Check it yourself.
Paste an Agent Passport or a decision proof. It is verified in this browser, against a key you supply. Nothing is uploaded, no account is needed, and Cirvix never sees what you are checking.
Four things,
in this order.
The signature, first
Before a single field inside the artifact is read. A hostile artifact must not get to steer the verifier through its own contents.
The canonical round trip
The body must re-serialise to exactly the bytes that were signed. Without this a verifier can be shown one thing and check another.
Shape and required fields
A proof cannot be presented as a passport, and a passport missing its identity is refused rather than partially rendered.
Policy binding
Reported either way. A passport that names no policy hash attests to no particular rule set, and the result says so instead of implying otherwise.
VALID means one specific thing. That these bytes were signed by that key and have not changed since. It is not a statement that the agent is safe, that the policy is good, or that Cirvix endorses anyone. A passport is evidence about posture; reading it is still your job.
UNVERIFIED is not INVALID. If your browser cannot import Ed25519 keys the page says so rather than guessing. Nothing is wrong with the artifact — check it offline with cirvix verify --file <artifact>.