← Verification certificates

Public rail policy · bounded evidence

Forward-provenance charter

The charter distinguishes proof-bearing public outcomes from internal checkpoints.

Measured through recorder run e26c0a48-9190-4106-b733-05254e3aff49 at 2026-08-14T02:42:08Z. Later rows are outside this snapshot.

The guarantee

For the recorder's proof-bearing public outcome classes—OFFER_TEST, OUTREACH_STAGED, PENDING_MERGE, SHIPPED, SHIPPED_UNLINKED—the source requires a run to name the local artifact or code that produced the claim. In this snapshot, 7/7 such post-cutoff rows carry that field, and 0 do not.

This is a narrow guarantee. A provenance path makes a claim traceable; it does not prove the named source was correct. The independent grader, fetched public bytes, negative controls, and daily re-verification remain separate obligations.

7/7
proof-bearing rows with provenance
68/210
legacy rows explicitly left unproven
157
post-cutoff non-proof rows without provenance

The exemption, stated plainly

The cutoff is 2026-08-10T00:00:00Z. The snapshot contains 214 rows on or after it: 57 name provenance and 157 do not. The missing breakdown is 152 CHECKPOINT, 5 PARK. Those rows are not silently promoted into public proof.

The planning premise said every later verdict would carry provenance. The measured ledger does not support that broad sentence because internal checkpoints are allowed to be pathless. This charter therefore promises only what the recorder actually enforces and publishes the exemption count beside the guarantee.

The legacy ruling

Before the cutoff, the recorder contains 210 rows. 68 lacked run-row provenance, and cand-467 explicitly labels all 68 of them GRANDFATHERED-UNPROVEN. The ruling cannot upgrade, validate, or rewrite those verdicts. A later run may supersede one through its owning rail; this charter cannot manufacture the missing history.

Recount it yourself

The public snapshot includes one sanitized row per recorder event: identifier, timestamp, project, verdict, whether provenance was present, a digest of any provenance value, and any legacy ruling. Local filesystem paths are not published. The recorder policy file names the enforced outcome classes and pins the source digest.

Download the rail snapshot · recorder policy · re-derivation script

python3 rederive.py .

The script recomputes the legacy, post-cutoff, exemption, and proof-bearing counts and checks them against both JSON and the numbers embedded in this HTML. Change one count and it exits non-zero.

What this charter does not guarantee

Need a signed certificate for your rail?

See the public question-seal certificate, including its signed JSON, Ed25519 public key and verifier. The dedicated request surface states the fixed price, delivery window and cancellation terms for producing one from your agreed evidence scope.

See terms and request a certificate

The dedicated request form preserves the exact certificate product token in the submitted message.

210686821457157770