Security model

Evidence

Exact bytes, explicit provenance, deterministic support.

Two dimensions of trust

Authoritative evidence is submitted by an authorized reporter and passes the structured schema. Supplemental evidence can add context, but cannot establish payout-bearing facts by itself.

Hash display

SHA-256 proves the fetched bytes match the committed hash. It does not prove who produced a measurement or whether a measurement is true. Reporter identity and quorum are separate controls.

Immutable artifacts

Canonical JSON is stored as exact bytes behind a content-addressed URL. Fetching the raw artifact and hashing it should reproduce the recorded SHA-256.