Input
Usually the lender
Data submitted to the automated system.
How it works
A configuration version label is not proof that the configuration contents were preserved, committed before execution, or independently witnessed. Where a provider cannot expose a configuration artifact at execution time, none of the claims below can be established for it. That is a gap in what the provider makes available, not a value this instrument computes.
These are not results this instrument emits. The verifier reports five facts about a sealed relation, not a verdict per object.
Input
Usually the lender
Data submitted to the automated system.
Configuration
Usually the AVM or cascade provider
Cascade order, thresholds, decision logic, model pins. The state that may be overwritten.
Output
Usually the lender
The valuation that came back.
Execution
Only if capture happened
The specific run that links the other three.
Missing evidence stays Unchecked. It is not converted into a pass.
Established
The required evidence is present and checks out.
Not established
The required evidence is missing, invalid, or fails.
Unchecked
An outside party’s own count or checkpoint was needed and was not supplied. This applies to completeness and disclosure, below, not to the five claims about a single run. Coverage uses a different default: absent, not unchecked.
Claim
What it asks
A yes means
A yes does not mean
Claim
Precedence
What it asks
Does the commitment appear on the chain before the seal that names it?
A yes means
The commitment appears before the seal.
A yes does not mean
That the bytes were on the chain before the analysis ran, that the system consumed them, or that the source data was true.
Claim
Witness
What it asks
Did a separately trusted party attest to the capture?
A yes means
A separate key signed the observed relation at the time.
A yes does not mean
That the witness saw everything, is commercially independent, or is truthful. A signature in the operator’s own file is not a witness. This is the narrow sense of an independent observer of the capture, not a claim that anything was reviewed, audited, or endorsed.
Claim
Recipe
What it asks
Is there a version-pinned procedure for checking the claimed computation?
A yes means
A reproduction path is specified and linked to this run.
A yes does not mean
That the original run occurred.
Claim
Reproduction
What it asks
Can a later verifier reproduce the sealed output where the computation is deterministic?
A yes means
A later check matched the sealed output.
A yes does not mean
That the original run happened that way. For machine-learning valuation models this is reported as not established, not granted. A matched reproduction adds nothing a commodity timestamping service could not do unless an outside retention determination says the operator could not have kept the input.
Claim
Execution
What it asks
Is there evidence that the claimed run actually occurred at the stated time?
A yes means
A valid observed-execution witness covers the required relation.
A yes does not mean
Anything inferred only from a later matching rerun.
The record, not the run
Completeness and Coverage describe the record. They are never numbered as a sixth claim.
Completeness asks whether a single supplied chain is whole against a chain-level statement of its length. An artifact of three entries and an artifact cut from five to three are the same document without that statement. If the statement is missing, the result is Unchecked. It does not prove every relevant run in the world was captured.
Coverage asks whether the workfile binding makes omission of a run detectable. The verifier reports one of three values, not established or unchecked.
Contiguous
The binding names the chain as a whole, so a missing sequence is visible.
Subset
The binding does not cover the chain as a whole, and that is detected. Omitted sequence numbers are named because this chain was supplied whole. A truncated chain whose binding matches what remains would read contiguous. Phantom entries, a failed head check, and runs sealed after the binding are named the same way. That last case is a chain that kept growing past its own certification.
Absent
There is no workfile binding. This is the default. An undecorated call leaves Coverage absent.
Contiguous does not mean every relevant run was captured. A chain can show what was submitted. It cannot reveal a run that never entered the capture boundary. Establishing that boundary, the relationship between an assignment and the full set of executions that should have been captured, remains open.
Supporting determinations
Disclosure is the assignment-level counterpart. Seal five valuations on five chains, send the three that support the number, and every sent record can still verify. A separately held count of the chains makes short disclosure detectable against that count. If that count is not supplied, the result is Unchecked.
What it asks: do independent anchors constrain when the chain could have been written. A yes means the claimed instants fall between supported external bounds. A yes does not mean that the configuration or the number was correct. A timestamp alone bounds the later side and leaves backdating untouched.
The verifier also reports input provenance and holding. They are not claims. They feed the determination at the end of this page: whether a commodity timestamping service over the same local files would have reached the same place.
Inputs, a configuration, and an output can sit in the same file and still have been assembled after the number existed. A signature can authorize that file. It does not, by itself, make the claims inside it an account of what the provider had in force.
After the five claims, the demonstration prints two summary lines.
They diverge in one direction only. A record can verify as a document and still fail this test. The reverse cannot occur: evidentiary reliance requires the cryptographic result. The test is intentionally narrower than a claim that it is safe to rely on. It does not require precedence, recipe availability, historical execution, or that the supplied chain is whole. Completeness is a record-axis result. It is not in this predicate. A yes can sit next to historical execution remaining not established.
A valid independent witness of the capture closes the third condition. A matched reproduction does not, unless an outside retention determination says the operator could not have kept the input.
See a record that still looks legitimate·Verification core on GitHub