Freeze cadence, delay, canonicalization, hash, and signature scope.
REQUIREDCommit first.
Learn outcomes later.
A digest proves integrity only if someone independent saw it on time. Profile 0.2-RC1 requires periodic telemetry roots, two organizationally independent Ed25519 witnesses per root, and publication within a bounded 24-hour delay.
One root is a claim.
A witnessed series is evidence.
Every due root is reconstructed from the declared activation, observation end, and frozen cadence. Missing windows, late disclosure, single-organization quorum, invalid signatures, or root substitution fail eligibility.
Use distinct witness organizations outside sponsor control.
REQUIREDPublish every periodic root and the final observation root.
REQUIREDReproduce one canonical digest across every deployment and root.
REQUIREDBind deployment, ordinal, coverage time, root, witness, and log entry.
REQUIREDRequire two valid Ed25519 receipts from distinct organizations.
REQUIREDWitness every deployment used by the claimed field target.
REQUIREDBind public index, controlled archive, and independent review.
REQUIREDBounded delay.
No post-hoc roots.
For interval Δ and deployment end T, the verifier requires a root at every min(t₀ + kΔ, T). Each receipt must be observed no earlier than its coverage boundary and no later than 24 hours afterward.
For every root rk, at least two distinct registered organizations sign the exact deployment, ordinal, coverage time, digest, observation time, and transparency-log entry.
Prevents backfill.
Does not prove sensor truth.
A pass proves the exact root collection was independently disclosed on schedule. Event signatures still prove authorship and chain continuity; the exposure ledger still proves resident time; endpoint, safety, and audit profiles remain separate.
At least every 24 hours plus the final observation boundary.
Two registered Ed25519 keys from different non-sponsor organizations.
One RFC 8785 / SHA-256 digest binds all deployments and root ordinals.
Paste the receipts.
Verify every witness.
The browser reconstructs every due root, the canonical collection digest, witness registry authority, key lifecycle, signature, quorum, and publication delay. No pasted manifest is uploaded. CI can run a claim with node wanted-root-witness-verifier.mjs manifest.json or all 11 normative vectors with --conformance.
Witness quality cannot compensate for a lower WANTED score, weak tail support, or any safety failure. It establishes whether the evidence existed on time.
OPEN PROTOCOL KIT →