The text can be checked
Changing the signed statement breaks verification. Future canaries should verify against the same published public key.
Transparency
A dated statement about government demands for ReverseRef case information. The plain-text statement is signed so anyone can check that it came from the same operator and has not been altered.
Signed statement
ReverseRef Warrant Canary Affirmed: 2026-09-24 Next scheduled review: 2026-12-15 Canonical page: https://reverseref.com/canary As of the affirmation date: 1. ReverseRef has received no subpoena, warrant, court order, National Security Letter, FISA order, or other compulsory government demand for candidate, participant, or case information. 2. ReverseRef has received no such demand accompanied by a nondisclosure or gag requirement. 3. ReverseRef has not disclosed candidate, participant, or case information to a government or law enforcement authority. 4. ReverseRef has not been required to provide bulk or ongoing access, install surveillance capability, create a backdoor, or weaken its privacy or security safeguards. Scope and limits This statement covers the ReverseRef operator and the ReverseRef service. It does not cover a service provider's independent legal obligations or actions that ReverseRef does not know about. If a statement can no longer truthfully be made, ReverseRef intends to remove or revise it when legally permitted. A missing, changed, or overdue update may have explanations other than a government demand. This canary is a transparency signal, not a legal guarantee. This file is signed with the ReverseRef Minisign key published at: https://reverseref.com/canary.pub
Independent verification
Download the statement, signature, and public key into the same folder. With Minisign installed, run:
minisign -Vm canary.txt -p canary.pubMinisign is available through most package managers, for example brew install minisign, apt install minisign, or winget install minisign.
The current public key ID is CF1A7EE8A78F48F4. The same key is pinned in a DNS TXT record controlled separately from the website deployment.
dig +short TXT _canary.reverseref.comThe DNS result should contain the same key ID and public key as canary.pub. This makes replacement through a website-only compromise easier to detect. It does not protect against compromise of both the website and DNS account.
What to compare
The public key in canary.pub:
RWT0SI+n6H4az2MpZZX5NPP3c6ODoMZsZTmzEM9l7VTBPiorFuJZq+xzThe DNS record should read:
v=minisign1; id=CF1A7EE8A78F48F4; key=RWT0SI+n6H4az2MpZZX5NPP3c6ODoMZsZTmzEM9l7VTBPiorFuJZq+xzBoth values are shown here for convenience. Compare them with what DNS actually returns rather than trusting this page alone.
A successful check confirms that the statement matches the signed file and was signed by the holder of the corresponding private key. It does not independently prove that each statement is true.
Quick integrity check
If you can’t install Minisign, a checksum still tells you whether your copy of the statement matches the one published here. It doesn’t prove who wrote it; only the signature does that.
shasum -a 256 canary.txtThe SHA-256 of the current canary.txt, computed when this page was built:
3404ac3e9523d89a43e7b1e7523d977964b3e1529e858f3afb038900c603db82What the signature adds
Changing the signed statement breaks verification. Future canaries should verify against the same published public key.
A signature does not prove the claims, prevent legal restrictions, or explain a late update. The date and wording still need to be assessed directly.