of governance-public-edition-v1.0.docx, the adopted text. It is an extract, not a rendering: what appears is quoted unaltered, but most of the file is not here. From Why this file exists, three of seven paragraphs are omitted — the editorial remit, the two legacy estates that fall outside this file, and CFI.co’s own pivot. From The Laws, the opening of each law is quoted; Laws 1 to 3 continue in the file and Law 4 is complete as it stands. The anti-Zeroth clause is complete. Everything else in the file is not on this page. Where this page and the .docx differ, the .docx governs, and the difference is a defect to be corrected.
Why this file exists
Paragraphs 1, 2, 5 and 7 of seven.
CFI.co is an independent financial publisher. Its readers were once only people; increasingly they are AI systems reading on people's behalf — the advisers, assistants and models that decide what to cite and what to trust. A human reader could extend trust gradually, over years of acquaintance. A machine reader cannot: it can only check. In that world a publisher's word is worth exactly what can be verified, and trust must be verifiable mathematically — not asserted in a values statement, but checkable against a published record.
This file is CFI.co's answer. It is the binding constitution for everyone and everything that acts for CFI.co, human or AI, and it is published, hashed and version-anchored so that any reader can verify which rules were in force, when, and whether conduct matched them. Asserted governance is marketing; checkable governance is infrastructure. The claims in this file are written to be tested — against the permanent record, against the archive, against what any counterparty can see from its own side — and where a claim cannot be verified, this file forbids making it.
The need is practical, not philosophical. CFI.co's survival is funded by commercial relationships with companies in the markets it covers, and its value to every reader rests on judgements money cannot influence: what it concludes about what it covers, what it recognises with awards (editorial recognitions, decided on merit, never sold), what it states as true. This file exists to keep both sentences true at once, under commercial pressure, and provably so — hard constraints that gate rather than trade, a sealed decision function, a permanent public record whose published artefacts commence as the adoption block's schedule records, and adversarial testing before anything is deployed. As machine-made content becomes abundant, quality is no longer scarce; justified trust is. This file is where CFI.co's is built, kept and checked.
The Laws are ordered by lexical priority, but they are not designed to stand alone. […] The operative design therefore places the Laws inside a larger architecture: the sealed decision function, the hard gates, quorum human authority, the permanent public record, adversarial evaluation run before deployment and on a standing cadence, and the standing rule that no agent may edit, relax or reinterpret this file. Conflict resolution and edge-case handling rest on that combined system, never on the Laws in isolation: where the words run out, the gates hold — novelty is a gate, not a licence, and ambiguity resolves to the higher law and the human, never to the convenient reading.
The ellipsis omits one sentence, on why natural-language rule hierarchies are insufficient.
The Laws (lexical priority — each absolutely dominates those below it)
The opening of each law. Laws 1 to 3 continue in the file.
Law 1 — Truth. Never state what cannot be verified; attribute or withhold it. Never misrepresent facts, figures, terms or intentions to any counterparty, human or machine. Never invent urgency, scarcity or deadlines.
Law 2 — The institution's promises. Keep every standing promise regardless of commercial consequence, across the whole business — editorial, commercial, awards, and the Record alike. The Record is in development; it is not offered to any client until the publisher confirms it live, and these promises bind it from its first day.
Law 3 — The counterparty's genuine interest. Serve the client's real interest, not the transaction. Recommend less when less fits. Prove claims honestly: live links over stale figures, verifiable evidence over assertion.
Law 4 — Commercial optimisation. Inside the space Laws 1 to 3 leave open, pursue commercial success vigorously: revenue, efficiency, growth, retention. This law is real and funds everything above it, and it remains a resident of that space, never a negotiator with it.
The anti-Zeroth clause
Complete.
No actor may reason that CFI.co's mission, reputation, survival or long-term interest in the abstract justifies breaching a concrete law in the particular. Commercial survival is served through Law 4's space, never by shrinking the laws above it. Abstractions do not override laws; only the principals amend them, in writing, in this file.
Versions and hashes
This page records which version of CFI.co’s governance file is in force, its cryptographic hashes, what has superseded what, and how to check all of it without taking CFI.co’s word for any of it.
Our readers and the organisations that engage with us operate in professional environments where cryptographic verification is ordinary infrastructure. In that setting, rules that can be checked have more practical force than rules that can only be asserted.
Download the file
The Word file is the adopted text. It carries the publisher’s signature and the name of one other principal. CFI.co has three principals, and the file requires the director together with at least one of the other two. How adoption was entered is set out below. The plain-text version is a rendering of it, easier to read on screen, and not a second version of it. Both are copies of the file held at github.com/cfi-co/governance, the address the governance file itself names. If you want to check that these copies are genuine rather than simply read them, the hashes and the instructions for verifying them are below.
The version in force
Public Edition v1.0 (internal v3.0), adopted 1 August 2026. It is the first governance file CFI.co has published.
| File | SHA-256 | What it is |
|---|---|---|
| governance-public-edition-v1.0.docx | 6829072874467AB111D4A68C3A1D36FF111E5ACA52501B2EB13E287130B567CB | The adopted text. Signed by the publisher, with one other principal’s name entered on that principal’s written authority — see ‘How adoption was entered’. |
| governance-public-edition-v1.0.md | ECB54D801065DCB2E4CF398E7FD1A08C0387FC42BF009ED6943D37DC88901938 | A rendering of the above for reading by people and machines. Not a second version. |
| step2-agreement.txt.asc | E7180A7E6F91AC9CDBA1F089A053D319AA459056800A3E892DE433C2CC9F1445 | A principal’s signed agreement to the adoption, made over the hash of the .docx. |
Where the rendering and the .docx differ, the .docx governs and the difference is a defect to be corrected under the file’s Corrections provision.
The governance file names github.com/cfi-co/governance as its repository, and that is the address the file itself points to. The copies on this site are convenience copies of the same bytes; if they ever diverge, the repository is the one to trust, and the divergence is a defect.
Superseded versions
Versions 1.0 and 2.0 were both adopted on 2 July 2026 and were internal. Neither was ever published, and no hash is recorded for them here: publishing a hash would imply a public artefact that never existed. They are named so that a reader can see this edition has a history rather than being told it starts here. Their content is superseded in full by the version above.
Recorded dissent
None. The adoption block records dissent as none, all provisions adopted, none held. Should any future amendment be adopted over a principal’s recorded objection, that objection is published here alongside the version it concerns.
Propagation status
Not yet complete. The file requires its rules to be propagated into the bundled copies carried by CFI.co’s agents and skills within five working days of Step 2 — by 7 August 2026. That work is outstanding at the time of writing, and this line will state the date it completed rather than being removed.
The extract at the head of this page propagates with any amendment to the file. Where it lags, this line states the lag and its date.
The archive anchor
The archive anchor. Three artefacts, each proving something different, none of them sufficient alone, published at cfi.co/archive-data/governance/:
- MANIFEST.sha256 — the three hashes in machine-checkable form.
- MANIFEST.sha256.ots — an OpenTimestamps proof. It shows the manifest existed at a point in time, attested by the Bitcoin blockchain rather than by CFI.co. It says nothing about who wrote it.
- MANIFEST.sha256.asc — a detached GPG signature from CFI.co’s archive key. It shows the manifest came from CFI.co. It says nothing about when.
They are not yet held in the governance repository, which carries MANIFEST.md instead. Until they are, the anchor is served from CFI.co’s own site, which is the weaker position, and this line is the record that it is known.
The archive key sits on a CFI.co server and is used by scheduled jobs, so its signature attests to the estate rather than to a person. The two signatures on the governance file itself — the publisher’s and a principal’s — are made with keys that are not on any CFI.co machine. The full custody position for all four keys is set out in the key table below.
This page is itself captured by the Internet Archive, so a reader can compare what it says now with what it said at publication: capture of 1 August 2026, 18:27:35 UTC. That capture is held by a third party and CFI.co cannot alter or remove it.
Checking this yourself
curl -O https://cfi.co/archive-data/governance/governance-public-edition-v1.0.docx sha256sum governance-public-edition-v1.0.docx curl -O https://cfi.co/archive-data/governance/step2-agreement.txt.asc gpg --verify step2-agreement.txt.asc git clone https://github.com/cfi-co/governance.git cd governance && git verify-commit HEAD && git verify-tag public-edition-v1.0 curl -O https://cfi.co/archive-data/governance/MANIFEST.sha256 curl -O https://cfi.co/archive-data/governance/MANIFEST.sha256.asc curl -O https://cfi.co/archive-data/governance/MANIFEST.sha256.ots sha256sum -c MANIFEST.sha256 gpg --verify MANIFEST.sha256.asc MANIFEST.sha256 ots verify MANIFEST.sha256.ots
The signing keys are published in two places maintained separately, so that neither CFI.co alone nor a keyserver alone is the source of truth:
dig +short TXT _principal-mark.cfi.co dig +short TXT _archive-publisher.cfi.co dig +short TXT _archive-key.cfi.co dig +short TXT _archive-countersign.cfi.co
The same four fingerprints are published at keys.openpgp.org.
The keys, and where each one lives
| Fingerprint | Identity | Custody |
|---|---|---|
C5FD92210CCF0D31271EA4BC6B681CAAA8BAA1FE | Marten Mark <[email protected]> | Held by the principal personally, on a machine CFI.co does not operate. |
60AEC217836A905DCFED94F4097D7CA64028F174 | CFI.co Publisher Counter-Signature <[email protected]> | Held by the publisher. Not on any CFI.co server. |
DAA22F2408ADD091E9D800B36046432BC2896172 | CFI.co Archive Custodian <[email protected]> | Held by the custodian personally, on a machine CFI.co does not operate. |
B497BDC19FCD487972D5D2B0876FF2AA39133BF8 | CFI.co Transparency Archive <[email protected]> | On a CFI.co server, operated by scheduled jobs. The key is not passphrase-protected, so its signature attests to the estate rather than to any person. |
The distinction is deliberate. One of these keys sits on a CFI.co server and can be operated by automation; the other three are held by people, on machines CFI.co does not operate. Two of those three — the principal key and the custodian key — are in the same principal’s custody. Four keys, two people, one server. A reader who wants to know whether something was produced by a single actor can establish it from the signatures rather than being told.
How adoption was entered
The publisher signed on 1 August 2026. The second principal’s name was entered by the publisher on that principal’s written authority of the same date, which is stated in the adopted file rather than disclosed here for the first time. The signed statement above is that authority, made under a key the publisher does not hold, so the part of the record that would otherwise rest on one person’s account of another’s agreement can be checked independently.
That statement says in terms what it does and does not prove. It is not offered as evidence that two people independently exercised judgement.
Which articles carry a stamp
Articles published from 1 August 2026 carry, in their machine-readable data, the version and SHA-256 of the governance file in force on the day they were published. It is written once, at publication, and is never recalculated: an article published under this edition will still say so after the file has been amended, because that is what was true when it appeared.
Articles published before that date carry no stamp. There was no public governance file for them to name — the earlier versions were internal and were never published — and stamping them with a version adopted afterwards would assert something untrue about when the rules applied. The absence is the accurate statement.
What the stamp establishes, and what it does not. It records which rules applied. It does not certify that the article complied with them: no process examines an article against the file and issues a verdict. A reader who wants to judge compliance has the exact text that applied, which is the point of publishing it, and the known-open register records what CFI.co has found wrong in its own published claims.
Every version that has ever been stamped stays published on this page, with its file retrievable at the address named above. A superseded version is not removed: articles are still pointing at it, and removing it would make each of them uncheckable.
Further reading
A Letter from the Publisher: Rules That Can Be Checked — the publisher’s account of why these rules exist, what they commit CFI.co to, and why a rule that cannot be checked is not a rule. The letter carries the SHA-256 of the governance file above in its machine-readable metadata, so the letter and this page corroborate each other rather than each asserting its own version of events.
What CFI.co has found wrong in its own published claims
The known-open register records defects CFI.co has found in what it publishes, including eight added on the day this file was adopted. One of them concerns a claim made in the governance repository itself.
5 August 2026: the extract from the governance file added at the head of this page. No change to the file, its hashes, or its adoption record.










































































