Verification happens entirely in your browser against the published public key — a post-quantum ML-DSA-65 signature (NIST FIPS 204). No trust in this server required.
Loading public key…
The classical HMAC-SHA256 signature on the same certificate can only be checked by the Mood Art server; the ML-DSA signature is the one anyone can verify, on any machine, at any point in the future. How provenance works →