Hello,
We're bcrypto.com (Q-Audion, an E2EE messaging/calling app) and we're
preparing to start submitting real identity-key transparency bindings
to the sigsum-generic-2025-1 policy (seasalp.glasklar.is +
ginkgo.tlog.mullvad.net, 2-of-3 witness quorum).
Two things we'd appreciate help with before going live:
1. We're about to publish a rate-limit public key at
_sigsum_v1.bcrypto.com per the submit-token spec. Could someone
confirm the current TXT record format/label is still "_sigsum_v1"
(we've implemented against that, but wanted to double-check against
current docs before publishing a real DNS record)?
2. Our expected initial volume is low (new identity-key publish events
only — new accounts + key rotations, not per-message or per-call),
likely well under the default rate-limit allotment, but we'd like
to flag it in advance in case our growth trajectory matters to your
capacity planning.
Our rate-limit public key (Ed25519, hex):
2089973caf3ff3db5e1596e1f1971992c82b827dd4c42e76c52841f3c0a02093
Happy to answer any questions about our use case.
Thanks,
Pavel
bcrypto.com