September 5, 2026

In an effort to make the web safer, Entelecheia is sharing this proposed architecture with browser developers, standards organizations, and others working on the future of the web. It addresses a fundamental weakness in the face of JavaScript backdoors: browsers verify content per domain, but not per URL. A reference implementation is at github.com/entelecheia-inc/page-integrity.

The web is already secure, but only up to a server. HTTPS confirms that the browser has reached a server authorized for a domain, but from that point the server defines the page. It can inject a JavaScript backdoor or replace the page entirely tomorrow while keeping the same URL and certificate. Alice’s pages and Bob’s pages may share a domain, as they commonly do on hosting platforms such as Netlify and GoDaddy, yet the browser has no way to distinguish their separate authorities; it simply trusts whatever the server sends. Whoever controls the server—a hosting provider, CDN, cloud account, or an attacker who has compromised it—therefore controls everything it serves.