Verification
Is this really NiteOwl?
Every release is signed with an offline key. Compare the fingerprint below with the copies published outside this site before you trust it.
| File | Result |
|---|
Loading…
Where the fingerprint is published
Why the check on this page isn't enough on its own
This page is delivered by the same server it is checking. It catches injected or altered code, CDN rewrites and stale deploys. A fully compromised operator, however, could serve a page that reports success. That's why the fingerprint must match the copies published elsewhere, and why you can check a deployment from your own computer:
git clone <the NiteOwl repository> && cd niteowl npm ci npm run verify:remote -- <this site> --fingerprint "six fingerprint words"
The script downloads the signed manifest, checks the signature against the fingerprint you supply, hashes every file the site serves, and checks the security headers. It exits with an error on any mismatch, so it can also run on a schedule as a public tamper alarm.
What NiteOwl can't protect
Whoever reads a message can copy or photograph it. Cloudflare, which runs this service, sees network metadata such as IP addresses and timing — use Tor Browser if that matters to you. Your own device must not be compromised or managed by your employer.