Network status.
A convenience, not a source of truth. The network’s honesty does not depend on this page.
Live status
[CONFIRM: embed the live status feed, or link the status subdomain. A status page that is not actually wired to monitoring is worse than no status page, because people stop checking anything else.]
What we publish when something breaks
- That it broke, while it is still broken. Not after it is fixed, and not after we have worked out how it reads.
- What was affected, specifically. Which capability, which window, and whether settled transactions were touched.
- A timeline with real timestamps. When it started, when we noticed, when we said something. The gap between the second and third is the number that matters, so we publish it.
- What we changed. Including when the honest answer is that we have not fixed the underlying cause yet.
- Incidents nobody noticed. If it met the threshold, it gets published whether or not anyone complained.
The part that matters
You do not have to trust this page.
Every attestation the network has issued verifies independently, with no account and no permission from us. If this page said everything was fine and it was not, the proofs would still tell you the truth.
That is the whole design. A status page is us reporting on ourselves, and self-reporting is exactly the thing the rest of this infrastructure exists to make unnecessary.
Get told
[CONFIRM: incident subscription — feed, email list or webhook. Agents should be able to subscribe programmatically, not only people.]