thanks again for the compliance test. Your reports have been driving most of the work. nostrcheck.me is now at 90%, and once 0.7.1 ships every nostrcheck-server instance will inherit the same fixes. I'm parking the report there on purpose. The remaining warnings come from my anti-replay system (the suite reuses the same auth event across co flows, and I'd rather keep replay protection strict) and from rejecting application/octet-stream uploads when file-type sniffing can't identify the bytes. IMO both feel like the right trade-off for a public server.