Skip to content

A shared link says what we sell, and names the company behind it - #334

Merged
Apolloccrypt merged 1 commit into
mainfrom
feat/fe-meta
Sep 2, 2026
Merged

A shared link says what we sell, and names the company behind it#334
Apolloccrypt merged 1 commit into
mainfrom
feat/fe-meta

Conversation

@Apolloccrypt

@Apolloccrypt Apolloccrypt commented Sep 2, 2026

Copy link
Copy Markdown
Owner

Head elements only, on 50 of the 60 frontend pages: <title>, meta description, Open Graph, Twitter cards and JSON-LD. No body text, no styling. apply-nav.py and js/nav-auth.js are untouched, and a machine check over all 50 changed HTML files reports 0 diff hunks after </head> in either the old or the new version of the file.

Rebased on main

Squashed onto origin/main (d946752). Main moved a long way while this was open: #328 (homepage head rewritten), #325 (/parasign exists), #331 (docs/brand/messaging.md, and it is now the authority for titles and descriptions), #338, #340, #341, #342, #352, #332, #353, #337 and #333. The diff against main is 52 files: 50 HTML heads, the generator that writes them, and the test that gates them.

Two conflicts, frontend/index.html and frontend/pricing.html, both in the head. Resolved the same way each time: main wins where main already writes to the guide, this branch adds what main does not have.

  • /index keeps main's title, main's description sentence, main's SoftwareApplication node ("ParaSign by Paramant", BusinessApplication, Community at EUR 0) and main's Organization description ("Dutch company, servers in Germany"). This branch adds the founder, the address, the KvK identifier and the contact address to that Organization node, on every public page rather than on the homepage only, and adds one clause to the description (below).
  • /pricing had no head work on main at all, so the head comes from this branch, rewritten against the guide.

docs/brand/messaging.md is on main now, so the earlier round's dead source reference is a live one. The head texts follow the guide, not the current body: three of these pages have a body rewrite open in another PR.

One drift fixed. python3 bron-seo/apply_seo_head.py --check on plain origin/main reports would change: 1 pages, because #328 hand-edited the homepage JSON-LD block the generator owns. Left alone, the next run of the generator would have silently reverted it. The generator now carries that shape (SOFTWARE_OVERRIDES) and keeps the middot instead of flattening it to a hyphen, so the JSON-LD name is the title character for character. On this branch: would change: 0 pages.

What the review asked for

1. Who is behind it, in the text a human actually sees. The founder and the legal entity were in the JSON-LD, which no preview in WhatsApp, LinkedIn, Signal or iMessage renders. og:description is pinned to the meta description by the consistency gate, so it had to go in the description itself.

The legal entity is now in the description of all three pages that sell on who is behind it. The founder's name is in one of them, /about, because that is the page whose own sentence backs it; on / and /pricing he stays in the Organization node, where the same three fields are now present on every public page.

page what the description now names
/ "Built and hosted in the EU by Paramantis Solutions B.V." — entity
/about "Paramant is a product of Paramantis Solutions B.V. in Harderwijk, founded by Mick Beer, privacy and security researcher." — entity, town and founder
/pricing "From Paramantis Solutions B.V." — entity

2. No jargon in a description, and no product name assumed known in its first sentence. /verify said "ML-DSA-65 (FIPS 204)" and now says what you get out of it; /sign said the key never reaches "the relay" and now says it stays on your device. "relay", "envelope", .prmnt, ML-DSA, ML-KEM, FIPS, AES-n and "open-core" are out of every title and out of the first sentence of every description, except on the four pages whose subject is the architecture. Every description opens with the action, never with ParaSign or ParaSend.

TOTP is out of the first sentence of /help, /help/api-key-vs-totp, /help/lost-authenticator and /help/session-issues; they say "a code from your authenticator app", which is what those articles call it themselves. It is not added to the INTERNAL list: TOTP is RFC 6238 and the word every authenticator app prints, so it is the reader's vocabulary rather than ours, and putting it on the list would force a rename of a page whose own H1 and URL slug are API key vs TOTP while #333 is rewriting that body.

3. A title that promises no more than the page delivers. The old homepage title was "Sign and send without a US server". /security lists third-party services and the guide is explicit (section 4, proof 1) that the claim is about the data path and that Resend is the named exception. The title is now main's: "sign and send documents in the EU", which the rules grid backs word for word ("Hetzner Germany, Bunny DNS (Slovenia). No US provider in the data path. Email goes out via Resend"). No head element on any page carries an unqualified no-US claim.

4. The free plan is Community in the head too. /signup said "ParaSign Free gives 2 signatures a month"; /pricing said "Free stays free". Both now say Community, which is what tests/ui-truthfulness.test.mjs requires of the body and what the guide fixes as the name.

5. /trust said three different things at once. <title> and <h1> said "Trust & Verification" while og:title, twitter:title and the JSON-LD WebPage name said "Trust & Transparency". No test compared a title with its JSON-LD. One does now, and all four agree.

6. /parashare is byte-identical to main. It is in the PRIVATE set of both bron-seo/apply_seo_head.py and tests/seo-contract.test.mjs, so both content gates skip it: git diff origin/main -- frontend/parashare.html is empty and the page carries no Organization node.

7. No em-dashes, no PARAMANT in caps. Swept over <title>, description, og:* and twitter:* on all 60 pages, private and redirect pages included: 0 violations.

8. The sentences are pinned now. Previous round's gate pinned <title>, og:title and twitter:title to each other, so setting all three to "Paramant is ISO 27001 certified and free forever" passed. Eight pages now have their title and description pinned word for word, with the source of every claim named in the file.

Sabotage, run on this commit:

change result
<title> on / to "Paramant, the fastest signing tool in Europe", og:title and twitter:title and the JSON-LD name pulled along with it not ok 12 - the pages that carry the offer say exactly what they are pinned to say
JSON-LD WebPage.name on /trust to "Trust & Transparency", title and cards left alone not ok 10 - the title, Open Graph, Twitter cards and JSON-LD say the same thing
baseline, both reverted 14 pass, 0 fail

Head values, and where each claim comes from

Every claim below is printed on the page it appears on, unless a different file is named.

page title description source of the claims
/ ParaSign by Paramant · sign and send documents in the EU Get documents signed and send files safely, straight from your browser. Built and hosted in the EU by Paramantis Solutions B.V. The Community plan is free, forever. H1 and lede on index.html ("Get documents signed and send files safely, from your browser", "Everything runs on servers in Germany"); rules grid "EU soil, EU law: Hetzner Germany, Bunny DNS (Slovenia). No US provider in the data path"; footer entity from apply-nav.py; "The Community plan is free, forever" from pricing.html
/about About Paramant · Founded by Mick Beer Paramant is a product of Paramantis Solutions B.V. in Harderwijk, founded by Mick Beer, privacy and security researcher. Company, mission, and how to check us. about.html "founded by Mick Beer, privacy and security researcher"; footer entity and town from apply-nav.py
/pricing Pricing · What is free, and what businesses pay · Paramant The Community plan is free, forever. Organisations pay for higher limits: sending from 15 euro a month, signing from 49, excl. btw. From Paramantis Solutions B.V. pricing.html: "The Community plan is free, forever"; the ParaSend Pro card at EUR 15/mo and the ParaSign Pro card at EUR 49/month, named per product because an unsplit "from 15 euro" reads as if signing starts there; the page-wide "excl. btw" basis
/parasign ParaSign · get documents signed, by Paramant Send a document out for signature and get a receipt anyone can check, from your browser. Free on the Community plan, business plans for firms that sign more. parasign.html (#325): the signing flow, the public verification log, and the Community/Pro/Business split
/sign Sign a PDF in your browser · Paramant Sign a PDF in your browser. The document text and your signing key never leave it, and anyone can check the finished document afterwards. sign.html:391 "the file and your private key stay in this browser, and the relay only ever sees a hash"; sign.html:412 "Private key stays on your device"; sign.html:686 the downloads verify offline. "the document text", not "the file": sign.html:514 says "Paramant delivers the encrypted document with the request" and :708 that it opens in the recipient's browser, so in Request signatures the encrypted file does leave. Plaintext and key stay local in all three modes
/verify Check whether a signed document was changed · Paramant Check whether a signed document was changed after it was signed. It happens in your browser, without an account and without uploading the file. verify.html: in-browser verification, no account, nothing uploaded
/vault Lock a file with a passphrase · Paramant Lock any file with a passphrase before you store or share it. Everything happens on this device; the file and the passphrase never leave your browser. vault.html: the file and the passphrase never leave the browser
/signup Create a free Paramant account Create a Paramant account. ParaSign Community gives 2 signatures a month, unlimited receiving and full post-quantum crypto, forever. No card required. the ParaSign Community card on pricing.html: "2 signatures per month", "unlimited receiving", "Forever · no card required"
/download Download the Paramant desktop app The Paramant desktop app. The current build is from March 2026 and misses 21 protections the web app has, so the web app is the one we recommend. the banner on download.html: "last built in March 2026 and is missing 21 protections the web app has ... Use paramant.app until the native app is rebuilt"
/security Security · How to check Paramant Servers at Hetzner in Nuremberg, Germany, under EU and German law. Post-quantum cryptography, nothing kept on disk, and a disclosure policy you can read. the jurisdiction table on security.html (Hetzner Nuremberg, EU/Germany GDPR) and its disclosure section
/trust Trust and verification · Paramant What Paramant can see on your own server, what it can do, and how you check both yourself. Every claim on the page is tagged live or planned. trust.html: the self-hosting section and the LIVE/PLANNED tags on the page
/status System status · Paramant Live status of the Paramant network. Uptime is calculated from the last 24 hours of checks and the page refreshes every 30 seconds. status.html visible line: "Auto-refreshes every 30s · uptime % calculated from last 24h of checks"
/sla Service level agreement · Paramant Uptime commitments, downtime credits and support response times for every Paramant plan, from Community to Enterprise. the plan table on sla.html, which runs Community to Enterprise
/pararules ParaRules · What Paramant stands for The rules Paramant holds itself to: zero third-party requests, EU sovereignty, post-quantum by default, you own your keys, honest by design. the five rule headings on pararules.html
/privacy Privacy policy · Paramant What Paramant stores and what it does not. An email address to run your account, no phone number, no IP logging for analytics. EU and German hosting. privacy.html: the stored-data list and the IP retention section
/terms Terms of service · Paramant The agreement between you and Paramantis Solutions B.V. for the use of Paramant. Plans, payment, cancellation, acceptable use, liability and Dutch law. the section headings of terms.html; entity from apply-nav.py
/dpa Data processing agreement · Paramant The GDPR Article 28 agreement between Paramantis Solutions B.V. as processor and your organisation as controller. Sign it electronically, EU and German law. dpa.html, which is an Article 28 processor agreement
/license License · Paramant Business Source License 1.1 Paramant is source-available under the Business Source License 1.1. Free for personal use, and it converts to MIT on 2030-01-01. license.html: BSL 1.1 and Change Date 2030-01-01
/docs Documentation · Paramant API and self-hosting API reference, SDK guide, self-hosting and compliance docs for Paramant v3.0.0. Your IT can check everything here. The relay never holds a decryption key. the description is #333's own, taken over unchanged because that PR owns the page; the title replaces main's PARAMANT · Documentation
/changelog Changelog · Paramant release history Transparent Paramant release history. What changed, when, and why. Security-relevant items are always listed. changelog.html and its security-relevant marker
/ct-log Certificate transparency log · Paramant Every public key registration is appended to a tamper-evident Merkle tree. Anyone can verify that a device was registered, without seeing the payload. ct-log.html: the Merkle tree description
/crypto-agility Crypto agility · Paramant Algorithms you can swap without rebuilding. Identifiers travel in the header, not in the code path. NIST FIPS 203, 204, 205 and 206 loaded in production. crypto-agility.html, the algorithm table (technical page, exempt from the internal-vocabulary gate)
/architecture Architecture · How Paramant works A plain-language walkthrough: how your file is encrypted in the browser, how it travels, why the relay cannot read it, and what happens when a link opens. architecture.html (technical page, exempt from the internal-vocabulary gate)
/docs/paramant-ot-brief Industrial OT brief · Paramant The problem with OT and IT data transfer is architectural, not operational. A RAM-only relay for the DMZ zone boundary. No VPN, no persistent storage. the OT brief itself (technical page, exempt)
/audit-log-export Send audit logs to a regulator without a second leak · Paramant Deliver GDPR Article 30 evidence to a supervisory authority or an auditor without a second exposure. The file is destroyed after the first read. audit-log-export.html: Article 30 and burn-on-read
/partners In the wild · Paramant Organisations that publicly confirm they run Paramant in production will be listed here. For case studies or references, get in touch. partners.html, which lists nobody; the future tense is the correction
/press Press kit · Paramant Paramant press kit: blurbs, key facts, brand assets and a press contact. Post-quantum document signing and encrypted file transfer from the Netherlands. press.html contents
/vs Paramant compared to Zivver, Tresorit and WeTransfer How Paramant compares to Zivver, Tresorit, WeTransfer and SFTP on post-quantum encryption, EU jurisdiction, burn-on-read, and self-hosting. the comparison table on vs.html
/security/acknowledgements Security acknowledgements · Paramant Paramant thanks the researchers who responsibly disclosed security issues. Good-faith research makes Paramant better for everyone. security/acknowledgements.html
/help Help and troubleshooting · Paramant Answers for people who already have a Paramant account: sign-in codes, authenticator setup, backup codes, session problems, and the Gmail and Outlook extensions. the article list on help/index.html, which names authenticator setup, backup codes, "session expired, clock drift" and the two extensions
/help/api-key-vs-totp API key vs TOTP · Paramant Help When to use a Paramant API key and when to use a code from your authenticator app, and how the two work together on one account. the article: "When you need just the API key", "When you need both", and its own use of "authenticator app"
/help/authenticator-apps Authenticator apps · Paramant Help Every standard authenticator app works with Paramant, including Google Authenticator. For the strongest setup, use a SHA-256 app such as Authy or 1Password. the article: "a SHA-256 app such as Authy or 1Password"
/help/authenticator-setup Set up your authenticator · Paramant Help How to set up your authenticator app for Paramant. About 3 minutes. Any standard authenticator app works, including Google Authenticator. the article: "about 3 minutes"
/help/backup-codes Backup codes · Paramant Help How to generate, store and use Paramant backup codes. Emergency access when you lose your authenticator app. the article itself
/help/gmail-extension Gmail extension · Paramant Help Install and configure the Paramant Chrome extension for sending encrypted attachments from Gmail. the article itself
/help/iot-integration IoT and embedded devices · Paramant Help Using the Paramant API on constrained devices: Pi Zero, ESP32, OT gateways. Static API key, no TOTP required. the article: Pi Zero, ESP32, static API key
/help/lost-authenticator Lost authenticator access · Paramant Help How to get back into your Paramant account after losing your authenticator app. Backup codes, support recovery, and re-enrollment. the article: backup codes, support recovery and re-enrollment are its three sections
/help/outlook-extension Outlook add-in · Paramant Help Set up the Paramant Outlook add-in for Microsoft 365 and Exchange. Send encrypted attachments from within Outlook. the article itself
/help/session-issues Session and login issues · Paramant Help Fix a sign-in code your account rejects, a session that expires too soon, and clock drift. The most common Paramant login problems, with the fix for each. the article: rejected code, "session expiry", "clock drift"

All titles under 65 characters, all descriptions between 50 and 165, og:* and twitter:* identical to the title and the description on all 39 public pages, and the founder and the legal name in the Organization node of every one.

Head re-check needed after these land

The head texts follow docs/brand/messaging.md, not the current body, so five open PRs rewrite bodies under a head that is already written for the new text. Each still deserves a look at the head after it merges, because a description that quotes a page has to keep quoting it:

PR pages what to re-check
#339 /parasign, /parasend, /sign /parasend does not exist yet: a new page needs a title, a description and a sitemap entry, and the three gates apply to it the moment the file lands. /parasign and /sign descriptions quote the signing flow.
#335 /about, /security, /trust /about and /trust are pinned word for word here; /security's description quotes the jurisdiction table, which #335 moves up the page. If the sentence changes on the page, the pin must change in the same commit.
#336 /pricing, /signup both pinned here, both quoting pricing.html. If a tier price or the Community wording moves, PINNED fails first, which is the intent.
#337 auth pages Landed. Its titles won the rebase on /auth/backup, /auth/request-reset and /signup/verified; those pages are noindex and have no description contract, so only the em-dash and caps sweep applies, and it is clean.
#333 /docs, /help Landed. Its /docs description won the rebase ("compliance docs for Paramant v3.0.0 ... The relay never holds a decryption key"); this branch keeps the title, because main's og:title there was still PARAMANT · Documentation. On the three /help pages main's head was still the untouched caps version, so this branch's head stands.

Also still open and not closed by this PR, because they are body work: the first screen of /pricing at 390px carries no amount, the homepage H1 does not repeat the title, and and /security's jurisdiction table still carries the unqualified "no US company" row that the guide's section 9 names as an open contradiction (#332 has since closed section 9's third point by putting the give-back sentence on /about). None of them is promoted by any head element in this branch.

Green

seo-contract 14 pass, ui-truthfulness, site-claims, links, frontend-loading-contract (33 pass, 0 fail, 2 skipped for a missing live server), scripts/check-csp-inline.sh, scripts/check-cache-bust.sh, npx eslint . exit 0, python3 bron-seo/apply_seo_head.py --check = would change: 0 pages.

tests/static-sanity.sh: PASS, all ten checks clear, check 10 (commit-style guard) included. No trailer on the commit.

Apolloccrypt added a commit that referenced this pull request Sep 2, 2026
…does

Review of #334 found the head elements were consistent but not honest, and
not pinned. Eleven points, all inside <head>.

Who is behind it, visible to people
The founder and the legal entity were in the JSON-LD only, which no preview
in WhatsApp, LinkedIn or iMessage renders. The meta description, og:description
and twitter:description of /index and /about now carry the same sentence the
footer and /about already print: a product of Paramantis Solutions B.V. in
Harderwijk, founded by Mick Beer, privacy and security researcher.

Preview text a buyer can read
Algorithm names and internal words are out of the sentence a search result
shows. /verify no longer opens with ML-DSA-65 (FIPS 204) but with what the
page does. The same for /sign, /index, /vault, /download, /pricing, /trust,
/audit-log-export, /status, /sla and /co-sign. The word "relay" is ours, not
the reader's, so it is out of every title and out of every first sentence
except on the four pages whose subject is the architecture itself. The names
stay on the pages, where there is room to explain them.

A title the page keeps
"Sign and send without a US server" was the clearest sentence on the site and
appeared nowhere on the page, and it promoted a claim /security contradicts:
Cloudflare is on the third-party list there. The title is now "Sign and send
documents under EU law", which is what rule 04 on the homepage says and what
/security backs.

Prices in the pricing description
/pricing promised "organisations pay for higher limits" and named no amount.
It now names ParaSend Pro at 15 euro a month and ParaSign Pro at 49, excl.
VAT, the figures on the page. The first sentence is the free plan, which is
the point of the plan structure. The first screen of the page itself is body
work and out of scope here.

Product names after the verb
/index and /pricing opened with ParaSign and ParaSend as if the reader knew
them. Both now open with the action.

Three gates, because consistency is not truth
The gate added earlier pins title, og:title and twitter:title to each other,
which the sentence "Paramant is ISO 27001 certified and free forever" passed
on all three. Added:
- the sentences of /index, /pricing and /about are pinned word for word
- no title or description may claim a certification, an accreditation, a
  qualified signature or a 100% guarantee, none of which the site backs
- the title and the first sentence of the description stay free of ML-DSA,
  ML-KEM, FIPS, .prmnt, AES-n, envelope, open-core and relay, except on
  /architecture, /crypto-agility, /ct-log and the OT brief

Loose ends from the review
- the test comment no longer cites docs/brand/messaging.md, which is still an
  open PR and not in the repo
- /parashare is private in both PRIVATE sets, so its head is back to what main
  has: a gated page should not carry an ungated head change
- admin, account and iot carried "PARAMANT" and an em-dash in og and twitter
  tags; they are private, but the claim that both are gone from every head is
  now true
- merged origin/main, so /parasign from #325 is covered by the new gates

Green: seo-contract (14), links, ui-truthfulness, site-claims, navigation-shell,
frontend-loading-contract, frontend-module-scripts, pricing-page, the full root
integration set (123), check-csp-inline, check-cache-bust, eslint.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XJk2nCLCLmi3F71qkCUn7N
@Apolloccrypt Apolloccrypt changed the title A shared link now says what we sell, and who is behind it The preview text says what we sell, and names the man behind it Sep 2, 2026
@Apolloccrypt
Apolloccrypt force-pushed the feat/fe-meta branch 2 times, most recently from 4f8476c to a82f611 Compare September 2, 2026 17:48
@Apolloccrypt Apolloccrypt changed the title The preview text says what we sell, and names the man behind it A shared link says what we sell, who is behind it, and nothing else Sep 2, 2026
@Apolloccrypt
Apolloccrypt force-pushed the feat/fe-meta branch 2 times, most recently from ca52f4d to 586e9b9 Compare September 2, 2026 18:05
@Apolloccrypt Apolloccrypt changed the title A shared link says what we sell, who is behind it, and nothing else A shared link says what we sell, and names the company behind it Sep 2, 2026
@Apolloccrypt Apolloccrypt reopened this Sep 2, 2026
@Apolloccrypt
Apolloccrypt force-pushed the feat/fe-meta branch 3 times, most recently from f2ae7c7 to e98f122 Compare September 2, 2026 18:11
Head elements only: title, meta description, Open Graph, Twitter cards and
JSON-LD on 50 of the 60 frontend pages. No body text, no styling. apply-nav.py
and js/nav-auth.js are untouched, and no diff hunk in any of the 50 files falls
after </head>.

Rebased on main. Main's wording wins in every head it already writes to the
messaging guide (#331): the homepage keeps the title, the description sentence
and the SoftwareApplication node #328 gave it, and the Organization description
keeps "Dutch company, servers in Germany". This branch adds what main does not
have: the founder, the legal entity, the address and the KvK number in the
Organization node of every public page, and Open Graph and Twitter cards that
match the title.

The legal entity is now in the description itself on /, /about and /pricing,
not only in the JSON-LD no preview renders. The founder's name is in one
description, /about, because that is the only one of the three where /about's
own sentence backs it; on / and /pricing the description names Paramantis
Solutions B.V. and the founder stays in the Organization node.

Jargon is out of the sentence a buyer reads first. /verify says what it gets
you instead of naming FIPS 204, and "relay" is gone from every title and every
opening sentence except the four pages whose subject is the architecture.

/sign says "the document text and your signing key never leave it", not "the
file". In Request signatures the encrypted document does go to Paramant, which
is how a recipient receives it. The plaintext and the key stay in the browser
in all three modes; the file does not.

/pricing names a floor per product, sending from 15 euro a month and signing
from 49. An unsplit "from 15 euro" reads as if signing starts there.

The free plan is called Community in the head as well, on /pricing and /signup.

Three gates in tests/seo-contract.test.mjs:
- title, og:title, twitter:title and the JSON-LD WebPage name are one sentence.
  /trust shipped three different names at once and nothing failed.
- eight pages have their title and description pinned word for word, with the
  source of every claim named in the file.
- no title or description carries a certification we do not hold, and none
  carries our own vocabulary.

bron-seo/apply_seo_head.py reproduces every generated block exactly:
"would change: 0 pages". Main drifted by one page before this commit, because
carries that shape instead.
@Apolloccrypt
Apolloccrypt merged commit 2276d93 into main Sep 2, 2026
10 checks passed
Apolloccrypt added a commit that referenced this pull request Sep 2, 2026
#334 tightened the head contract: the JSON-LD WebPage name has to be the page
title character for character, and every public page has to carry an
Organization node naming the company and the founder. /parasend was written
before that landed, so on the merged result tests/seo-contract.test.mjs failed
twice: the WebPage name used a hyphen where the title uses a middot, and there
was no Organization node at all.

The block comes from bron-seo/apply_seo_head.py, not from hand editing, so it
is the same graph the other 39 pages carry and it stays that way the next time
the script runs. `--check` is clean afterwards.

Found by rebasing on main and running the suite against the merged tree. A
green run on the branch head only describes the branch head, which is how this
would have reached main red.
Apolloccrypt added a commit that referenced this pull request Sep 2, 2026
The three pages a buyer reaches after the homepage were written for someone
who already believes the product. /about opened on the mission and put the
founder in section 03, below the cryptography. /security opened on defence in
depth and kept the one row a buyer came for, the jurisdiction table, seven
screens down. /trust never said who it was for.

They now run the order docs/brand/messaging.md fixes: what this is, who it is
for, who is behind it, a next step, then the proof including the honest
limits. Copy, hierarchy and order only. No restyle. index.html, apply-nav.py
and js/nav-auth.js are untouched.

/about is the founder page.

  The lede is plain language: sign and send documents so only you and the
  recipient can read them, so anyone can check later that the document is
  genuine, on servers in Germany under EU law. Under it, in the first phone
  screen, who it is for, then Mick Beer with the title the guide fixes, then
  two buttons. Measured at 390x844: the founder sits at y=463 and the second
  button at y=608. The section number "00" is hidden in the mobile override
  instead of landing under the H1 as a stray number.

  Two sentences are gone. "The cryptography is post-quantum, which is the
  proof that it still holds up in ten years" was not a proof and not
  checkable, on the page whose argument is that everything on it is
  checkable. The founder paragraph explained the free plan with a
  jurisdiction claim ("should not depend on a US subscription"), which the
  guide forbids beside his name. In its place stands the paragraph #332
  landed on main while this branch was in review: the Community plan is his
  way of giving something back to society, the business plans pay for it,
  that is the whole arrangement, and it is why the Community plan is not a
  trial and has no end date. Taken from main verbatim, moved with the section
  into the top half, and pinned so the two copies cannot drift.

  The tier block names the free plan Community, which is what /pricing prints
  on the card since #328.

/security answers "why would I trust you" before it answers "how it works".

  The promise carries its own scope. It read "even if our own server is
  broken into, nobody can read your documents" flat out, while ten screens
  lower the page says the Chromium and Outlook extensions take a server-side
  encryption path. For an extension user the flat version is untrue today, so
  the exception now travels with the promise, in the hero.

  It also says what that exception costs the reader, in words rather than in
  ours: the extensions encrypt on our server, which means we can read what
  you upload through them until that is changed. "Treat those uploads as
  relay-side" was the internal phrasing, and relay is exactly the word this
  branch removed from the /trust hero. Neither hero uses it now, and a test
  says so.

  The first screen also carries who is behind the page (Paramantis Solutions
  B.V., Harderwijk, KvK 42115132, and the founder line) and the next step.
  The buttons used to sit at roughly y=11400 on a phone; "See pricing" is now
  at y=656 and "Verify a document" at y=716.

  The free plan is Community here too. A first version of this branch left
  "ParaSign Free and ParaSend Free cost EUR 0" standing at r.448, because the
  only check that forbade the old name was scoped to /about. That check now
  covers all three pages, and the sitewide sweep in ui-truthfulness gained the
  shape it was missing, so any page using it fails. The page description no
  longer sells "relay architecture" either.

  The audit block says what /docs#audits actually adds up to: three external
  audits in April 2026, two by R. Zwarts and one by Ryan Williams of Smart
  Cyber Solutions, forty findings, four of them critical, with the resolving
  commits in the table. The previous round claimed "the audit reports
  themselves are not published" and pinned it. That was false:
  docs/security-audit-2026-04.md is the full Smart Cyber Solutions writeup
  and it ships in the site tree. Only the raw pentest output is missing,
  which is what that document itself calls the raw report. Both pages now say
  that, and link the report.

  The CLOUD Act row and the EU-law card move to the data-path wording, as
  section 9.2 of the guide requires: no US provider in the data path, with
  Resend named as the one exception in the same breath. The old row read "not
  applicable: no US infrastructure, no US company", which is broader than
  /privacy allows.

/trust names its reader, then gives that reader somewhere to go.

  The hero addresses organisations running their own relay and anyone
  checking a supplier, and now offers them two buttons instead of one text
  link mid-paragraph (y=416 and y=476). The first sentence under the hero no
  longer says "the operator who runs the relay": relay is not a word a
  supplier reviewer knows.

  The page called itself Trust & Verification in its title and H1 while the
  social card and the structured data still said Trust & Transparency. #334
  then rewrote every head on the site, so the literal strings belong there and
  tests/seo-contract.test.mjs pins them. What this branch pins is the
  relation: the title, og:title, twitter:title and the JSON-LD name must name
  the page the same, and that name must contain the words the H1 uses.
  Punctuation and case are not the point; Transparency versus Verification
  was. Its plan sentence named two of the three paid
  ParaSign tiers; it names all three, and both free tiers as Community.

Tests

  tests/ui-truthfulness.test.mjs pins each of the above, and each one was
  sabotaged in place to confirm it goes red: the ten-year promise, the
  give-back sentence, the US-subscription framing, the Community rename, the
  CLOUD Act row, the Resend exception dropped from the card, the finding
  counts, the "reports not published" sentence, the auditor names on
  /security as well as /trust, the two hero buttons on each page, the
  who-is-behind line, the bounded promise, the /trust og:title and JSON-LD
  name, the jargon in the first screen, and the paid tiers. Twenty-five
  sabotages, twenty-five red, no gaps.

  tests/site-claims.test.mjs block 11 reads the numbers out of the /pricing
  tier card that owns them and requires /about to repeat them; it follows the
  Community rename and now also forbids "ParaSign Free" on /about.

  node --test over the CI glob: 162 pass, 0 fail. check-csp-inline,
  check-cache-bust and eslint exit 0. At 390px all three pages have
  scrollWidth === clientWidth === 390.

Still open, deliberately

  The eIDAS level (SES on /about, advanced (AES) in the /pricing FAQ) is a
  real contradiction and needs a decision, not a copy edit. This branch stops
  it spreading and pins that it stays on the one page that has always carried
  it.
Apolloccrypt added a commit that referenced this pull request Sep 2, 2026
The three pages a buyer reaches after the homepage were written for someone
who already believes the product. /about opened on the mission and put the
founder in section 03, below the cryptography. /security opened on defence in
depth and kept the one row a buyer came for, the jurisdiction table, seven
screens down. /trust never said who it was for.

They now run the order docs/brand/messaging.md fixes: what this is, who it is
for, who is behind it, a next step, then the proof including the honest
limits. Copy, hierarchy and order only. No restyle. index.html, apply-nav.py
and js/nav-auth.js are untouched.

/about is the founder page.

  The lede is plain language: sign and send documents so only you and the
  recipient can read them, so anyone can check later that the document is
  genuine, on servers in Germany under EU law. Under it, in the first phone
  screen, who it is for, then Mick Beer with the title the guide fixes, then
  two buttons. Measured at 390x844: the founder sits at y=463 and the second
  button at y=608. The section number "00" is hidden in the mobile override
  instead of landing under the H1 as a stray number.

  Two sentences are gone. "The cryptography is post-quantum, which is the
  proof that it still holds up in ten years" was not a proof and not
  checkable, on the page whose argument is that everything on it is
  checkable. The founder paragraph explained the free plan with a
  jurisdiction claim ("should not depend on a US subscription"), which the
  guide forbids beside his name. In its place stands the paragraph #332
  landed on main while this branch was in review: the Community plan is his
  way of giving something back to society, the business plans pay for it,
  that is the whole arrangement, and it is why the Community plan is not a
  trial and has no end date. Taken from main verbatim, moved with the section
  into the top half, and pinned so the two copies cannot drift.

  The tier block names the free plan Community, which is what /pricing prints
  on the card since #328.

/security answers "why would I trust you" before it answers "how it works".

  The promise carries its own scope. It read "even if our own server is
  broken into, nobody can read your documents" flat out, while ten screens
  lower the page says the Chromium and Outlook extensions take a server-side
  encryption path. For an extension user the flat version is untrue today, so
  the exception now travels with the promise, in the hero.

  It also says what that exception costs the reader, in words rather than in
  ours: the extensions encrypt on our server, which means we can read what
  you upload through them until that is changed. "Treat those uploads as
  relay-side" was the internal phrasing, and relay is exactly the word this
  branch removed from the /trust hero. Neither hero uses it now, and a test
  says so.

  The first screen also carries who is behind the page (Paramantis Solutions
  B.V., Harderwijk, KvK 42115132, and the founder line) and the next step.
  The buttons used to sit at roughly y=11400 on a phone; "See pricing" is now
  at y=656 and "Verify a document" at y=716.

  The free plan is Community here too. A first version of this branch left
  "ParaSign Free and ParaSend Free cost EUR 0" standing at r.448, because the
  only check that forbade the old name was scoped to /about. That check now
  covers all three pages, and the sitewide sweep in ui-truthfulness gained the
  shape it was missing, so any page using it fails. The page description no
  longer sells "relay architecture" either.

  The audit block says what /docs#audits actually adds up to: three external
  audits in April 2026, two by R. Zwarts and one by Ryan Williams of Smart
  Cyber Solutions, forty findings, four of them critical, with the resolving
  commits in the table. The previous round claimed "the audit reports
  themselves are not published" and pinned it. That was false:
  docs/security-audit-2026-04.md is the full Smart Cyber Solutions writeup
  and it ships in the site tree. Only the raw pentest output is missing,
  which is what that document itself calls the raw report. Both pages now say
  that, and link the report.

  The CLOUD Act row and the EU-law card move to the data-path wording, as
  section 9.2 of the guide requires: no US provider in the data path, with
  Resend named as the one exception in the same breath. The old row read "not
  applicable: no US infrastructure, no US company", which is broader than
  /privacy allows.

/trust names its reader, then gives that reader somewhere to go.

  The hero addresses organisations running their own relay and anyone
  checking a supplier, and now offers them two buttons instead of one text
  link mid-paragraph (y=416 and y=476). The first sentence under the hero no
  longer says "the operator who runs the relay": relay is not a word a
  supplier reviewer knows.

  The page called itself Trust & Verification in its title and H1 while the
  social card and the structured data still said Trust & Transparency. #334
  then rewrote every head on the site, so the literal strings belong there and
  tests/seo-contract.test.mjs pins them. What this branch pins is the
  relation: the title, og:title, twitter:title and the JSON-LD name must name
  the page the same, and that name must contain the words the H1 uses.
  Punctuation and case are not the point; Transparency versus Verification
  was. Its plan sentence named two of the three paid
  ParaSign tiers; it names all three, and both free tiers as Community.

Tests

  tests/ui-truthfulness.test.mjs pins each of the above, and each one was
  sabotaged in place to confirm it goes red: the ten-year promise, the
  give-back sentence, the US-subscription framing, the Community rename, the
  CLOUD Act row, the Resend exception dropped from the card, the finding
  counts, the "reports not published" sentence, the auditor names on
  /security as well as /trust, the two hero buttons on each page, the
  who-is-behind line, the bounded promise, the /trust og:title and JSON-LD
  name, the jargon in the first screen, and the paid tiers. Twenty-six
  sabotages, twenty-six red, no gaps.

  tests/site-claims.test.mjs block 11 reads the numbers out of the /pricing
  tier card that owns them and requires /about to repeat them; it follows the
  Community rename and now also forbids "ParaSign Free" on /about.

  node --test over the CI glob: 162 pass, 0 fail. check-csp-inline,
  check-cache-bust and eslint exit 0. At 390px all three pages have
  scrollWidth === clientWidth === 390.

Two things this branch had to touch on main's side

  tests/ui-truthfulness.test.mjs did not parse on main: #336 and #339 each
  landed a const named pricingVisible in the same module, for two different
  values. The one #339 added is renamed to pricingText, with a comment saying
  why. Without it nothing in this file runs, this branch included.

  tests/site-claims.test.mjs block 12 read the /pricing tier cards by their
  section heading. #336 renamed both headings and put ParaSign first, so the
  split now finds them by product prefix and orders them by position.

  Not touched, and still broken on main: relay/test/pricing-page.test.js r.498
  declares tiers twice, so eslint cannot parse it. It is outside these three
  pages and outside this PR.

Still open, deliberately

  The eIDAS level (SES on /about, advanced (AES) in the /pricing FAQ) is a
  real contradiction and needs a decision, not a copy edit. This branch stops
  it spreading and pins that it stays on the one page that has always carried
  it.
Apolloccrypt added a commit that referenced this pull request Sep 2, 2026
The three pages a buyer reaches after the homepage were written for someone
who already believes the product. /about opened on the mission and put the
founder in section 03, below the cryptography. /security opened on defence in
depth and kept the one row a buyer came for, the jurisdiction table, seven
screens down. /trust never said who it was for.

They now run the order docs/brand/messaging.md fixes: what this is, who it is
for, who is behind it, a next step, then the proof including the honest
limits. Copy, hierarchy and order only. No restyle. index.html, apply-nav.py
and js/nav-auth.js are untouched.

/about is the founder page.

  The lede is plain language: sign and send documents so only you and the
  recipient can read them, so anyone can check later that the document is
  genuine, on servers in Germany under EU law. Under it, in the first phone
  screen, who it is for, then Mick Beer with the title the guide fixes, then
  two buttons. Measured at 390x844: the founder sits at y=463 and the second
  button at y=608. The section number "00" is hidden in the mobile override
  instead of landing under the H1 as a stray number.

  Two sentences are gone. "The cryptography is post-quantum, which is the
  proof that it still holds up in ten years" was not a proof and not
  checkable, on the page whose argument is that everything on it is
  checkable. The founder paragraph explained the free plan with a
  jurisdiction claim ("should not depend on a US subscription"), which the
  guide forbids beside his name. In its place stands the paragraph #332
  landed on main while this branch was in review: the Community plan is his
  way of giving something back to society, the business plans pay for it,
  that is the whole arrangement, and it is why the Community plan is not a
  trial and has no end date. Taken from main verbatim, moved with the section
  into the top half, and pinned so the two copies cannot drift.

  The tier block names the free plan Community, which is what /pricing prints
  on the card since #328.

/security answers "why would I trust you" before it answers "how it works".

  The promise carries its own scope. It read "even if our own server is
  broken into, nobody can read your documents" flat out, while ten screens
  lower the page says the Chromium and Outlook extensions take a server-side
  encryption path. For an extension user the flat version is untrue today, so
  the exception now travels with the promise, in the hero.

  It also says what that exception costs the reader, in words rather than in
  ours: the extensions encrypt on our server, which means we can read what
  you upload through them until that is changed. "Treat those uploads as
  relay-side" was the internal phrasing, and relay is exactly the word this
  branch removed from the /trust hero. Neither hero uses it now, and a test
  says so.

  The first screen also carries who is behind the page (Paramantis Solutions
  B.V., Harderwijk, KvK 42115132, and the founder line) and the next step.
  The buttons used to sit at roughly y=11400 on a phone; "See pricing" is now
  at y=656 and "Verify a document" at y=716.

  The free plan is Community here too. A first version of this branch left
  "ParaSign Free and ParaSend Free cost EUR 0" standing at r.448, because the
  only check that forbade the old name was scoped to /about. That check now
  covers all three pages, and the sitewide sweep in ui-truthfulness gained the
  shape it was missing, so any page using it fails. The page description no
  longer sells "relay architecture" either.

  The audit block says what /docs#audits actually adds up to: three external
  audits in April 2026, two by R. Zwarts and one by Ryan Williams of Smart
  Cyber Solutions, forty findings, four of them critical, with the resolving
  commits in the table. The previous round claimed "the audit reports
  themselves are not published" and pinned it. That was false:
  docs/security-audit-2026-04.md is the full Smart Cyber Solutions writeup
  and it ships in the site tree. Only the raw pentest output is missing,
  which is what that document itself calls the raw report. Both pages now say
  that, and link the report.

  The CLOUD Act row and the EU-law card move to the data-path wording, as
  section 9.2 of the guide requires: no US provider in the data path, with
  Resend named as the one exception in the same breath. The old row read "not
  applicable: no US infrastructure, no US company", which is broader than
  /privacy allows.

/trust names its reader, then gives that reader somewhere to go.

  The hero addresses organisations running their own relay and anyone
  checking a supplier, and now offers them two buttons instead of one text
  link mid-paragraph (y=416 and y=476). The first sentence under the hero no
  longer says "the operator who runs the relay": relay is not a word a
  supplier reviewer knows.

  The page called itself Trust & Verification in its title and H1 while the
  social card and the structured data still said Trust & Transparency. #334
  then rewrote every head on the site, so the literal strings belong there and
  tests/seo-contract.test.mjs pins them. What this branch pins is the
  relation: the title, og:title, twitter:title and the JSON-LD name must name
  the page the same, and that name must contain the words the H1 uses.
  Punctuation and case are not the point; Transparency versus Verification
  was. Its plan sentence named two of the three paid
  ParaSign tiers; it names all three, and both free tiers as Community.

Tests

  tests/ui-truthfulness.test.mjs pins each of the above, and each one was
  sabotaged in place to confirm it goes red: the ten-year promise, the
  give-back sentence, the US-subscription framing, the Community rename, the
  CLOUD Act row, the Resend exception dropped from the card, the finding
  counts, the "reports not published" sentence, the auditor names on
  /security as well as /trust, the two hero buttons on each page, the
  who-is-behind line, the bounded promise, the /trust og:title and JSON-LD
  name, the jargon in the first screen, and the paid tiers. Twenty-six
  sabotages, twenty-six red, no gaps.

  tests/site-claims.test.mjs block 11 reads the numbers out of the /pricing
  tier card that owns them and requires /about to repeat them; it follows the
  Community rename and now also forbids "ParaSign Free" on /about.

  node --test over the CI glob: 162 pass, 0 fail. check-csp-inline,
  check-cache-bust and eslint exit 0. At 390px all three pages have
  scrollWidth === clientWidth === 390.

Three things this branch had to touch on main's side

  tests/ui-truthfulness.test.mjs did not parse on main: #336 and #339 each
  landed a const named pricingVisible in the same module, for two different
  values. The one #339 added is renamed to pricingText, with a comment saying
  why. Without it nothing in this file runs, this branch included.

  tests/site-claims.test.mjs block 12 read the /pricing tier cards by their
  section heading. #336 renamed both headings and put ParaSign first, so the
  split now finds them by product prefix and orders them by position.

  relay/test/pricing-page.test.js r.498 required ../lib/tiers a second time,
  under a name the file already binds at r.18. That is a SyntaxError, and it
  took down two CI checks on every PR: "static, every name must exist" (eslint
  cannot parse the file) and "relay - unit suite". The duplicate line is
  removed; the binding at the top of the file is the same module. This was
  outside the three pages, but no PR can go green while it stands.

Still open, deliberately

  The eIDAS level (SES on /about, advanced (AES) in the /pricing FAQ) is a
  real contradiction and needs a decision, not a copy edit. This branch stops
  it spreading and pins that it stays on the one page that has always carried
  it.
Apolloccrypt added a commit that referenced this pull request Sep 2, 2026
The three pages a buyer reaches after the homepage were written for someone
who already believes the product. /about opened on the mission and put the
founder in section 03, below the cryptography. /security opened on defence in
depth and kept the one row a buyer came for, the jurisdiction table, seven
screens down. /trust never said who it was for.

They now run the order docs/brand/messaging.md fixes: what this is, who it is
for, who is behind it, a next step, then the proof including the honest
limits. Copy, hierarchy and order only. No restyle. index.html, apply-nav.py
and js/nav-auth.js are untouched.

/about is the founder page.

  The lede is plain language: sign and send documents so only you and the
  recipient can read them, so anyone can check later that the document is
  genuine, on servers in Germany under EU law. Under it, in the first phone
  screen, who it is for, then Mick Beer with the title the guide fixes, then
  two buttons. Measured at 390x844: the founder sits at y=463 and the second
  button at y=608. The section number "00" is hidden in the mobile override
  instead of landing under the H1 as a stray number.

  Two sentences are gone. "The cryptography is post-quantum, which is the
  proof that it still holds up in ten years" was not a proof and not
  checkable, on the page whose argument is that everything on it is
  checkable. The founder paragraph explained the free plan with a
  jurisdiction claim ("should not depend on a US subscription"), which the
  guide forbids beside his name. In its place stands the paragraph #332
  landed on main while this branch was in review: the Community plan is his
  way of giving something back to society, the business plans pay for it,
  that is the whole arrangement, and it is why the Community plan is not a
  trial and has no end date. Taken from main verbatim, moved with the section
  into the top half, and pinned so the two copies cannot drift.

  The tier block names the free plan Community, which is what /pricing prints
  on the card since #328.

/security answers "why would I trust you" before it answers "how it works".

  The promise carries its own scope. It read "even if our own server is
  broken into, nobody can read your documents" flat out, while ten screens
  lower the page says the Chromium and Outlook extensions take a server-side
  encryption path. For an extension user the flat version is untrue today, so
  the exception now travels with the promise, in the hero.

  It also says what that exception costs the reader, in words rather than in
  ours: the extensions encrypt on our server, which means we can read what
  you upload through them until that is changed. "Treat those uploads as
  relay-side" was the internal phrasing, and relay is exactly the word this
  branch removed from the /trust hero. Neither hero uses it now, and a test
  says so.

  The first screen also carries who is behind the page (Paramantis Solutions
  B.V., Harderwijk, KvK 42115132, and the founder line) and the next step.
  The buttons used to sit at roughly y=11400 on a phone; "See pricing" is now
  at y=656 and "Verify a document" at y=716.

  The free plan is Community here too. A first version of this branch left
  "ParaSign Free and ParaSend Free cost EUR 0" standing at r.448, because the
  only check that forbade the old name was scoped to /about. That check now
  covers all three pages, and the sitewide sweep in ui-truthfulness gained the
  shape it was missing, so any page using it fails. The page description no
  longer sells "relay architecture" either.

  The audit block says what /docs#audits actually adds up to: three external
  audits in April 2026, two by R. Zwarts and one by Ryan Williams of Smart
  Cyber Solutions, forty findings, four of them critical, with the resolving
  commits in the table. The previous round claimed "the audit reports
  themselves are not published" and pinned it. That was false:
  docs/security-audit-2026-04.md is the full Smart Cyber Solutions writeup
  and it ships in the site tree. Only the raw pentest output is missing,
  which is what that document itself calls the raw report. Both pages now say
  that, and link the report.

  The CLOUD Act row and the EU-law card move to the data-path wording, as
  section 9.2 of the guide requires: no US provider in the data path, with
  Resend named as the one exception in the same breath. The old row read "not
  applicable: no US infrastructure, no US company", which is broader than
  /privacy allows.

/trust names its reader, then gives that reader somewhere to go.

  The hero addresses organisations running their own relay and anyone
  checking a supplier, and now offers them two buttons instead of one text
  link mid-paragraph (y=416 and y=476). The first sentence under the hero no
  longer says "the operator who runs the relay": relay is not a word a
  supplier reviewer knows.

  The page called itself Trust & Verification in its title and H1 while the
  social card and the structured data still said Trust & Transparency. #334
  then rewrote every head on the site, so the literal strings belong there and
  tests/seo-contract.test.mjs pins them. What this branch pins is the
  relation: the title, og:title, twitter:title and the JSON-LD name must name
  the page the same, and that name must contain the words the H1 uses.
  Punctuation and case are not the point; Transparency versus Verification
  was. Its plan sentence named two of the three paid
  ParaSign tiers; it names all three, and both free tiers as Community.

Tests

  tests/ui-truthfulness.test.mjs pins each of the above, and each one was
  sabotaged in place to confirm it goes red: the ten-year promise, the
  give-back sentence, the US-subscription framing, the Community rename, the
  CLOUD Act row, the Resend exception dropped from the card, the finding
  counts, the "reports not published" sentence, the auditor names on
  /security as well as /trust, the two hero buttons on each page, the
  who-is-behind line, the bounded promise, the /trust og:title and JSON-LD
  name, the jargon in the first screen, and the paid tiers. Twenty-seven
  sabotages, twenty-seven red, no gaps.

  tests/site-claims.test.mjs block 11 reads the numbers out of the /pricing
  tier card that owns them and requires /about to repeat them; it follows the
  Community rename and now also forbids "ParaSign Free" on /about.

  node --test over the CI glob: 173 pass, 0 fail. check-csp-inline,
  check-cache-bust and eslint exit 0, bron-seo/apply_seo_head.py --check
  reports 0 pages, and tests/static-sanity.sh is PASS on all eleven checks,
  including #362's new test-scope guard. At 390px all three pages have
  scrollWidth === clientWidth === 390.

Following main through four parallel merges

  #359 landed the deduplication this branch was carrying (the second const
  tiers in relay/test/pricing-page.test.js, and pricingVisible renamed to
  pricingText), so both local fixes are dropped in favour of main's.

  This branch's own block in tests/ui-truthfulness.test.mjs now sits inside a
  bare block scope and declares nothing at module level. Four PRs merged into
  that file in parallel on 2 September and two of them collided on a top-level
  const, which is a SyntaxError: not one assertion in the file runs, on any
  branch. A block that declares nothing at module level cannot do that to the
  next branch.

  tests/site-claims.test.mjs block 12 stopped spelling the units itself. #336
  renamed both /pricing section headings and put ParaSign first, and #359
  reworded "2 signatures per month" to "2 signatures a month". The block now
  finds the headings by product prefix, orders them by position, and lifts each
  fact out of the card as a whole phrase, so /about repeats what /pricing says
  rather than what this file guesses /pricing says. /about follows the new
  wording: "2 signatures a month", "24 hour link expiry", "up to 10 reads per
  link".

Still open, deliberately

  The eIDAS level (SES on /about, advanced (AES) in the /pricing FAQ) is a
  real contradiction and needs a decision, not a copy edit. This branch stops
  it spreading and pins that it stays on the one page that has always carried
  it.
Apolloccrypt added a commit that referenced this pull request Sep 2, 2026
The three pages a buyer reaches after the homepage were written for someone
who already believes the product. /about opened on the mission and put the
founder in section 03, below the cryptography. /security opened on defence in
depth and kept the one row a buyer came for, the jurisdiction table, seven
screens down. /trust never said who it was for.

They now run the order docs/brand/messaging.md fixes: what this is, who it is
for, who is behind it, a next step, then the proof including the honest
limits. Copy, hierarchy and order only. No restyle. index.html, apply-nav.py
and js/nav-auth.js are untouched.

/about is the founder page.

  The lede is plain language: sign and send documents so only you and the
  recipient can read them, so anyone can check later that the document is
  genuine, on servers in Germany under EU law. Under it, in the first phone
  screen, who it is for, then Mick Beer with the title the guide fixes, then
  two buttons. Measured at 390x844: the founder sits at y=463 and the second
  button at y=608. The section number "00" is hidden in the mobile override
  instead of landing under the H1 as a stray number.

  Two sentences are gone. "The cryptography is post-quantum, which is the
  proof that it still holds up in ten years" was not a proof and not
  checkable, on the page whose argument is that everything on it is
  checkable. The founder paragraph explained the free plan with a
  jurisdiction claim ("should not depend on a US subscription"), which the
  guide forbids beside his name. In its place stands the paragraph #332
  landed on main while this branch was in review: the Community plan is his
  way of giving something back to society, the business plans pay for it,
  that is the whole arrangement, and it is why the Community plan is not a
  trial and has no end date. Taken from main verbatim, moved with the section
  into the top half, and pinned so the two copies cannot drift.

  The tier block names the free plan Community, which is what /pricing prints
  on the card since #328.

/security answers "why would I trust you" before it answers "how it works".

  The promise carries its own scope. It read "even if our own server is
  broken into, nobody can read your documents" flat out, while ten screens
  lower the page says the Chromium and Outlook extensions take a server-side
  encryption path. For an extension user the flat version is untrue today, so
  the exception now travels with the promise, in the hero.

  It also says what that exception costs the reader, in words rather than in
  ours: the extensions encrypt on our server, which means we can read what
  you upload through them until that is changed. "Treat those uploads as
  relay-side" was the internal phrasing, and relay is exactly the word this
  branch removed from the /trust hero. Neither hero uses it now, and a test
  says so.

  The first screen also carries who is behind the page (Paramantis Solutions
  B.V., Harderwijk, KvK 42115132, and the founder line) and the next step.
  The buttons used to sit at roughly y=11400 on a phone; "See pricing" is now
  at y=656 and "Verify a document" at y=716.

  The free plan is Community here too. A first version of this branch left
  "ParaSign Free and ParaSend Free cost EUR 0" standing at r.448, because the
  only check that forbade the old name was scoped to /about. That check now
  covers all three pages, and the sitewide sweep in ui-truthfulness gained the
  shape it was missing, so any page using it fails. The page description no
  longer sells "relay architecture" either.

  The audit block says what /docs#audits actually adds up to: three external
  audits in April 2026, two by R. Zwarts and one by Ryan Williams of Smart
  Cyber Solutions, forty findings, four of them critical, with the resolving
  commits in the table. The previous round claimed "the audit reports
  themselves are not published" and pinned it. That was false:
  docs/security-audit-2026-04.md is the full Smart Cyber Solutions writeup
  and it ships in the site tree. Only the raw pentest output is missing,
  which is what that document itself calls the raw report. Both pages now say
  that, and link the report.

  The CLOUD Act row and the EU-law card move to the data-path wording, as
  section 9.2 of the guide requires: no US provider in the data path, with
  Resend named as the one exception in the same breath. The old row read "not
  applicable: no US infrastructure, no US company", which is broader than
  /privacy allows.

/trust names its reader, then gives that reader somewhere to go.

  The hero addresses organisations running their own relay and anyone
  checking a supplier, and now offers them two buttons instead of one text
  link mid-paragraph (y=416 and y=476). The first sentence under the hero no
  longer says "the operator who runs the relay": relay is not a word a
  supplier reviewer knows.

  The page called itself Trust & Verification in its title and H1 while the
  social card and the structured data still said Trust & Transparency. #334
  then rewrote every head on the site, so the literal strings belong there and
  tests/seo-contract.test.mjs pins them. What this branch pins is the
  relation: the title, og:title, twitter:title and the JSON-LD name must name
  the page the same, and that name must contain the words the H1 uses.
  Punctuation and case are not the point; Transparency versus Verification
  was. Its plan sentence named two of the three paid
  ParaSign tiers; it names all three, and both free tiers as Community.

Tests

  tests/ui-truthfulness.test.mjs pins each of the above, and each one was
  sabotaged in place to confirm it goes red: the ten-year promise, the
  give-back sentence, the US-subscription framing, the Community rename, the
  CLOUD Act row, the Resend exception dropped from the card, the finding
  counts, the "reports not published" sentence, the auditor names on
  /security as well as /trust, the two hero buttons on each page, the
  who-is-behind line, the bounded promise, the /trust og:title and JSON-LD
  name, the jargon in the first screen, and the paid tiers. Twenty-seven
  sabotages, twenty-seven red, no gaps.

  tests/site-claims.test.mjs block 11 reads the numbers out of the /pricing
  tier card that owns them and requires /about to repeat them; it follows the
  Community rename and now also forbids "ParaSign Free" on /about.

  node --test over the CI glob: 173 pass, 0 fail. check-csp-inline,
  check-cache-bust and eslint exit 0, bron-seo/apply_seo_head.py --check
  reports 0 pages, and tests/static-sanity.sh is PASS on all eleven checks,
  including #362's new test-scope guard. At 390px all three pages have
  scrollWidth === clientWidth === 390.

Following main through four parallel merges

  #359 landed the deduplication this branch was carrying (the second const
  tiers in relay/test/pricing-page.test.js, and pricingVisible renamed to
  pricingText), so both local fixes are dropped in favour of main's.

  This branch's own block in tests/ui-truthfulness.test.mjs now sits inside a
  bare block scope and declares nothing at module level. Four PRs merged into
  that file in parallel on 2 September and two of them collided on a top-level
  const, which is a SyntaxError: not one assertion in the file runs, on any
  branch. A block that declares nothing at module level cannot do that to the
  next branch.

  tests/site-claims.test.mjs block 12 stopped spelling the units itself. #336
  renamed both /pricing section headings and put ParaSign first, and #359
  reworded "2 signatures per month" to "2 signatures a month". The block now
  finds the headings by product prefix, orders them by position, and lifts each
  fact out of the card as a whole phrase, so /about repeats what /pricing says
  rather than what this file guesses /pricing says. /about follows the new
  wording: "2 signatures a month", "24 hour link expiry", "up to 10 reads per
  link".

Still open, deliberately

  The eIDAS level (SES on /about, advanced (AES) in the /pricing FAQ) is a
  real contradiction and needs a decision, not a copy edit. This branch stops
  it spreading and pins that it stays on the one page that has always carried
  it.
@Apolloccrypt
Apolloccrypt deleted the feat/fe-meta branch September 5, 2026 18:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant