Evidence Timeline
Proof, not promises.
Every execution leaves a verifiable trail showing who had authority, what policy applied, what happened, and what evidence was recorded.
01
Authority verified
Credential pinned to one authority; scope, delegation, inheritance, genesis lineage and the authority-event chain are checked at the moment of use. Any unresolvable link denies.
02
Admissibility determined
A second, separate decision over the material conditions recorded for this subject at execution time. Missing or stale state fails closed.
03
Preparation admissibility
On the read path, an early refusal point that runs before any protected value is fetched or decrypted.
04
Pre-vault freshness re-read
Authority, matter boundary and material conditions are re-read from the database immediately before decryption. If anything changed, no ciphertext is fetched.
05
Final effect boundary
A fresh re-evaluation at the last instant before disclosure. It can deny outright or tighten a transformation, and the prepared — including already-decrypted — payload is discarded rather than released.
06
Evidence sealed
Every step is written to an append-only, per-action hash-chained record, closed out with a sealed action receipt and, on disclosure, a receipt carrying a keyed fingerprint of the exact payload approved to leave.
Stated plainly: Trace re-evaluates the state available to it immediately before a consequence occurs. It cannot independently know that an external condition changed unless that change has been reported to it or otherwise made observable. Evidence tables are append-only against ordinary application code and ordinary database roles; that is tamper-evidence, not a claim of absolute tamper-proofing.
Generate live evidence