Trust · oddly trust

A posture written by the party being assessed is not evidence.

Ours is not written. Every change to this estate merges through a gate no machine can release, every reading carries the source's clock and ours, and the day's receipts are folded into one root and submitted somewhere we do not run. Diligence moves from relationship to arithmetic.

The estate itself

A day closes, its receipts fold into one root, and the root leaves.

newest root [today's root]

The newest root is nearly always pending, and that is the honest state rather than an exception: a day is built the night after it closes and confirmed later still. A root that has not cleared is shown as a root that has not cleared.

This surface publishes no count of anchored days. The public read serves the newest batch and the newest confirmed batch, so the only numbers available are one and one, and neither of them is the count the canvas asks for.

Down to one confirmed day

The point where checking us stops involving us.

A confirmed day is a root someone else's ledger carries, at a height nobody here can move. Until a block carries it, the time still rests on our clock, and this page says so rather than rounding the difference away.

What the decision rests on today

A claim, with a logo on it.

Every one of these is believed because of who supplied it. None of them can be checked by the person who has to form a view.

the report

A report is a snapshot someone else took, of a system as it was, for a reader who was not you.

the questionnaire

A security questionnaire is an assertion by the party being assessed, in its own words, on its own schedule.

the trust page

A trust page is a claim with a logo. Nothing on it goes dark when it stops being true.

What oddly puts on the record

The same thing, observed.

Two clocks on every row. A root a day. An anchor outside us. Nothing here is our word.

posture

Controls observed as they run, not described. Every change to this estate merges through a gate a machine cannot release, and the gate is on the record.

evidence

Each observation carries the source, both clocks, and the receipt of the one before it. The evidence pack is generated from what runs, never written.

anchor

The confirmed days, named with the newest day, its receipt count and its block height. A pending day is named as pending and carries no height.

The verbs

Observe. Seal. Publish. Anchor.

The same four on every surface. A product here is the record read for one decision, never a second machine.

observe

Read the source as it is published, and write down both clocks.

seal

Hash the row with its predecessor, so no receipt can move without every later one changing.

publish

Fold the day's receipts into one root and put it where anyone can read it.

anchor

Submit the root to a chain we do not run. From then on, checking us does not involve us.

One confirmed day, read live

A day of this estate's receipts, folded into one root, in a block we do not run.

Read at load from the public observation endpoint. Every slot stays bracketed until a day has actually cleared, and a pending day never appears here.

day
[no confirmed day]
receipts folded
[pending]
day root
[pending]
chain
[pending]
block
[pending]
confirmed
[pending]
newest root
[today's root]

The newest root and the day root above it are two different facts and are printed as two rows for that reason: the newest root is whatever the estate built last, confirmed or not, and the confirmed root is the last one another ledger carries. The inclusion path from a single receipt up to a day root is a separate rail and is not published yet, so this page shows the root and does not claim the step between them.