Trust / Evidence Register

Evidence Register

Claim-to-source bindings and the exact status of signed evidence.

3 exact recordsSource + SHA-256Failure + recovery

Dated repository-local capture

Authority & Evidence

CAPTURED PASS2026-08-02T07:30:52Z

Dated repository-local command-output evidence captured from the named commit and tree. Reported hashes vary by execution; they are exact fields from this captured payload, not reproducible canonical constants.

Source commit
5cec88069a5646c188079fab2c701c79b4941f34
Source tree
7f9808af367d630265b2bb115a9f90d041e661e4
Captured payload bytes
receiz-docs/evidence/slice-6/trust-command-output.v1.json90f04e0d6aa4e29813f0ef54022b8fafdc21b8b1076429def82ae8cff13b44f3
Capture runtime
Node.js v24.15.0; pnpm 10; macOS arm64; repository-local commands
PASS

Governance controls

15 documents · 15 active families

8bba1dc326518c4de85a34de007219c04498457e150729245b4f959e5f6d4037b920acc795893361c66512017b29cc2f95ca66935ea5b2a97798dcfb57fdfef8receiz.governance.ed25519.2a7c4651102d1498
PASS

Governance evidence

4 controls

d08b41fe380fa07035f85d05520ca260d38e64043e90596d58501e79a8423354
PASS

Artifact signatures

7 artifacts · public/governance/artifact-manifest.v1.json

defeb9426855b8552b930bf1b1c790b15bb6479d2ac820ea2945b51fc347fb96receiz.governance.ed25519.2a7c4651102d1498
VERIFIED

Dated release attestation

artifacts/release-attestations/2026-06-30T18-43-21-460Z-617c943ad70e.json

Commit
617c943ad70eae1c72ab6dda587636aa0dd32a03
Tree
f4df91467bb73f67bbb3767d45a70ceb7a238b9b
Build
Fy4kSk7jLG1YOIVrQP0BJ1ae616db02577495a4167cf383a54854d13d9b39d293d470263aa82bfa731785
Economy revision
322edae1b449a2c0dfb3da34e0f72488df459ed852fdc972dafb8009799c9c7e
Verification revision
4e230c6f125637a76c70dbef160e4eaa5defacc8cee114bc8bbbfcc2e2caec4b
Market revision
15175c2566ca5e860d5538a2657c9ebe5818aff87f3982962ada3c35b670ba4c
Payload hash
c3c37fa46d27eec432a5ce8b4cf7c4d78d849e0002685f280aa2c85d61f7d5e8
Signing key
receiz.governance.ed25519.2a7c4651102d1498
Signature
sz1VpQXA_unmO6mS9Tmv-ZUwxlDJEVD5NUA4Yps31XE4kBxFLbj8qNdcjVD62APAYKJlrFBGR8rYwZP_JTbCAQ
01

evidence-register

Governance evidence check

Evidence mappings are checked without converting the register into artifact truth.

Exact source
scripts/check_governance_evidence.tsSHA-2564d887a3943808bec1f3d274b02bd4cf7cfc9f3b39c5e34169c709ddc97c8263c
Implemented primitive
governance evidence
Source of truth
The underlying evidence artifacts and their registered digests.
Guarantee
Registered evidence entries satisfy the checker's exact presence, binding, and status rules.
Executable check
pnpm governance:evidence-check
Evidence output
Evidence validation result identifying each accepted or failed binding.
Failure meaning
An evidence claim is unbound, stale, missing, or structurally invalid.
Recovery / escalation
Do not relabel evidence; supply the missing source or correct the exact register binding.
Offline behavior
Committed evidence and digests are checked locally.
External boundary
An evidence entry does not independently prove current production state.
What this record does not prove
This record does not prove signature presence or unobserved activity.
02

signed-evidence-verifier

Release attestation verification

A dated attestation is verified independently; latest.json is not independent proof.

Exact source
scripts/verify_release_attestation.tsSHA-256f04e07009107c30a2c41a2f237ed08a581b4773caef3771d8167b762e23d6606
Implemented primitive
release attestation
Source of truth
Exact dated attestation bytes, registered key, signature, commit, tree, and build bindings.
Guarantee
A passing command verifies every bound attestation field for the supplied artifact.
Executable check
pnpm release:verify-attestation <exact-dated-attestation-path>
Evidence output
Verified attestation result or an exact binding/signature failure.
Failure meaning
Verification absent; a missing artifact retains failure status.
Recovery / escalation
Use the exact dated artifact emitted after gates and resolve the first failed binding.
Offline behavior
Committed attestation and key material can be verified offline.
External boundary
A valid attestation does not establish later production drift or an unbound deployment.
What this record does not prove
This record does not prove latest.json is independent evidence or that production state is current.
03

evidence-register

Governance evidence register

The register maps claims to artifacts, controls, and status without replacing their underlying authority.

Exact source
docs/governance/evidence-register.v1.jsonSHA-256d08b41fe380fa07035f85d05520ca260d38e64043e90596d58501e79a8423354
Implemented primitive
evidence provenance
Source of truth
Each referenced evidence artifact and its exact digest.
Guarantee
Declared evidence remains traceable to a stable registered record.
Executable check
pnpm governance:evidence-check
Evidence output
Register validation plus exact evidence source identifiers.
Failure meaning
The claim-to-evidence chain is incomplete or inconsistent.
Recovery / escalation
Correct the mapping or declare the evidence absent; never invent or upgrade status.
Offline behavior
The committed register and referenced committed evidence remain inspectable offline.
External boundary
Production state is unknown unless a dated production observation is explicitly bound.
What this record does not prove
This record does not prove every registered statement remains true outside its dated evidence boundary.