ROOT COMMITMENT WITNESS · 0.2-RC1

Commit first.
Learn outcomes later.

A digest proves integrity only if someone independent saw it on time. Profile 0.2-RC1 requires periodic telemetry roots, two organizationally independent Ed25519 witnesses per root, and publication within a bounded 24-hour delay.

2WITNESS ORGS / ROOT
24HMAX ROOT INTERVAL
24HMAX PUBLISH DELAY
8HARD GATES
01 / ANTI-BACKFILL INTEGRITY

One root is a claim.
A witnessed series is evidence.

Every due root is reconstructed from the declared activation, observation end, and frozen cadence. Missing windows, late disclosure, single-organization quorum, invalid signatures, or root substitution fail eligibility.

RC1FROZEN PROTOCOL

Freeze cadence, delay, canonicalization, hash, and signature scope.

REQUIRED
RC2INDEPENDENT REGISTRY

Use distinct witness organizations outside sponsor control.

REQUIRED
RC3COMPLETE CADENCE

Publish every periodic root and the final observation root.

REQUIRED
RC4ROOT COLLECTION

Reproduce one canonical digest across every deployment and root.

REQUIRED
RC5BOUND RECEIPTS

Bind deployment, ordinal, coverage time, root, witness, and log entry.

REQUIRED
RC6SIGNED QUORUM

Require two valid Ed25519 receipts from distinct organizations.

REQUIRED
RC7TARGET COVERAGE

Witness every deployment used by the claimed field target.

REQUIRED
RC8ASSURANCE

Bind public index, controlled archive, and independent review.

REQUIRED
02 / PUBLICATION CLOCK

Bounded delay.
No post-hoc roots.

For interval Δ and deployment end T, the verifier requires a root at every min(t₀ + kΔ, T). Each receipt must be observed no earlier than its coverage boundary and no later than 24 hours afterward.

ROOT DUE TIMEStk = min(t0 + kΔ, T)

For every root rk, at least two distinct registered organizations sign the exact deployment, ordinal, coverage time, digest, observation time, and transparency-log entry.

03 / INTERPRETATION

Prevents backfill.
Does not prove sensor truth.

A pass proves the exact root collection was independently disclosed on schedule. Event signatures still prove authorship and chain continuity; the exposure ledger still proves resident time; endpoint, safety, and audit profiles remain separate.

PERIODIC ROOTS

At least every 24 hours plus the final observation boundary.

INDEPENDENT QUORUM

Two registered Ed25519 keys from different non-sponsor organizations.

CANONICAL COLLECTION

One RFC 8785 / SHA-256 digest binds all deployments and root ordinals.

04 / LOCAL VERIFICATION

Paste the receipts.
Verify every witness.

The browser reconstructs every due root, the canonical collection digest, witness registry authority, key lifecycle, signature, quorum, and publication delay. No pasted manifest is uploaded. CI can run a claim with node wanted-root-witness-verifier.mjs manifest.json or all 11 normative vectors with --conformance.

LOCAL ROOT-WITNESS VERIFIERPROFILE / 0.2-RC1 · WEB CRYPTO ED25519
ROOT CHRONOLOGYINVALIDPaste a manifest or explicitly load the signed synthetic example.
ELIGIBILITY ONLY · NEVER A TIEBREAKER

Witness quality cannot compensate for a lower WANTED score, weak tail support, or any safety failure. It establishes whether the evidence existed on time.

OPEN PROTOCOL KIT →