FOR SKEPTICS · AND EVERYONE ELSE

Don’t trust the seal. Check the bytes.

Every claim on this site is checkable. This page is how.

The three layers

  1. The seal. Your stick arrives in a tamper-evident bag. If the seal is broken or looks re-applied — don’t use it, contact us for a replacement. The seal deters casual tampering; it is not the proof.
  2. The hash. The stick’s entire contents can be fingerprinted with SHA-256 and compared against the official fingerprint published below and at koini.io/keystick/verify. If even one byte were altered, the fingerprints would not match. This defeats any tampering — a counterfeit stick, a swapped image, an intercepted shipment — by anyone, anywhere in the supply chain, including us. Publishing the fingerprint reveals nothing about our code: it is a one-way fingerprint, not a blueprint.
  3. The audit. The entropy path — the code that creates your randomness — is reviewed by an independent security firm before we ship, and the attestation is published here. The hash proves your stick is authentically ours; the audit proves ours is sound.

Official release fingerprint

KŌINIkeystick v1.0 · sha256 · PUBLISHED AT LAUNCH
[ RELEASE HASH WILL BE PUBLISHED HERE AND SIGNED — SPECIMEN PAGE ]

To check your stick: on any computer, run a SHA-256 over the stick’s image and compare every character against the published value. Full plain-English instructions for Windows, macOS, and Linux ship on your card and live on this page at launch. Fingerprints are always displayed in full — anyone who shows you a truncated hash is asking you to trust the part you can’t see. Optionally, releases are cryptographically signed so you can confirm the fingerprint itself genuinely came from KŌINI.

Why the code stays closed

KŌINIkeystick is a commercial product, not an open-source project. Keeping the operating system closed means no one can clone it, counterfeit it convincingly, or ship a tampered fork under our name. You don’t need the source to trust the stick — you need proof the stick is genuine and proof the generator is sound, and you have both: the published hash confirms authenticity, the independent audit confirms correctness, the seal confirms it reached you untouched. Guard your stick like the tool it is; if it’s ever lost or the seal is broken, replace it.

READ-ONLY EDITION NOTEThe write-protect switch on the read-only edition ships in the locked position, set after our verification. The switch means no computer can ever alter the stick’s contents — but verify the hash anyway. That’s the whole ethos: check, don’t trust.