The Key That Signed Without You — Prove Nothing on Your Machine Borrows Your SSH Identity
🤝 Want this built for you? Start a request — our AI scopes it, estimates a price range, and matches you with a vetted AI Advisor. →
🔒 Ambassador-exclusive build
Two ways to open it
Unlocks this full walkthrough on your account — no subscription, and no account needed until you check out. Advisor-grade build.
Every Ambassador-exclusive build, first access to new ones, and your spot on the advisor-only needs board. Or $300/year.
Become an Advisor to unlock →Already an Advisor? Sign in to open it.
What you'll do
A four-subcommand tool you own that reports which private keys on your workstation are genuinely encrypted at rest without ever decrypting one, which identities your live agent will use with no human in the loop, and what OpenSSH will really do per host according to `ssh -G` rather than according to your config file — plus a declared policy file it checks against, a three-state exit contract that refuses to report "clean" when it could not establish the facts, confirmation and lifetime controls installed on your real keys, and four completed drills in which you watched a passphrase-protected key sign a canary with no prompt, watched a wildcard config block silently overrule an explicit per-host setting, watched the same signing attempt be refused after you installed the control, and watched the report exit non-zero rather than bless a machine it could not read.