OpenSecret, the Rust backend for confidential AI applications such as
Maple, is developed in
MaplePrivacyLabs/Maple under services/opensecret/.
This repository now serves only the signed PCR files that older installed
clients fetch from these fixed URLs:
Each history entry carries an ECDSA P-384 signature over the PCR0 text,
verifiable with the public key pinned in the Maple SDKs. Current SDKs read the
canonical copies under
https://raw.githubusercontent.com/MaplePrivacyLabs/Maple/master/services/opensecret/;
both locations publish identical bytes from one reviewed Maple commit.
- How clients verify enclave attestation against these files: PCR verification.
- Offline validation of the four files, every signature, and history
preservation:
scripts/pcr_compatibility.py check .from the Maple backend component. The workflow in this repository runs it on every change.
Approvals are built, signed and merged in Maple first, then copied here byte-for-byte with the compatibility procedure. Never sign or regenerate files here. Keep this repository public, writable and unarchived; do not rename, transfer or rewrite its history. There is no sunset date for these URLs.
The retired backend source, documentation and tooling remain in this repository's git history before the retirement commit. Nothing here is a development or deployment entrypoint.