diff --git a/ESTATE.md b/ESTATE.md
index d872905..f7ac60d 100644
--- a/ESTATE.md
+++ b/ESTATE.md
@@ -37,13 +37,12 @@ flowchart LR
crs["course + llms.txt
14 notebooks"]
key["SIGNING KEY (offline)"]
ops["operational log state
the true accumulator"]
- sd["SD archive
kits · stamps · correspondence"]
+ sd["evidence archive (offline)
kits · stamps"]
end
subgraph P["PUBLISHED FACES"]
mir["lean-transparency-log
GENERATED mirror · fail-closed verify.py + selftest"]
site["ltl.zkdefi.org
homepage · /v1 API · /paper"]
fj["Forgejo (droplet)
nightly full-account mirror"]
- pcs["PersonalCloudServer (private)
droplet infra as code"]
book["verifying-crypto-with-lean
undergrad book (independent)"]
end
subgraph C2["CONSUMERS"]
@@ -69,7 +68,6 @@ flowchart LR
prov -->|app code| site
mir -->|published copy| site
pap -->|/paper| site
- pcs -->|infra| site
mir -.->|nightly| fj
mir -->|clone + verify| cl
site -->|API · custody card| ag
@@ -91,7 +89,7 @@ flowchart LR
class d,a,r,b,p,c sub
class prov,sig,lib,wal,pap,crs mach
class key,ops,sd held
- class mir,site,fj,pcs,book pub
+ class mir,site,fj,book pub
class cl,wr,ag,sw,rev cons
```
@@ -123,18 +121,17 @@ deployed verifier; see the corpus KNOWN-GAPS ledger).
| `proof-aware-crypto-tooling-agent` (this repo) | machinery | provider service, consumer library, warden, dogfood signer, paper, course, tests | **changes freely — the hub** |
| `lean-transparency-log` | published | the public mirror: leaves, heads, receipts, fail-closed `verify.py` + selftest | **generated by publish** — canonical files here, templates in pacta, CI-pinned |
| `verifying-crypto-with-lean` | published | undergraduate book; zero coupling to log state | changes freely |
-| `PersonalCloudServer` (private) | published | droplet infrastructure as code | changes freely |
| `swisspost-evoting-go-poc` | consumer | operator's PoC; prospective consumer (family-level dalek match only) | independent |
## Services, infra, operator-held
| Entity | What it is |
|---|---|
-| **ltl.zkdefi.org** | droplet (caddy → docker `cloud-ltl-1`): homepage rendered from live leaves, `/v1` API, `/paper` (+`/v0.2`, `/v0.1`), key endpoint. Read-only; no key material on the server. |
+| **ltl.zkdefi.org** | droplet (caddy → docker `cloud-ltl-1`): homepage rendered from live leaves, `/v1` API, `/paper` (+`/v0.2`, `/v0.1`), key endpoint. Read-only; no key material on the server. Deployment configuration is maintained privately. |
| **Forgejo** (`cloud-forgejo-1`) | nightly (03:00) mirror of the entire saymrwulf GitHub account — disaster-recovery copy. |
-| **Signing key** | offline, operator-only; fingerprint `874c8a00…`; sole copy + one encrypted SD backup; public half published in two independent locations. |
+| **Signing key** | offline, operator-only; fingerprint `874c8a00…`; never on the server; public half published in two independent locations. |
| **Operational log state** | `provider/state/transparency-log-main` — the true accumulator. Appends happen here; the mirror is its projection. |
-| **SD archive** | review kits (rounds 1–15), stamped artifacts (`_timestamp_hash8`), evidence records, submission correspondence (never in git). |
+| **Evidence archive (offline)** | review kits and stamped artifacts (`_timestamp_hash8` convention); never in git. |
## Edge glossary
@@ -154,4 +151,7 @@ line), the paper version changes, a repo/service/consumer is added or
retired, or a loop-relevant mechanism changes. Rules that keep the map
honest: **generated artifacts are fixed at their source** (mirror files
→ pacta templates); subject repos move only for docs; the three
-operator-held entities are never expanded into detail here.
+operator-held entities are never expanded into detail here, and the
+private infrastructure layer is deliberately unnamed — this map lists
+only entities whose existence is already public or must be public for
+trust.