Security model
Evidence
Exact bytes, explicit provenance, deterministic support.
Two dimensions of trust
Authoritative evidence is submitted by an authorized reporter and passes the structured schema. Supplemental evidence can add context, but cannot establish payout-bearing facts by itself.
Hash display
SHA-256 proves the fetched bytes match the committed hash. It does not prove who produced a measurement or whether a measurement is true. Reporter identity and quorum are separate controls.
Immutable artifacts
Canonical JSON is stored as exact bytes behind a content-addressed URL. Fetching the raw artifact and hashing it should reproduce the recorded SHA-256.