Vealth · Security and proof
Do not accept a green badge. Run the check.
This program exposes evidence you can inspect with your own browser or your own AI. It does not certify this site, identify the people behind a key, or make an irreversible action safe. Every claim below carries the check that tests it, and the last section names what none of them prove.
Live posture, read by your browser
Press the button and your browser reads this site's transport and header posture right now: strict transport security, the content security policy, sniffing and framing protections, and whether the published disclosure contact is current. Each row is one named property of the response as your network saw it. A row your browser cannot finish says so; a quiet server stays neutral, not green.
Honest scope: headers prove configuration at this moment from your network position. They do not prove this site is honest, competent, or safe to send money to. The checker fetches only this origin's own / and /.well-known/security.txt, follows no redirects, and can never be pointed at somebody else's site.
Browser safety checks
The visitor-run safety page fetches its named evidence in your browser: the settlement contract on Base, the anchor record, and a domain binding signed by the key the contract's owner() returns, so even a byte-for-byte copy of that page served from a lookalike domain goes red. A response can support one named claim; what your browser cannot finish is shown as unfinished, never as a pass.
Safety card
Read EcoWealth's machine-readable safety card, then run npx tsx scripts/safety-card/check-safety-card.ts --from-html apps/web/public/vealth/is-this-safe.html --as-served-from vealth.net. It checks structure and domain binding; it cannot prove legal identity or that a key is uncompromised. The format is a public spec with a blank template, so any other site can publish its own card and anyone can validate it: a card supplies claims and checks, and a card that asserts a verdict is invalid by construction.
Proof ledger
Verify a priority proof yourself. A matching hash shows that particular bytes were committed before the recorded anchor; it does not prove the bytes are true, complete, or authored by a particular person. Anchoring is free and verification is never paywalled, as a matter of house law.
Security contact
Read security.txt. It publishes a contact and policy location; it is not an audit, warranty, or response-time promise.
The same laws, pointed at places
This program is the digital side of one family. The other side is the Vealth Standard, where a place holds a Standing computed only from settled work with accepted proof, recomputed on every read and lapsing when the work stops. Same laws both ways: the receipt is the certificate, nothing asserts a verdict a visitor cannot recompute, and digital provisioning is the maintenance loop that keeps an estate alive under them.
What none of this proves
Stated on the face of the program, because a seal that implies more is worse than no seal: none of this stops anyone clicking a bad link. The domain binding proves the holder of a key named this domain, not who the holder is, and not that the key was never stolen. An anchored hash proves bytes existed by a date, not that they are true. Passing posture headers prove configuration, not intent. There is no legal-entity attestation anywhere on this site. If a page here ever claims otherwise, that page is wrong and this one wins.
Run the safety checks · Open the proof ledger · The Vealth Standard