Trust / Evidence Register
Evidence Register
Claim-to-source bindings and the exact status of signed evidence.
Dated repository-local capture
Authority & Evidence
Dated repository-local command-output evidence captured from the named commit and tree. Reported hashes vary by execution; they are exact fields from this captured payload, not reproducible canonical constants.
- Source commit
5cec88069a5646c188079fab2c701c79b4941f34- Source tree
7f9808af367d630265b2bb115a9f90d041e661e4- Captured payload bytes
receiz-docs/evidence/slice-6/trust-command-output.v1.json90f04e0d6aa4e29813f0ef54022b8fafdc21b8b1076429def82ae8cff13b44f3- Capture runtime
- Node.js v24.15.0; pnpm 10; macOS arm64; repository-local commands
Governance controls
15 documents · 15 active families
8bba1dc326518c4de85a34de007219c04498457e150729245b4f959e5f6d4037b920acc795893361c66512017b29cc2f95ca66935ea5b2a97798dcfb57fdfef8receiz.governance.ed25519.2a7c4651102d1498Governance evidence
4 controls
d08b41fe380fa07035f85d05520ca260d38e64043e90596d58501e79a8423354Artifact signatures
7 artifacts · public/governance/artifact-manifest.v1.json
defeb9426855b8552b930bf1b1c790b15bb6479d2ac820ea2945b51fc347fb96receiz.governance.ed25519.2a7c4651102d1498Dated release attestation
artifacts/release-attestations/2026-06-30T18-43-21-460Z-617c943ad70e.json
- Commit
617c943ad70eae1c72ab6dda587636aa0dd32a03- Tree
f4df91467bb73f67bbb3767d45a70ceb7a238b9b- Build
- Fy4kSk7jLG1YOIVrQP0BJ
1ae616db02577495a4167cf383a54854d13d9b39d293d470263aa82bfa731785 - Economy revision
322edae1b449a2c0dfb3da34e0f72488df459ed852fdc972dafb8009799c9c7e- Verification revision
4e230c6f125637a76c70dbef160e4eaa5defacc8cee114bc8bbbfcc2e2caec4b- Market revision
15175c2566ca5e860d5538a2657c9ebe5818aff87f3982962ada3c35b670ba4c- Payload hash
c3c37fa46d27eec432a5ce8b4cf7c4d78d849e0002685f280aa2c85d61f7d5e8- Signing key
receiz.governance.ed25519.2a7c4651102d1498- Signature
sz1VpQXA_unmO6mS9Tmv-ZUwxlDJEVD5NUA4Yps31XE4kBxFLbj8qNdcjVD62APAYKJlrFBGR8rYwZP_JTbCAQ
evidence-register
Governance evidence check
Evidence mappings are checked without converting the register into artifact truth.
- Exact source
scripts/check_governance_evidence.tsSHA-2564d887a3943808bec1f3d274b02bd4cf7cfc9f3b39c5e34169c709ddc97c8263c- Implemented primitive
- governance evidence
- Source of truth
- The underlying evidence artifacts and their registered digests.
- Guarantee
- Registered evidence entries satisfy the checker's exact presence, binding, and status rules.
- Executable check
pnpm governance:evidence-check- Evidence output
- Evidence validation result identifying each accepted or failed binding.
- Failure meaning
- An evidence claim is unbound, stale, missing, or structurally invalid.
- Recovery / escalation
- Do not relabel evidence; supply the missing source or correct the exact register binding.
- Offline behavior
- Committed evidence and digests are checked locally.
- External boundary
- An evidence entry does not independently prove current production state.
- What this record does not prove
- This record does not prove signature presence or unobserved activity.
signed-evidence-verifier
Release attestation verification
A dated attestation is verified independently; latest.json is not independent proof.
- Exact source
scripts/verify_release_attestation.tsSHA-256f04e07009107c30a2c41a2f237ed08a581b4773caef3771d8167b762e23d6606- Implemented primitive
- release attestation
- Source of truth
- Exact dated attestation bytes, registered key, signature, commit, tree, and build bindings.
- Guarantee
- A passing command verifies every bound attestation field for the supplied artifact.
- Executable check
pnpm release:verify-attestation <exact-dated-attestation-path>- Evidence output
- Verified attestation result or an exact binding/signature failure.
- Failure meaning
- Verification absent; a missing artifact retains failure status.
- Recovery / escalation
- Use the exact dated artifact emitted after gates and resolve the first failed binding.
- Offline behavior
- Committed attestation and key material can be verified offline.
- External boundary
- A valid attestation does not establish later production drift or an unbound deployment.
- What this record does not prove
- This record does not prove latest.json is independent evidence or that production state is current.
evidence-register
Governance evidence register
The register maps claims to artifacts, controls, and status without replacing their underlying authority.
- Exact source
docs/governance/evidence-register.v1.jsonSHA-256d08b41fe380fa07035f85d05520ca260d38e64043e90596d58501e79a8423354- Implemented primitive
- evidence provenance
- Source of truth
- Each referenced evidence artifact and its exact digest.
- Guarantee
- Declared evidence remains traceable to a stable registered record.
- Executable check
pnpm governance:evidence-check- Evidence output
- Register validation plus exact evidence source identifiers.
- Failure meaning
- The claim-to-evidence chain is incomplete or inconsistent.
- Recovery / escalation
- Correct the mapping or declare the evidence absent; never invent or upgrade status.
- Offline behavior
- The committed register and referenced committed evidence remain inspectable offline.
- External boundary
- Production state is unknown unless a dated production observation is explicitly bound.
- What this record does not prove
- This record does not prove every registered statement remains true outside its dated evidence boundary.