Transparency and records
- Version
- v1
- In force since
- Not yet
- Next review
- At adoption
- Snapshot
- None yet
- Adopted by
- Proposed for founding adoption
- Signature
- At adoption
- Log entry
- Not appended yet
- Binding text
- English
Proposed, not in force
Open for comment until 28 October 2026, 00:00 UTC. Nothing here binds anyone until it is adopted.
Scope
This policy sets what GOpenCDR publishes about its own changes, and how. Recorded votes, comment periods, vetoes and declarations of interest follow the governance charter.
Change log
Every change to the root zone is published in a public change log within 1 hourfixed of its publication: what changed, why, who approved it, the serial and the time.
Transparency log
Every root change, key event, root role grant, certificate, policy version, veto and abuse action is entered in the transparency log, a Merkle log in the C2SP tlog-tiles format, in the same transaction as the change it records.
Rule tlog.record.
Checkpoints are signed with Ed25519 inside Vault and cosigned by at least 1 independent witnessfixed.
Nothing in the log is ever changed or removed.
Practice statements
A DNSSEC practice statement following RFC 6841 is published before the first production root signature, and a certificate policy and practice statement following RFC 3647 before the first production certificate. Both are versioned and change only after public comment.
Policy versions
Every adopted policy version is rendered to canonical JSON, hashed, signed through Vault Transit and entered in the transparency log before it takes effect. Every version stays readable for good, with what changed and the instrument that adopted it.
Rule policy.publication.
English is the binding language. Translations are informative and marked as such.
Global policies stay at their founding versions until councils vote in GOpenCDR. Until then only an emergency measure or a clerical correction changes them.
Legal assessment
A written legal assessment is obtained before public launch, and every finding is tracked to closure. It covers NIS2, the GDPR roles, the Digital Services Act, the trademark exposure of TLD strings and German legal notice duties.